Every permission requested is a read permission. Nothing is ever published on your behalf.
A private tool for a single account holder. No public sign-up, no other users, no shared data.
Disconnect from the platform's own settings at any time. Collection stops the moment you do.
Every permission, and what it is actually for
Listed in full rather than summarised, because a permission you cannot see the purpose of is one you should not grant.
TikTok
- user.info.basic
- Open ID, display name, avatar. Used once, so the dashboard can show whose account is connected.
- user.info.stats
- Follower, following, likes and video counts. Stored daily so growth reads as a trend.
- video.list
- Your own public videos: id, post time, description, duration, cover image, share link, and the view, like, comment and share counts.
Facebook Page
- pages_read_engagement
- Reach, views, engagement and video watch time on posts you published.
- read_insights
- Page level figures: follower movement, page views, post engagements.
- instagram_basic
- Account identity and your own published media.
- instagram_manage_insights
- Reach, saves, shares and watch time on your own posts.
The list that matters more
- Post, comment, message, follow or delete anything.
- Read your direct messages or anything you have not published.
- Collect data about anyone other than the account holder who connected the account.
- Sell, share or transfer your data to any third party.
- Use your data for advertising, audience building or model training.
- Ask for, see or store your password. Authorisation happens on the platform, never here.
Connect, read, disconnect
Connect
You click Connect on the platform you want. You are taken to that platform's own authorisation screen, where you can see exactly what is being asked for before you agree to anything.
It reads, daily
Once a day the app asks each platform for the numbers on posts you already published, and stores a snapshot. Platforms lag 24 to 48 hours, so nothing faster would tell you anything more.
Disconnect whenever
Revoke access from the platform's own settings, or ask for deletion here. Collection stops immediately, and stored data is removed within 30 days.
Where it lives and how to get rid of it
- Database
- Supabase, PostgreSQL
- Region
- ap-northeast-1, Tokyo
- Encryption
- In transit and at rest
- Row level security
- On, default deny
- Access tokens
- Server side secrets, never in the database
- Who can read it
- The account holder and the operator
Getting it deleted
Email unclelearnstocode@gmail.com and ask. Everything stored about your account is removed within 30 days and you get a confirmation when it is done.
Revoking access on the platform stops all future collection immediately, without waiting for anything from us. On TikTok that is Settings, then Security and permissions, then Manage app permissions. On Meta it is Settings, then Business Integrations.
The full detail is in the privacy policy.
Questions about your data?
A person answers, within five working days, and you can ask for a copy of everything stored about you at any time.