This policy explains what information SIYai collects, why, how long we keep it, who we share it with, and the choices you have. It covers the SIYai website and app, run by SIYai ("we", "us").
In short
- We collect what we need to run SIYai: your account, the videos and products you add, and the accounts you connect.
- When you connect TikTok, we see your display name and profile picture, and we upload only the videos you confirm to your TikTok inbox.
- We never sell your information, and we don't use it for advertising.
- You can disconnect TikTok or Google Drive at any time, and ask us to delete your account.
1. Information we collect
Account information
Your email address, and your name if you give it, when you sign up. Our sign-in provider, Clerk, also stores your sign-in methods, such as a password, passkeys and two-step verification settings. We never see your password. We also keep your workspace's name, members, roles and settings.
Content you add
The videos, clips and photos you upload, the products you add (titles and photos), text you type into our tools (such as overlay text), and the folders and names you create. Files are stored in Cloudflare R2.
Connected accounts
What we receive from Google Drive and TikTok when you connect them is described in sections 3 and 4.
Records of activity
Records of the jobs you run (which tool, when, and the result or the reason it failed), and an audit log of account actions, such as connecting or disconnecting an account, sending a video or changing a setting, with who did it and when.
Technical information
When you use the website or app, our hosting providers process your IP address, browser type and the pages you request, to deliver the service and protect it from abuse.
2. How we use information
- To provide SIYai: store your videos and products, run the tools you start, and send videos where you ask.
- To keep accounts and the service secure: sign-in, two-step verification, and preventing and investigating abuse.
- To support you, and to send service messages such as sign-in codes and notices about changes to our terms.
- To meet legal obligations.
We don't sell personal information, we don't use it for advertising, and we don't use your videos to train AI models.
3. Google Drive
If you connect Google Drive, we ask Google for your email address and the drive.file permission, which lets SIYai see and change only the files and folders SIYai creates in your Drive. We create one folder there and put the videos you send (or, if you turn it on, every finished video) into it. We show your Google email so you can see which account is connected. The sign-in is stored encrypted with your workspace's own key. Disconnecting (Settings → Connections) removes our access at Google and deletes it; files already in your Drive stay there. SIYai's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
4. TikTok
SIYai uses TikTok's Login Kit and Content Posting API. You connect your own TikTok account, and we ask TikTok for exactly two permissions (scopes):
| Permission | What we receive | What we use it for | How long we keep it |
|---|---|---|---|
user.info.basic | Your open_id (an ID for your account in our app), your display name and a link to your profile picture (avatar). | To show the connected account in Settings and on the send screen, so you can see where a video will go. | While you are connected. After you disconnect, the open_id and display name stay only with your posting records (see below). |
video.upload | Permission to upload videos to your TikTok inbox. For each upload, TikTok returns a publish ID and a status. | To upload only the videos you confirm on the send screen, to your own TikTok inbox. You finish and post them in TikTok. | Posting consents and records: 3 years. |
Tokens
When you connect, TikTok gives us an access token and a refresh token. We store only the refresh token, encrypted with your workspace's own key, and it is replaced with a new one every time it is used. Access tokens are short-lived: we get a fresh one for each send you confirmed, use it only for that send, and don't store it. When you disconnect, we revoke our access at TikTok and delete the refresh token.
Posting consents and records
When you confirm a send, we record what you confirmed: who confirmed it and when, the TikTok account, the videos, and the text shown on the send screen. For each upload we record the publish ID TikTok returns, the status and any error code. We keep these records for 3 years, so we can show what you confirmed if there is ever a question about a post, and then delete them.
What we don't do with TikTok data
- We can't post publicly for you, and we don't. You post from TikTok.
- We don't read your TikTok videos, followers, likes, comments, messages or statistics. The permissions above don't allow it.
- We never sell TikTok data or use it for advertising, as TikTok's US Data Sharing Agreement requires.
- We don't build profiles of you or anyone else from TikTok data, and we don't combine it with other data for that purpose.
