Last updated: 1 September 2026

Privacy Policy

1. Who is responsible

The data controller for Bouncr is the Bouncr project, maintained by GitHub user osilas1. Privacy requests can be submitted through the Bouncr website issue tracker. Please do not include confidential information in a public issue. No data protection officer has been appointed.

2. Data we process

When you connect TikTok, Bouncr processes your TikTok user identifier, granted scopes, access token, refresh token, and token expiry times. When you schedule content, Bouncr processes the selected video reference, caption, publishing time, privacy and interaction choices, commercial-content and AI labels, consent timestamp, upload progress, publish identifier, and API error or status information.

The desktop application keeps this information in a local SQLite database on the user's device. The video remains in the directory selected by the user until it is transferred to TikTok.

3. Why and on what basis

We process account and schedule data to provide the publishing service requested by the user, to secure the OAuth flow, and to diagnose failed transfers. Where the GDPR applies, the legal bases are performance of the user agreement and requested service, the user's explicit publishing instructions, compliance with applicable legal obligations, and legitimate interests in service and account security.

4. Recipients and international transfers

Video content, selected metadata, and authorization data are transmitted to TikTok only when needed to authorize or perform the user's requested action. TikTok processes data under its own privacy terms. This public website is hosted by GitHub Pages. GitHub may process connection and diagnostic data according to the GitHub Privacy Statement. These providers may process data outside the user's country under the safeguards described in their respective privacy terms.

5. Retention and deletion

OAuth tokens remain stored locally until the user disconnects TikTok, the authorization expires, or the local application data is removed. Finished, cancelled, or failed schedule records can be deleted from the dashboard. The Bouncr website does not create user accounts, run advertising analytics, or retain scheduler data. GitHub applies its own retention rules to Pages service logs.

6. Security

The desktop dashboard binds to the loopback interface by default, uses OAuth state validation and desktop PKCE, restricts selectable video paths, validates upload destinations, and excludes credentials and tokens from source control. No system can guarantee absolute security.

7. Your choices and rights

You can disconnect TikTok to revoke authorization and delete eligible schedule records in the dashboard. Depending on applicable law, you may also have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, and a complaint with a supervisory authority. Submit a request through the website issue tracker; use a minimal initial message if the request contains personal information.

8. Children

Bouncr is not directed to children below the minimum age required to use TikTok or to enter a binding agreement in their country.

9. Changes

Material changes will be shown with a new effective date and, where required, an additional notice.