Ember Content Desk

Content Desk Privacy Notice

How Ember Content Desk handles creator and TikTok data.

1. Controller

Geordan Gesink
Haesselackerstraße 3
69198 Schriesheim
Germany
Email: support@emberalarm.com

2. Scope

This notice applies to the Ember Content Desk macOS application, its TikTok connection, the short-lived photo delivery service, and the Content Desk pages on emberalarm.com. It supplements the general Ember website privacy policy.

3. TikTok data and purposes

Content Desk processes only the TikTok data needed for features you choose:

  • Basic profile: TikTok open ID, display name, nickname, and avatar, used to show and bind the account you authorized.
  • Authorization: granted scopes, access token, refresh token, expiry times, and revocation state, used to make authorized API calls and keep the connection working.
  • Recent videos: public video identifiers and the public metadata returned by TikTok, used only for the optional analytics view.
  • Publishing: your approved photos, title, caption, hashtags, privacy and interaction choices, disclosures, consent record, TikTok publish ID, processing status, and error state, used to submit and track the one post you approved.

The legal basis is performance of the service you request and our legitimate interests in securing the authorization flow, preventing duplicates, documenting consent, and diagnosing failures. TikTok asks for your separate scope consent. You can refuse optional scopes or disconnect at any time.

4. Storage and retention

  • TikTok access and refresh tokens are stored in your macOS Keychain, not in the public app bundle. The secure exchange service processes codes and tokens transiently and does not retain them after the response. The media service also validates the connected creator's access token and open ID with TikTok for each upload, without storing either value.
  • Approved post records, account binding, consent and submission status remain in the local Content Desk database until you remove the local workspace or delete the records in the app.
  • Each approved photo is copied to private storage solely so TikTok can fetch it. The public route expires after one hour and the stored object is deleted after expiry.
  • Security and request logs are limited to what Vercel, Supabase, TikTok, and our infrastructure need to deliver and protect the service under their retention schedules. We do not intentionally log OAuth tokens or uploaded image bodies.

5. Recipients and international transfers

TikTok receives the photos and publishing choices you deliberately submit. Vercel hosts the website, exchange endpoints, and public media route. Supabase provides private short-lived object storage. These providers may process data outside the European Economic Area under their applicable contractual safeguards. We do not sell personal data or use TikTok data for advertising.

6. Security and creator control

The desktop authorization flow uses state and PKCE. Client secrets stay on the server, creator credentials stay in macOS Keychain, hosted photos use digest-locked URLs, and Direct Post requires a fresh final review. Changed media, expired approvals, mismatched accounts, and duplicate submissions are blocked.

7. Disconnect, deletion, and rights

Disconnecting TikTok revokes the connection and removes its local Keychain credential. Removing the local Content Desk workspace deletes its local database and generated files. Short-lived hosted photos expire automatically. You can also revoke Ember from TikTok's connected-app settings.

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and may complain to a data-protection authority. Contact support@emberalarm.com. We may request limited information to verify the request.

8. Changes

We update this notice when the real Content Desk data flow changes. A material change is published before it applies to new TikTok connections.

Last updated: August 23, 2026.