Privacy Policy
Last updated: 19 July 2026
GUCupload (“the Service”) is a self-hosted tool operated by an independent creator in Seoul, Republic of Korea (“the Operator”). It has no public sign-up and no end users other than the Operator. This policy explains what data the Service touches and how it is handled.
1. Data the Service handles
| Data | Source | Purpose |
|---|---|---|
| OAuth access & refresh tokens | Issued by TikTok, Instagram, Threads, YouTube after the account holder authorises access | To upload and publish content to the authorising account |
| Basic profile info (display name, avatar, account id) | Platform API, e.g. TikTok user.info.basic |
Shown in the panel so the Operator can confirm the correct destination account |
| Content files (video, images, captions) | Created by the Operator | To render and publish posts |
| Publish logs (timestamp, destination, post id, errors) | Generated by the Service | To trace what was published and diagnose failures |
| Public Threads posts matching the Operator's own keywords (post id, post text, author handle, timestamp, permalink) | Threads Keyword Search API, queried with keywords the Operator configures | So the Operator can find public conversations relevant to the account's topic and reply to them personally. Replies are written and published one by one after the Operator reviews them. |
2. What the Service does not collect
- No account passwords — authorisation happens entirely on the platform's own site.
- Beyond the public posts described above, no data belonging to other users of any platform: no follower lists, no private or restricted content, no direct messages, no email addresses or contact details, no profile analytics about third parties.
- Public posts retrieved by keyword search are never used to build profiles of their authors, never used for advertising or targeting, and never combined with data from any other source.
- No visitor tracking on this website: no analytics scripts, no advertising pixels, no cookies set by these pages.
3. Where data is stored
Tokens, content files and logs are stored on a single private server operated by the Operator, in a volume that is not publicly reachable. The server is a virtual machine rented from Oracle Cloud Infrastructure (Japan region), which acts as the hosting provider. Access to that server is restricted to the Operator, and the operating panel is protected by authentication.
4. Sharing and service providers
Data is never sold or rented, and is not shared for anyone else's purposes. Outbound transfers are limited to the following, all of them necessary to operate the Service:
- The destination platform's own API, when publishing — for example sending a rendered video to TikTok's upload endpoint, or a reply to the Threads publishing endpoint.
- Anthropic PBC (Claude API), as a processor. The text of a retrieved public post is sent so the model can judge whether a reply would be appropriate and draft one for the Operator to review. Only the post text is sent — no tokens, no account identifiers, no author contact details. Under Anthropic's commercial terms, API inputs are not used to train models.
- Oracle Cloud Infrastructure, as the hosting provider for the server described above.
There are no advertising or analytics integrations, and no data is transferred to any other party.
5. Retention and deletion
- Access tokens are kept only while the account is connected. Disconnecting from the panel deletes them immediately.
- Revoking access from the platform's own settings invalidates the tokens at once and stops all publishing.
- Basic profile information is used for on-screen display only and is not retained beyond the current session's cache.
- Content files and publish logs are retained on the Operator's server for record-keeping and can be deleted by the Operator at any time.
- Public posts retrieved by keyword search are held in a rolling buffer capped at 600 entries; once the cap is reached the oldest entries are discarded automatically. Nothing is archived elsewhere. An author who no longer wishes their post to appear can request removal via the contact page, or through the data deletion callback registered with the platform, and the entry is deleted.
6. Your rights
Apart from the Operator's own account data, the only information the Service holds about other people is the public posts described in section 1 — post text, author handle, timestamp and permalink. If you are the author of such a post, you may ask what is held about you and ask for it to be deleted. Write to DKC260701@gmail.com or use the contact page; the entry will be located and deleted, and a reply sent, without undue delay.
7. Government and law enforcement requests
The Operator has never received a request from a public authority for personal data, and has never disclosed any. Should such a request arrive, the following policy applies:
- Legality is reviewed first. No data is disclosed before the request has been checked against applicable law — whether the authority has jurisdiction, whether the legal basis is stated, and whether the process used is the one the law requires.
- Unlawful or overbroad requests are challenged. A request that lacks a valid legal basis, or that asks for more than the law permits, is refused or contested rather than complied with, and legal advice is sought where the position is unclear.
- Data minimisation. Where disclosure is legally required, only the narrowest set of data that satisfies the request is provided. Nothing beyond the specific items named is handed over.
- Documentation. Each request is recorded — date received, requesting authority, stated legal basis, data disclosed or refused, and the reasoning — and the record is retained.
Where the law permits it, the Operator will notify an affected person that their data has been requested.
7. Platform policies
Data obtained through platform APIs is used solely for the purposes described above and in accordance with each platform's developer terms and policies, including TikTok's Developer Terms of Service. See the TikTok integration page for the specific scopes requested and how each is used.
8. Changes
This policy may be updated as the Service changes; the date above reflects the most recent revision.
9. Contact
Privacy questions: DKC260701@gmail.com.