Privacy Policy
Last updated: September 28, 2026
This Privacy Policy describes how ContentMCP, operated by Noi That Viva, collects, uses, and protects information when you use our TikTok management platform.
1. Who We Are
ContentMCP is developed and operated by Noi That Viva, a technology company based in Ho Chi Minh City, Vietnam. This platform integrates with TikTok's developer platform through: Login Kit, Content Posting API, Local Service API, Share Kit, and Webhooks.
Contact: hoiai.com.vn@gmail.com · contentmcp.hoiai.com.vn
2. Information We Collect
When you authorize ContentMCP via TikTok OAuth 2.0, we collect:
| Data Type | Source | Purpose | Retention |
|---|---|---|---|
| TikTok Open ID (user_id) | Login Kit | Account identification for token binding | Until authorization is revoked |
| Display name & avatar URL | user.info.basic | Show in user dashboard | Until revoked |
| Follower/profile stats | user.info.profile, user.info.stats | Channel analytics for the user | Session only |
| Access Token (encrypted) | OAuth flow | Authenticate API calls on user's behalf | Until expiry (24h, auto-refreshed) |
| Refresh Token (encrypted) | OAuth flow | Renew access tokens automatically | Until expiry (365 days) |
| TikTok Shop product data | local.product.manage | View and update the user's shop listings | Not stored — fetched on demand |
| TikTok Shop orders & vouchers | local.shop.manage, local.voucher.manage | Manage the user's shop operations | Not stored — fetched on demand |
| Video publish ID | Content Posting API | Track post status after publishing | 30 days in change log |
We do not collect: passwords, private messages, followers list, browsing history, or any data outside the granted scopes.
3. How We Use TikTok Data
All data accessed via TikTok API is used solely to provide ContentMCP's services to the authorized user:
Content Posting API
video.upload— Upload product showcase videos (MP4) to TikTok's servers before publishingvideo.publish— Publish approved videos to the user's TikTok profilevideo.list— List published videos and check their processing status
TikTok Shop Management (Local Service API)
local.product.manage— View, create, and update product listings in the user's TikTok Shoplocal.shop.manage— Read shop performance metrics and order informationlocal.voucher.manage— Create and manage promotional vouchers for the user's shop
Account Verification
user.info.basic,user.info.profile,user.info.stats— Identify and display the authorized TikTok account in the dashboard
Every write action (posting content, updating products, creating vouchers) requires explicit user confirmation before execution. No automated actions are taken without human oversight.
4. Data Sharing
We do not sell, rent, or share TikTok user data with any third party, except:
- TikTok (ByteDance): API calls are sent to
open.tiktokapis.comandopen-api.tiktokglobalshop.comper TikTok Developer Platform requirements - Legal requirements: When compelled by applicable law or government authority
Data received from TikTok APIs is used in a manner consistent with the TikTok API Terms of Service.
5. Data Security
- Fernet encryption (AES-128-CBC + HMAC-SHA256): All access tokens and refresh tokens are encrypted before storage — never stored in plaintext
- HTTPS only: All communications use TLS/SSL encryption
- OAuth 2.0 PKCE: Authorization uses Proof Key for Code Exchange to prevent interception attacks
- Scoped access: The platform only requests the minimum scopes necessary for its features
- Audit logging: All write operations are recorded for accountability
6. TikTok Scopes Declared
| Product | Scope | Usage |
|---|---|---|
| Login Kit | user.info.basicuser.info.profileuser.info.stats | Identify the authorized TikTok account and display channel analytics |
| Content Posting API | video.uploadvideo.publishvideo.list | Upload and publish marketing content; list and check post status |
| Local Service API | local.product.managelocal.shop.managelocal.voucher.manage | Manage the user's TikTok Shop products, orders and promotions |
7. User Rights
As a ContentMCP user, you have the right to:
- Revoke access: Go to TikTok Settings → Security → Manage app permissions → revoke ContentMCP at any time
- Request data deletion: Email hoiai.com.vn@gmail.com — we will delete all stored tokens and data within 30 days
- Access your data: Request a summary of data stored in connection with your account
- Withdraw consent: You may stop using ContentMCP and revoke authorization at any time without penalty
8. Children's Privacy
ContentMCP is not intended for users under 13 years of age. We do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this Privacy Policy periodically. The "Last updated" date at the top of this page will reflect any changes. Continued use of ContentMCP after changes constitutes acceptance of the updated policy.
10. Contact
- Email: hoiai.com.vn@gmail.com
- Website: contentmcp.hoiai.com.vn
- Location: Ho Chi Minh City, Vietnam