This app is pending TikTok review. Posts published now will be visible only to you until review completes.

Privacy Policy

Last updated 9 September 2026

Who is responsible for your data

Steepfeed is operated by Ising Digital Sàrl, Route de Cuarnens 3b, 1308 La Chaux (Cossonay), Switzerland. We are the controller for the personal data described here, under the Swiss Federal Act on Data Protection (nFADP) and, where it applies, the EU General Data Protection Regulation. Write to us at the address above or at contact@isingdigital.ch.

Steepfeed lets you generate images with AI and publish ones you approve to a TikTok account you control. This policy describes what we receive, what we send to TikTok, who processes it for us, where it goes, how long we keep it, and how you delete it.

You must be 13 or older

Steepfeed is not for children. You must be at least 13, and old enough to hold a TikTok account in your country — which is higher than 13 in some places. We do not knowingly collect data from anyone younger; if you believe a child has an account here, email us and we will delete it.

What we collect, and why

  • Your account. The email address you sign up with, and an authentication credential handled by our authentication provider. We never see your password in plain text. Basis: performance of our contract with you.
  • What you type. Your project names and the brand context you write for them, the image prompts you write, and the captions you write or edit. Basis: performance of our contract.
  • What you upload. Screenshots and brand reference material — logos, product shots, style references — that you add to a project. Whatever is visible in an image you upload is uploaded with it, so do not upload a screenshot showing someone else's personal data unless you are entitled to. Basis: performance of our contract.
  • Images we generate for you. Every candidate image produced from your prompt, including the ones you do not publish. Basis: performance of our contract.
  • Your TikTok profile. When you connect an account, TikTok gives us your open_id, union id, username, display name and avatar URL. Each time you open the composer we ask TikTok for your current nickname, avatar and available privacy settings, so that the form shows the truth rather than a stale copy.
  • TikTok access credentials. An access token and a refresh token. Both are encrypted before they are stored, and they are only ever used on our server.
  • Post records. For each post you compose: the caption, the privacy level, your comment and commercial-content choices, the time you scheduled it for if you scheduled one, and the status TikTok reports back.

Our hosting provider also records ordinary server logs — IP address, timestamp and the request made — which we use to keep the service running and secure and which are deleted on their rolling schedule. Basis: our legitimate interest in operating a working, secure service.

We do not run advertising, we do not profile you, we do not make automated decisions that produce legal or similarly significant effects about you, and we do not sell or share your data with anyone for their own purposes. We ask TikTok only for the permissions needed to read your basic profile and publish a post you approved — we do not request or receive analytics about how a post performed.

Cookies

Steepfeed sets no tracking, advertising or analytics cookies, and we run no third-party analytics. The only cookies we set are the session cookies that keep you signed in; they are strictly necessary for the service to work, so we do not ask for consent to them. Signing out or deleting them logs you out.

What we send to TikTok, and when

Nothing is sent to TikTok until you approve a specific post. Generating an image, editing a caption or changing a setting sends nothing, and images are never pre-uploaded. Steepfeed does not generate and post on its own: every post that reaches TikTok is one you composed, reviewed and approved.

You then choose when it goes out. Publish now sends it immediately. Alternatively you can schedule the approved post for a time you pick, and Steepfeed releases it then — unchanged, with the caption and settings you already reviewed. Automatic release is off unless you switch it on, you can see everything queued on your Schedule page, and you can cancel a scheduled post at any time before it goes out.

When a post publishes we send TikTok your caption, your chosen privacy level, your comment setting, your commercial-content disclosure, and a single-use link to the image you selected. TikTok then downloads the image from that link. The link is signed, expires after 24 hours, and reveals nothing else about your account. We also ask TikTok for your creator information each time the composer opens, and for the status of a post after it publishes.

Who processes data for us

We use a small number of sub-processors. Each acts on our instructions only, under a data-processing agreement:

  • Vercel Inc. (United States) — hosts and runs the application.
  • Supabase, Inc. (United States) — stores your account, post records and generated images, and handles authentication.
  • OpenRouter, Inc. (United States) — routes your prompt to the AI model that generates an image or suggests a caption. OpenRouter passes it to the model provider we have selected, currently OpenAI (United States). Your prompt and any screenshot you upload leave our systems at this point, and each provider's own API terms govern what it may do with them.
  • TikTok — receives an approved post, as described above. TikTok is a controller in its own right for what it then does with it; its own privacy policy applies.

If we change a sub-processor we will update this list and the date at the top of this page.

Data that leaves Switzerland

Several of the providers above are established in the United States, so your data is transferred outside Switzerland and the EEA. We rely on the European Commission's Standard Contractual Clauses, together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, as the transfer mechanism — supplemented, where the provider is certified, by the Swiss–US and EU–US Data Privacy Framework. Ask us at contact@isingdigital.ch and we will tell you which basis applies to a given provider.

How we protect it

  • Your TikTok access and refresh tokens are encrypted before they are written to the database, and decrypted only on our server at the moment a request to TikTok is made. They are never sent to your browser.
  • Traffic to and from Steepfeed is encrypted in transit (TLS), and our database and file storage are encrypted at rest by our providers.
  • Every read and write is scoped to the signed-in account. The credentials that can read across accounts exist only on the server and are never exposed to the browser.
  • The image links we hand to TikTok are signed and expire after 24 hours, so a leaked link is not a lasting exposure.
  • Access to production systems is limited to the people who operate Steepfeed and protected by multi-factor authentication.
  • If a breach affects your personal data we will notify the Federal Data Protection and Information Commissioner, and you directly where the risk to you is high, as promptly as the law requires.

How long we keep things

  • TikTok access and refresh tokens: kept until you disconnect that account, revoke access from inside TikTok, or delete your Steepfeed account. Deleted immediately in all three cases.
  • Screenshots you upload, brand material and generated images: they belong to the project you added them to, not to a connected account, so they survive disconnecting one. They are deleted when you delete the project, or when you delete your account.
  • Images prepared for a TikTok post, and TikTok publish records: deleted when you use “Revoke every TikTok grant and delete TikTok data”, and when you delete your account.
  • Post records (caption, settings, schedule, status): kept while your account exists, so you can see what was published and what failed.
  • Your account and email address: kept until you delete the account.
  • Deleting your account erases all of the above together, immediately.

Revoking access and deleting your data

  • From Steepfeed. Your Account page offers three things. Disconnect on a single connection revokes that grant at the platform and deletes its tokens, leaving your projects and their images alone. Revoke every TikTok grant and delete TikTok data does that for every TikTok connection at once and also deletes your TikTok publish records and the images prepared for them. Delete account closes your account and erases everything we hold — projects, uploads, generated images, records and sign-in — straight away and without contacting us.
  • From TikTok. In the TikTok app, go to Settings and privacy → Security and permissions → Apps and services, and remove Steepfeed. The next time we call TikTok on your behalf the attempt fails, and we mark the connection as removed and stop using the credentials.
  • By email. If you would rather we did it, or something did not work, write to contact@isingdigital.ch.

Posts already published stay on TikTok. Only you can delete those, from your TikTok profile — we have no ability to remove a post once it is live.

Your rights

You can ask us for a copy of the data we hold about you, have it corrected or erased, object to or restrict how we use it, and receive it in a portable form. Write to contact@isingdigital.ch and we will answer within 30 days. If you are not satisfied you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) in Bern, or, if you are in the EEA, to your local supervisory authority.

Changes

If this policy changes materially we will update the date at the top of this page and, where the change affects what we send to TikTok or who processes your data, tell you in the app.