Privacy Policy

Last updated 28 July 2026

Who we are

Idolyra is a web application that lets you create short-form videos with AI-generated characters and publish them to social platforms you connect, currently TikTok. This policy explains what we collect, why, how long we keep it, and how you delete it.

Contact us about anything in this policy at support@idolyra.com.

What we collect

Account data

Your email address and, if you provide one, your name. This is how we identify your account and contact you about it.

Content you create

The characters you design, the prompts and settings you choose, and the images and videos generated from them. These are stored so you can return to them.

Data from a connected TikTok account

When you connect TikTok, we ask TikTok for the permissions user.info.basic, video.upload and video.publish, and we receive:

  • An access token and a refresh token. These let us act on your behalf. The access token expires after 24 hours; the refresh token lets us obtain a new one without asking you to log in again.
  • Your TikTok account identifier (open_id), username, display name and profile picture. We show these so you can see which account is connected and which account a post will go to.
  • Your current posting options — which audiences you can post to, your maximum video length, and whether comments, Duet or Stitch are switched off on your account. We request this fresh from TikTok each time you open the post form, because TikTok requires that you are shown your real, current options.
  • For each post: the publish identifier TikTok gives us, the resulting post identifier and link, and whether it succeeded or failed.

We do not request or receive your TikTok password, your follower or view counts, your direct messages, your bio, or your list of existing videos.

Technical data

Standard server logs from our hosting providers, and a record of each publishing attempt so we can show you why something failed and support you when it does. Access tokens, refresh tokens and authorization codes are stripped from anything we log.

How we use it

  • To run the service: generate your content and store it for you.
  • To publish or schedule a post to a connected account — only when you ask us to. We never post on your behalf without an action you took in the app.
  • To show you the status, result and link of a post you made.
  • To keep your connection working by refreshing tokens before they expire.
  • To diagnose failures and provide support.

We do not sell your data. We do not use your content or your TikTok data to train AI models. We do not share it with advertisers.

How your TikTok credentials are protected

Access and refresh tokens are encrypted with AES-256-GCM before they are written to our database. The encryption key is held in our application environment, never in the database, so a copy of the database on its own does not expose your tokens. Each token is cryptographically bound to the account it belongs to, so a stored token cannot be moved between accounts.

Tokens are never sent to your browser and are never written to logs. They are used only server-side, and only to carry out an action you started.

Who else is involved

We rely on a small number of processors to run the service. They handle data on our instructions:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • TikTok — when you publish, your video and the settings you chose are sent to TikTok and are then governed by TikTok's own terms and privacy policy.
  • AI providers (xAI, fal.ai, WaveSpeed) — prompts and reference images are sent to these services to generate your content. Your TikTok tokens are never sent to them.

How long we keep it

  • TikTok tokens — until you disconnect the account or delete yourIdolyra account, whichever comes first. Disconnecting deletes them immediately.
  • Your content — until you delete it or close your account.
  • Publishing history — kept while your account is open so you have a record of what was posted where.

Deleting your data

Disconnect a TikTok account

Go to Connections and press Disconnect. We immediately ask TikTok to revoke our access, then delete the stored tokens. Any post you had scheduled to that account and not yet sent is cancelled. Videos already published stay on TikTok — they are yours, and only you can remove them, from the TikTok app.

You can also revoke our access from TikTok's side, under Settings and privacy → Security and permissions → Manage app permissions. If you do, our next attempt to use the connection fails and we mark it as needing reconnection.

Delete your whole account

Email support@idolyra.com from the address on your account and we will delete your account, your generated content and every connected credential within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, export or erase your personal data, and to object to or restrict its processing. Write to support@idolyra.com and we will respond within 30 days.

AI-generated content

Everything Idolyra produces is synthetic. Videos published to TikTok through this service are always sent with TikTok's AI-generated content label applied. This is not optional and cannot be switched off in the app.

Children

Idolyra is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

Changes

If we change this policy we will update the date at the top and, for material changes, notify you in the app. The current version is always at https://idolyra.com/privacy.