Path Shards
pash-cut · TikTok integration

Privacy Policy

Effective date:

Who we are

pash-cut is a tool operated by Path Shards. This policy explains what pash-cut does with data from TikTok when a TikTok account authorizes it. Contact: noreply@pathshards.com.

What the app does

pash-cut uploads short video clips to the inbox of a TikTok account as drafts. It never publishes anything by itself: you open the draft in the TikTok app, write the caption and decide whether to publish it.

pash-cut is used only with TikTok accounts that belong to its operator.

Data we receive from TikTok

This is the complete list of data the app receives from TikTok and keeps, with the purpose, where it is kept and for how long. Nothing else is received or kept.

Data Purpose Where it is kept How long
Access token Authenticate each video upload and each upload status check. In memory only; never written to disk or database. Up to 24 hours, when it expires.
Refresh token Obtain a new access token without asking you to authorize again. Operator's own database, encrypted. While your account stays connected; deleted on request.
Token lifetime (expires_in) Know when the access token must be renewed. In memory only; never written to disk or database. Discarded right after use.
Upload identifier (publish_id) Track whether an uploaded video reached your drafts. Operator's own database. Kept as the upload history; deleted on request.
Upload status Know whether an upload is pending, in your drafts, or failed. Operator's own database. Kept as the upload history; deleted on request.
Error message (only when an upload fails) Diagnose why an upload failed. Operator's own database. Kept as the upload history; deleted on request.

Permissions (scopes) we request

When you authorize the app, TikTok asks you to grant two scopes:

  • video.upload — to upload a video to your inbox as a draft. This is the only scope the app uses.
  • user.info.basic — added by TikTok to every app that uses Login Kit. The app does not use it: it never requests your profile information.

What we never access

The app does not read or keep your display name, avatar, profile, followers or following, existing videos, likes, analytics, comments or messages. The account identifier (open_id) that TikTok returns together with the tokens is discarded and never stored.

What we send to TikTok

The only data we send to TikTok is the video file of each clip, uploaded to your inbox as a draft. The final decision to publish is always yours: you publish it yourself in the TikTok app.

Data Purpose Where it is kept How long
Video file of the clip Uploaded to your TikTok inbox as a draft. You review, caption and publish it yourself in the TikTok app. Operator's own storage, where the clip is produced. Kept by the operator as the clip's file; TikTok's copy follows TikTok's own policies.

Storage and security

Everything listed above stays in the operator's own environment, run by Path Shards. The refresh token is stored encrypted, and the encryption key is kept outside the database. The access token is kept in memory only.

Sharing

Your data is not sold and not shared with third parties. It is not used for advertising, profiling or any purpose other than uploading your clips as drafts and tracking those uploads.

Retention

The refresh token is kept while your account stays connected to the app. The upload history (identifier, status and error message of each upload) is kept to track the uploads. Both are deleted on request.

Your choices

You can revoke the app's access at any time in the TikTok app, under Settings and privacy, Security and permissions, Manage app permissions (labels may vary by app version). Revoking takes effect immediately: the stored token stops working.

To have the stored refresh token and upload history deleted, send a request to noreply@pathshards.com naming the connected TikTok account. Requests are fulfilled within 30 days.

Children

The app is not directed to children and is only used with its operator's own TikTok accounts.

Changes to this policy

If the app starts receiving or keeping any other data, this policy and its effective date will be updated before that happens.

Contact

Path Shards — noreply@pathshards.com

See also: Terms of Service