TikTok integration
Davdigi Studio schedules and publishes videos to TikTok accounts that our client organisations own or are authorised to manage. This page sets out precisely what the integration does, permission by permission.
Connecting an account
- A signed-in user opens Social Accounts and chooses TikTok.
- They are sent to TikTok's own login and consent screen. Credentials are entered on TikTok, never on our site, so we never see a TikTok password.
- After the user approves, TikTok returns an access token to
studio.davdigi.com/integrations/social/tiktok. The token is stored in our database and used only to carry out actions the user asks for. - The account then appears in the workspace, labelled with its display name and profile picture, and can be selected as a target for posts.
Disconnecting is one click on the same screen, and deletes the stored token immediately.
Permissions we request, and why
| Permission | What we do with it |
|---|---|
user.info.basic |
Read the open ID, display name, and profile picture of the connected account, so the interface can show which account a post will be published to. |
user.info.profile |
Read the account's username, so several connected TikTok accounts in the same workspace can be told apart reliably. |
user.info.stats |
Read follower, following, likes, and video counts for the connected account, shown on the analytics screen. |
video.list |
List the account's own videos and read their view, like, comment, and share counts, so the analytics screen can report on published content. |
video.upload |
Send a video file to TikTok as a draft, for a creator to review and post from the TikTok app. |
video.publish |
Publish a scheduled video directly, when the user chose direct publishing and set a time for it. |
All six are used by the product. If TikTok grants fewer than the set above, the connection is refused with an explanation rather than half-working.
How publishing works
- A user composes a post: caption, the video, and the TikTok account it should go to. The TikTok-specific options (privacy level, comment, duet and stitch settings, and the commercial content disclosure) are set here.
- The user chooses a publish time and saves. The post sits in the calendar until then.
- At that time our scheduler sends the video to TikTok using the stored token, then records the result on the post.
- If TikTok rejects it, the reason TikTok returned is shown on the post so it can be fixed and queued again.
Nothing publishes without a person choosing it
Every video sent to TikTok comes from a post a user composed and scheduled. There is no automatic reposting, no content generated and published without review, and no bulk activity beyond the rows a user entered and confirmed.
What we never do
- We do not read the For You feed or any other user's content.
- We do not follow, unfollow, like, comment, or send messages.
- We do not collect data about TikTok users other than the connected account itself.
- We do not sell, rent, or share TikTok data with advertisers or data brokers.
- We do not use TikTok data to train machine learning models.
Data handling and deletion
The TikTok data we hold is: the access and refresh token, the account's open ID, display name, username and profile picture, the posts published through the tool, and the metrics read back for those posts. It is stored in a private database on our own server and is not exposed to the public internet.
Disconnecting the account deletes the token at once. A full deletion of the workspace and its data can be requested at any time; the procedure is on the Data Deletion Instructions page. The complete statement is in our Privacy Policy, and the terms of use in our Terms of Service.
Content published to TikTok remains subject to TikTok's Community Guidelines and Terms of Service.