- We share TikTok data only with the providers that host SIYai for us (section 5), and only to run the service.
How to revoke access
- In SIYai: Settings → Connections → Disconnect. We revoke our access at TikTok and delete your tokens right away.
- In TikTok: Settings and privacy → Security → Manage app permissions, then remove SIYai. When TikTok tells us you removed access, we delete your tokens too.
Deleting TikTok data
Disconnecting deletes your tokens. To delete your posting records or anything else we hold about your TikTok account, email support@siyai.app from the address you use for SIYai. We will delete it, unless the law requires us to keep it or it is needed for an open dispute, and we will tell you if so.
5. Who we share information with
We share information only with the providers that run parts of SIYai for us, under contracts that limit their use of it to providing their service, and when the law requires it. If SIYai is ever sold or merged, your information would move to the new owner under this policy, and we would tell you first. Our providers today:
| Provider | What they do for us |
|---|---|
| Vercel | Hosts the website and the app. |
| Neon | Hosts our database. |
| Clerk | Sign-in and account security. |
| Cloudflare | Stores your videos, clips and photos (R2), and handles our domain and email routing. |
| Google Drive, when you connect it. Gemini models, only when you run an AI feature that uses them. | |
| OpenAI, Kling, Higgsfield | AI models, only when you run an AI feature that uses them. They receive the prompt and the files you chose for that job. |
| Kalodata | Supplies the product market data shown in Research. We send it no information about you. |
The free video tools (Overlay Studio, Batch combine and AI Edit) run on servers we operate. AI Edit's speech recognition runs there too; your clips are not sent to an outside AI service for it. TikTok and Google receive what you send to them when you ask us to.
6. How long we keep information
- Account and workspace information: while your account is open. Deleted within 30 days after you close your account or ask us to delete it.
- Videos in your Library, including ones you upload: until the "Kept until" date shown on each one (30 days by default), or sooner if you remove them. The file you uploaded is deleted within a day of us preparing its Library copy.
- Clips you upload only to run a tool: deleted after the job, at most a few days later.
- TikTok and Google Drive tokens: until you disconnect.
- TikTok posting consents and records: 3 years.
- Audit log: 2 years.
- Backups: deleted information can stay in encrypted backups until they roll off on their normal schedule.
Copies you sent to your Google Drive or your TikTok stay there, under your control.
7. Security
Information is encrypted in transit. TikTok and Google sign-ins are encrypted with a key for your workspace. The database keeps each workspace's data apart with row-level security, and only staff who need it can reach production systems. No system is perfectly secure; if we learn of a breach that affects you, we will tell you as the law requires. Report security issues to security@siyai.app.
8. Your choices and rights
- Disconnect TikTok or Google Drive at any time in Settings → Connections.
- Remove videos and products from your workspace at any time.
- Ask for a copy of your information, or to correct or delete it, by emailing support@siyai.app.
Depending on where you live, for example in California, the EU or the UK, you may have further rights, such as to object to or restrict some uses, or to complain to a data protection authority. We will answer requests within the time the law sets, and we won't treat you differently for making one. We don't sell or share personal information for cross-context behavioral advertising.
9. Cookies
We use cookies that are needed to sign you in and keep your session secure (set by Clerk), and a short-lived cookie that protects the Google Drive and TikTok connection steps. Your browser remembers your light or dark theme. We don't use advertising or cross-site tracking cookies.
10. Children
SIYai is not for anyone under 18. We don't knowingly collect information from children. If you believe a child has given us information, email support@siyai.app and we will delete it.
11. Where information is processed
We and our providers process information in the United States and other countries where they operate. When information moves across borders, we rely on the safeguards the law provides, such as standard contractual clauses.
12. Changes to this policy
We will post any change here with a new effective date. If a change is significant, we will also tell you by email or in the app before it takes effect.
Contact
SIYai. Questions about your account or this document: support@siyai.app. Legal notices: legal@siyai.app. Security reports: security@siyai.app.