ArtheaArthea
arthea.ai
Legal

Opal Privacy Policy

Effective 12 August 2026

This Privacy Policy explains how Opal, a content operations product built and operated by Arthea (“Arthea”, “we”, “us”), handles data when you connect a social account to it. Opal lets you plan, review, approve and publish your brand’s own posts to the accounts you connect, from one content calendar. It publishes only what you have approved, and it does not build advertising profiles or sell data.

1. Who this applies to

It applies to anyone who uses Opal and to any social account connected to it. Connecting an account is always done by the person who owns that account or is authorized to manage it, through the platform’s own authorization screen. Opal never asks for, receives or stores your platform password.

2. Data we collect

When you connect an account, Opal collects only what publishing requires:

  • Authorization data. The OAuth access and refresh tokens issued by the platform when you authorize Opal, so it can act on the account you connected until you disconnect it.
  • Basic account information. The connected account’s identifier and its public display name and avatar, shown so you can confirm the correct account is linked.
  • The content you schedule. The captions, images and scheduling details of the posts you choose to publish through Opal, plus the result the platform returns for each publish.
  • Account data. The email address used to sign in to Opal, and an audit log of privileged actions.

3. The TikTok permissions Opal requests

Opal uses TikTok’s Login Kit and Content Posting API. These are the only permissions it asks for, and this is exactly what each one is used for:

user.info.basicLogin Kit

What it grants. The open ID, display name and avatar of the account that authorized Opal.

How Opal uses it. Shown on the Channels screen so you can confirm the right account is connected, and stored so Opal knows which account a scheduled post belongs to. Nothing else is read from the profile.

video.publishContent Posting API

What it grants. Permission to post content directly to the profile of the account that authorized Opal.

How Opal uses it. Used once per post, at the scheduled time, to publish a photo post you already reviewed and approved inside Opal. Opal never posts anything you have not approved.

video.uploadContent Posting API

What it grants. Permission to send content to the account as a draft for the creator to finish in TikTok.

How Opal uses it. Not used. TikTok includes this scope with the Content Posting API by default and it cannot be removed from the request. Opal makes no upload-as-draft call.

Opal accesses and uses TikTok data solely to provide the publishing feature described above, in accordance with the TikTok Developer Terms of Service and the TikTok Platform Policies. It does not request, and cannot read, your followers, your direct messages, your video list, your analytics, your contacts or any other TikTok data.

4. How we use data

We use the data above only to operate the product, specifically to:

  • Publish the posts you have approved to the accounts you connected.
  • Show connection status and the identity of each linked account.
  • Keep sessions authenticated and refresh access tokens so publishing does not silently stop.
  • Notify you when a connection is expiring or a publish has failed.
  • Maintain an audit trail of privileged actions for security.

5. What we never do

  • We do not sell your data, and we do not share it for anyone else’s purposes.
  • We do not use platform data for advertising, profiling or training models.
  • We do not post, delete or change anything on a connected account that you have not approved in Opal.
  • We do not read data unrelated to publishing, and we do not request scopes we do not use.

6. How data is stored and protected

  • Access and refresh tokens are encrypted at rest and are never exposed to the browser.
  • All traffic is served over HTTPS with strict transport security.
  • Signing in requires an allowlisted email, a one-time code and two-factor authentication.
  • There are no public endpoints that expose connected-account data.

7. Sharing

Data is transmitted only to the platform APIs themselves (for example TikTok, Instagram, Facebook, Threads, X or LinkedIn) to carry out the publishing you asked for, and to the infrastructure providers that host the service under confidentiality obligations. We may disclose data if required by law.

8. Retention, revocation and deletion

Tokens and connection data are kept only while an account stays connected. You can revoke Opal’s access at any time, either by disconnecting the account inside Opal or by removing Opal from the platform’s own app or security settings. For TikTok this is under Settings and privacy, then Security and permissions, then Manage app permissions. On disconnection the stored tokens for that account are deleted. To request deletion of the remaining data held for your account, write to the address below and we will action it within 30 days. Posts already published stay on the platform until you remove them there.

9. Changes

We may update this Privacy Policy as the product evolves. Material changes take effect when the revised policy is posted at this address, with an updated effective date above.

10. Contact

For any question about this policy or the data Opal holds, contact privacy@arthea.ai.