1. Scope
This policy covers the Service at this domain, including the data we receive when you connect a TikTok, Instagram or Facebook account. It does not cover those platforms themselves, which handle your data under their own policies.
2. Data we collect
Account data. When you sign in with Google we receive your name, email address and profile picture, and we store an identifier for your account.
Content data. Material you upload or create in the Service: video, images, audio, scripts, captions, prompts, brand information and the drafts and renders produced from them.
Publishing records. For each publish attempt we store which account it targeted, its status, the platform post identifier and URL where returned, and any error.
Usage and technical data. Log records of requests to the Service, including timestamp, action, outcome and the account that performed it, plus standard network information such as IP address and user agent.
Communications. Messages you send us, including support requests.
3. Data from connected platforms
When you connect a social media account, we receive only what the permissions you granted allow. We do not receive or store your password for any platform.
TikTok. With your authorisation we receive your TikTok open identifier, username, nickname and avatar, your account's posting settings and eligibility (such as available privacy options and remaining posting quota), and access and refresh tokens. If you grant the relevant permission we may also read statistics for your account and your public videos. We use this data to show you which account is connected, to build the posting screen correctly, and to publish content you ask us to publish. We do not sell it, use it for advertising, use it to build profiles of individuals, or share it with third parties other than the processors named in clause 6.
Instagram and Facebook. With your authorisation we receive your Instagram professional account identifier and profile details, or the list of Facebook Pages you administer together with the access token for the Page you select, and we use them for the same purposes.
4. How we use data
- To operate the Service and provide the features you use.
- To publish content to the accounts you have connected, at your instruction.
- To generate content with AI tools where you ask us to, by sending your prompts and related material to the model providers named in clause 6.
- To secure the Service: authentication, access control, abuse and fraud prevention, and audit logging.
- To provide support and respond to your requests.
- To meet legal, accounting and regulatory obligations.
We do not use your content or platform data to train our own foundation models, and we do not sell personal data.
5. Legal bases
Where data protection law requires a legal basis, we rely on: performance of our contract with you, for operating the Service; your consent, for connecting a platform account and for publishing on your behalf, which you may withdraw at any time; our legitimate interests, for security, abuse prevention and service improvement; and legal obligation, where the law requires retention or disclosure.
7. International transfers
Hiip operates from Singapore and our providers may process data in other countries. Where data leaves your jurisdiction we rely on appropriate safeguards, including contractual protections with our processors.
8. Security
- Data we collect is encrypted, at rest and in transit.
- Data in transit uses HTTPS, SFTP and TLS 1.2 or above. SSL v2 and v3 are not permitted.
- Accounts are individual, with complex passwords, and multi-factor authentication is required for critical systems.
- Application audit logs record the actor, action, timestamp and outcome, and are reviewed at least every 7 days.
- Access grants are reviewed at least every 12 months, inactive accounts are reviewed monthly and disabled after 45 days of inactivity, and access is revoked promptly when a person leaves.
- Third-party vulnerability testing is carried out every 8 to 12 months, and software is kept patched under our update policy.
- Access and refresh tokens for connected platforms are stored encrypted and used only to perform actions you have asked for.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority where the law requires it.
9. Retention
- Account and content data — kept while your account is active, and deleted within 30 days of a deletion request or of account closure, unless we must keep it longer by law.
- Platform tokens and profile data — deleted when you disconnect the account, when you revoke access at the platform, or when your account is closed.
- Publishing records — kept for up to 24 months as a record of what was published on your behalf, then deleted or anonymised.
- Security and audit logs — kept for up to 12 months.
10. Your rights
Subject to applicable law, you may ask us to access, correct, delete, restrict or export your personal data, object to processing based on legitimate interests, and withdraw consent at any time. Exercising these rights will not disadvantage you in the Service.
11. Deleting your data
Email contact@hiip.asia with the subject line Data Deletion Request, from the address on your account. We permanently delete the personal data we hold about you within 30 days, except where the law requires us to keep specific records, and we confirm to you when it is done.
Deleting your data with us does not remove posts already published to a platform. Those live on that platform and must be deleted there.
12. Revoking platform access
You can disconnect a connected account at any time from within the Service, which deletes the stored tokens for it and stops all further publishing. You can also revoke our access from the platform itself:
- TikTok — Profile, then Settings and privacy, then Security and permissions, then Manage app permissions.
- Instagram and Facebook — Settings, then Apps and websites, then remove the app.
14. Children
The Service is not directed at children and is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy. The effective date at the top of this page shows when the current version took effect, and we will notify you of material changes in the Service or by email where we hold an address for you.
16. Contact
Hiip, 10 Marina Boulevard #08-01, MBFC Tower 2, Singapore 018983.
Email: contact@hiip.asia
Telephone: +65 9231 5303
See also our Terms of Service.