Privacy Policy

Effective date: 24 July 2026 — Data controller: Zylean AS

This Privacy Policy describes how Zylean AS (“CuriosityLoop”, “we”, “us”, or “our”) collects, uses, and protects information when you use the CuriosityLoop web application at https://curiosity-loop.com. Zylean AS is the data controller within the meaning of the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

1. Information we collect

1.1 TikTok account information

When you connect your TikTok account using TikTok Login Kit, we receive the following information with your permission:

  • TikTok Open ID (a unique, anonymised account identifier)
  • Display name and avatar image URL
  • OAuth access token and refresh token (encrypted before storage)
  • Token expiry timestamps
  • Granted permission scopes

We do not receive your TikTok password, email address, phone number, followers list, messages, or analytics.

1.2 Video and publishing data

  • Generated video metadata (title, caption, hashtags, duration)
  • Publishing settings you select (privacy level, interaction options)
  • TikTok publish ID returned by the Content Posting API
  • Publication status history (processing, succeeded, failed)

1.3 Technical and security logs

  • Server-side structured logs for error diagnosis (sanitised — no tokens or credentials are ever logged)
  • Request identifiers for log correlation
  • Rate-limiting state (IP-based, held in memory only, not stored permanently)

2. Legal bases for processing (GDPR Article 6)

We process personal data on the following legal bases:

  • Consent (Article 6(1)(a)): When you click “Sign in with TikTok” and authorise the connection, you give us your explicit consent to receive and store your TikTok account information and OAuth tokens. You may withdraw this consent at any time — see Section 7 below for how consent withdrawal differs from account disconnection.
  • Legitimate interests (Article 6(1)(f)): We process technical log data and rate-limiting state to operate the service securely, detect abuse, and diagnose errors. Our legitimate interest in maintaining a secure service is balanced against your right to privacy; we minimise data collected and retain logs for no more than 90 days.
  • Legal obligation (Article 6(1)(c)): We may retain or disclose data to the extent required by applicable Norwegian or EU law.

3. How we use your information

  • To authenticate your TikTok account connection
  • To display videos pending review in your dashboard
  • To submit approved videos to your connected TikTok account
  • To refresh your access token automatically before it expires (using your stored refresh token)
  • To track publishing status from TikTok
  • To notify our workflow system (n8n) of publishing events
  • To protect against unauthorised access and duplicate submissions
  • To diagnose and resolve technical errors

4. Data storage and processors

We use the following third-party services to operate CuriosityLoop:

  • TikTok — OAuth authentication and content publishing. Your interaction with TikTok’s authorization pages is governed by TikTok’s own privacy policy.
  • Supabase — Database and file storage for video assets and publishing records, hosted on AWS infrastructure in the EU Central (Frankfurt, Germany) region. Data stored in Supabase remains within the European Economic Area.
  • Replit — Hosting and deployment of this web application.
  • n8n — Private workflow automation for video generation orchestration. Receives event notifications (video IDs and status codes only — no tokens).
  • OpenAI — Used in the content generation pipeline for script drafting and research assistance.
  • ElevenLabs — Used in the content generation pipeline for voiceover production.
  • Creatomate — Used in the content generation pipeline for video assembly and rendering.

5. International data transfers

Zylean AS is registered in Norway. Our Supabase database is hosted in the EU Central (Frankfurt, Germany) region and does not involve an international transfer outside the EEA. However, several other service processors are based in the United States or operate infrastructure outside the European Economic Area (EEA):

  • Replit — cloud infrastructure operated in the United States
  • OpenAI — United States
  • ElevenLabs — United States
  • TikTok — international; subject to TikTok’s own transfer mechanisms
  • Creatomate — European Union (no transfer outside EEA)

Where personal data is transferred to a country outside the EEA that does not benefit from an adequacy decision, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or the equivalent mechanism required by applicable law, to ensure an adequate level of data protection.

6. Token security

OAuth access and refresh tokens are encrypted using AES-256-GCM immediately upon receipt, before being stored in HTTP-only, Secure, SameSite=Lax session cookies. The cookies are sealed using iron-session with a 256-bit secret. Tokens are never:

  • Stored in plaintext anywhere, including databases or logs
  • Accessible via JavaScript on the client side
  • Transmitted to third parties other than TikTok’s official API

Access tokens expire as determined by TikTok (typically 24 hours). We use your stored refresh token to obtain a new access token automatically before expiry. Refresh tokens expire after a longer period (typically 365 days). When your session cookie expires (7 days of inactivity) or when you disconnect your account, all token material is removed from the session.

7. Your rights and how to exercise them

Under the GDPR you have the following rights in relation to your personal data:

  • Right of access — obtain a copy of the data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — request deletion of your personal data
  • Right to restriction — limit the processing of your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — you may withdraw your consent to processing at any time, without affecting the lawfulness of processing carried out before withdrawal

Withdrawing consent vs. disconnecting your TikTok account

These are two distinct actions:

  • Disconnecting your TikTok account (via Dashboard → Settings → Disconnect) revokes our OAuth access token with TikTok, destroys your local session, and stops CuriosityLoop from being able to publish to your account. It does not automatically delete your video records from our database.
  • Withdrawing consent and requesting data erasure requires contacting us at contact@zylean.com with the subject line “Privacy Request”. We will delete your personal data within 30 days, subject to any legal retention obligations.

We will respond to all rights requests within one month, as required by GDPR Article 12.

8. Data retention

  • Session cookies expire after 7 days of inactivity or when you disconnect your account
  • Video and publishing records are retained until you request deletion
  • Technical logs are retained for up to 90 days
  • Rate-limiting state is held in memory only and is not persisted

9. Security safeguards

  • All data is transmitted over HTTPS/TLS
  • OAuth tokens are encrypted at rest using AES-256-GCM with a 256-bit key
  • Session cookies are HTTP-only, Secure, SameSite=Lax, sealed with iron-session
  • Server-side input validation on all API routes
  • CSRF protection via cryptographically secure OAuth state parameter
  • Rate limiting on authentication and publishing routes
  • Content Security Policy and additional HTTP security headers on all responses
  • TikTok access token revocation is performed on disconnect

We do not claim any specific certification. We implement security controls proportionate to the nature and sensitivity of the data we handle.

10. Right to lodge a complaint

If you believe we have processed your personal data in a manner that does not comply with applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your country of residence.

In Norway, the supervisory authority is:

Datatilsynet (Norwegian Data Protection Authority)
Website: www.datatilsynet.no
Telephone: +47 74 07 70 00
Post: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, Norway

If you reside in another EEA country, you may also contact the supervisory authority in your country of residence.

11. Changes to this policy

We may update this policy when our practices change. Material changes will be posted on this page with an updated effective date. Continued use after notice constitutes acceptance.

12. Data controller contact

Zylean AS
Organisation number: 937 332 459
Tovdalsvegen 111, 4363 Brusand, Norway
contact@zylean.com