GUCupload

Privacy Policy

Last updated: 19 July 2026

GUCupload (“the Service”) is a self-hosted tool operated by an independent creator in Seoul, Republic of Korea (“the Operator”). It has no public sign-up and no end users other than the Operator. This policy explains what data the Service touches and how it is handled.

1. Data the Service handles

DataSourcePurpose
OAuth access & refresh tokens Issued by TikTok, Instagram, Threads, YouTube after the account holder authorises access To upload and publish content to the authorising account
Basic profile info (display name, avatar, account id) Platform API, e.g. TikTok user.info.basic Shown in the panel so the Operator can confirm the correct destination account
Content files (video, images, captions) Created by the Operator To render and publish posts
Publish logs (timestamp, destination, post id, errors) Generated by the Service To trace what was published and diagnose failures
Public Threads posts matching the Operator's own keywords (post id, post text, author handle, timestamp, permalink) Threads Keyword Search API, queried with keywords the Operator configures So the Operator can find public conversations relevant to the account's topic and reply to them personally. Replies are written and published one by one after the Operator reviews them.

2. What the Service does not collect

3. Where data is stored

Tokens, content files and logs are stored on a single private server operated by the Operator, in a volume that is not publicly reachable. The server is a virtual machine rented from Oracle Cloud Infrastructure (Japan region), which acts as the hosting provider. Access to that server is restricted to the Operator, and the operating panel is protected by authentication.

4. Sharing and service providers

Data is never sold or rented, and is not shared for anyone else's purposes. Outbound transfers are limited to the following, all of them necessary to operate the Service:

There are no advertising or analytics integrations, and no data is transferred to any other party.

5. Retention and deletion

6. Your rights

Apart from the Operator's own account data, the only information the Service holds about other people is the public posts described in section 1 — post text, author handle, timestamp and permalink. If you are the author of such a post, you may ask what is held about you and ask for it to be deleted. Write to DKC260701@gmail.com or use the contact page; the entry will be located and deleted, and a reply sent, without undue delay.

7. Government and law enforcement requests

The Operator has never received a request from a public authority for personal data, and has never disclosed any. Should such a request arrive, the following policy applies:

Where the law permits it, the Operator will notify an affected person that their data has been requested.

7. Platform policies

Data obtained through platform APIs is used solely for the purposes described above and in accordance with each platform's developer terms and policies, including TikTok's Developer Terms of Service. See the TikTok integration page for the specific scopes requested and how each is used.

8. Changes

This policy may be updated as the Service changes; the date above reflects the most recent revision.

9. Contact

Privacy questions: DKC260701@gmail.com.