Privacy Policy

Last updated: September 28, 2026

This Privacy Policy describes how ContentMCP, operated by Noi That Viva, collects, uses, and protects information when you use our TikTok management platform.

Summary: ContentMCP is a platform that helps businesses manage their TikTok content and TikTok Shop operations. We do not sell user data, and only access TikTok accounts after explicit authorization via OAuth 2.0. Users can revoke access at any time.

1. Who We Are

ContentMCP is developed and operated by Noi That Viva, a technology company based in Ho Chi Minh City, Vietnam. This platform integrates with TikTok's developer platform through: Login Kit, Content Posting API, Local Service API, Share Kit, and Webhooks.

Contact: hoiai.com.vn@gmail.com · contentmcp.hoiai.com.vn

2. Information We Collect

When you authorize ContentMCP via TikTok OAuth 2.0, we collect:

Data TypeSourcePurposeRetention
TikTok Open ID (user_id)Login KitAccount identification for token bindingUntil authorization is revoked
Display name & avatar URLuser.info.basicShow in user dashboardUntil revoked
Follower/profile statsuser.info.profile, user.info.statsChannel analytics for the userSession only
Access Token (encrypted)OAuth flowAuthenticate API calls on user's behalfUntil expiry (24h, auto-refreshed)
Refresh Token (encrypted)OAuth flowRenew access tokens automaticallyUntil expiry (365 days)
TikTok Shop product datalocal.product.manageView and update the user's shop listingsNot stored — fetched on demand
TikTok Shop orders & voucherslocal.shop.manage, local.voucher.manageManage the user's shop operationsNot stored — fetched on demand
Video publish IDContent Posting APITrack post status after publishing30 days in change log

We do not collect: passwords, private messages, followers list, browsing history, or any data outside the granted scopes.

3. How We Use TikTok Data

All data accessed via TikTok API is used solely to provide ContentMCP's services to the authorized user:

Content Posting API

TikTok Shop Management (Local Service API)

Account Verification

Every write action (posting content, updating products, creating vouchers) requires explicit user confirmation before execution. No automated actions are taken without human oversight.

4. Data Sharing

We do not sell, rent, or share TikTok user data with any third party, except:

Data received from TikTok APIs is used in a manner consistent with the TikTok API Terms of Service.

5. Data Security

6. TikTok Scopes Declared

ProductScopeUsage
Login Kituser.info.basic
user.info.profile
user.info.stats
Identify the authorized TikTok account and display channel analytics
Content Posting APIvideo.upload
video.publish
video.list
Upload and publish marketing content; list and check post status
Local Service APIlocal.product.manage
local.shop.manage
local.voucher.manage
Manage the user's TikTok Shop products, orders and promotions

7. User Rights

As a ContentMCP user, you have the right to:

8. Children's Privacy

ContentMCP is not intended for users under 13 years of age. We do not knowingly collect personal data from children.

9. Changes to This Policy

We may update this Privacy Policy periodically. The "Last updated" date at the top of this page will reflect any changes. Continued use of ContentMCP after changes constitutes acceptance of the updated policy.

10. Contact