This Privacy Policy explains how Unomera (https://tik-studio.com, https://tik-studio.com, https://api-staging.tik-studio.com) processes personal data when you use our web application and related services. That includes live production, overlays, show control, community/collaboration features, and official TikTok Content Posting API integrations.
1. Controller
The controller under the GDPR is the operator of Unomera. Contact: familie.koerner@levi-x.de.
2. Data we process
- Account data: email, optional display name, hashed password, plan/tenant information, audit events
- Usage data: login sessions (necessary app cookie), IP/device metadata in security logs, product settings
- Content data: recording plans, stream metadata, recordings/clips, transcripts, AI results, publish jobs and captions
- Live / event data: handles and connection settings you configure, ingested live events (gifts, chat messages, follows) processed server-side for overlays, bots and show cues — not via an official TikTok LIVE Chat or Gift API
- TikTok OAuth (Content Posting): open_id, display name/avatar (if provided), access/refresh tokens (encrypted at rest), granted scopes, publish status/IDs from TikTok
- Other official OAuth / provider connections: where you connect a provider through its documented API (for example Spotify allowlisting), we store tokens and account identifiers needed to run that feature
- Operator secrets (not browser tracking cookies): some capture or chatbot send paths may still store encrypted operator-supplied TikTok session material on the server. That is not a visitor tracking cookie. The target architecture for chat, bots and platform event data does not rely on TikTok user-session cookies in the browser.
3. Purposes and legal bases
- Contract performance / pre-contractual steps (Art. 6(1)(b) GDPR): providing the platform, recording, live overlays, clips, publishing
- Legitimate interests (Art. 6(1)(f) GDPR): security, abuse prevention, operations and product improvement
- Consent (Art. 6(1)(a) GDPR): where you enable optional features (e.g. OAuth scopes, optional operator session material)
- Legal obligations (Art. 6(1)(c) GDPR) where applicable
4. TikTok, events and processors
When you connect a TikTok account and upload videos, data is transmitted to TikTok (ByteDance) via the official Content Posting API. TikTok's privacy terms also apply. We do not claim an official TikTok LIVE Chat or Gift API. Live interaction uses ingest/webcast-style event processing and our own overlays/bots. We use hosting/infrastructure providers (servers, database, object storage, mail) to deliver the service. Provider and bot infrastructure processes events for your tenant; roles (owner, member, platform admin) limit who can see or change those settings.
5. Retention
Account data is kept for the lifetime of the account. Recordings and clips follow plan retention and are then deleted or made inaccessible. OAuth tokens are stored while the account remains connected; you can disconnect at any time. Logs are retained for a limited period for security and operations.
6. Cookies / session
Authentication uses a necessary first-party session cookie (ts_session, on staging ts_session_stg) required for login. We do not currently set additional tracking cookies for the core product. Chat, bots and platform event processing are designed without TikTok viewer session cookies in your browser. We do not use TikTok session cookies as a general tracking mechanism.
7. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability and objection, and you may withdraw consent. You also have the right to lodge a complaint with a supervisory authority.
8. Security
We apply technical and organisational measures (TLS, access controls, encryption of secrets/tokens, tenant isolation). Absolute security cannot be guaranteed.
9. Changes
We may update this policy when services or law change. The current version is always available at this URL.
10. Related documents
See also our Terms of Service.