On this page we fully and transparently describe how our platform's TikTok integration works, which permissions it uses, which data is processed, and how users stay in control of their data at all times.
This page remains permanently public and serves both users and TikTok reviewers as a central source of information about our implementation of the TikTok Login Kit and the TikTok Content Posting API (Direct Post).
companycore ai is a B2B SaaS platform through which registered companies can plan and publish
posts for their social media channels – either entirely manually, or with the help of an AI
tailored to the brand, which creates post text and image suggestions based on the brand
information the user has provided. Users connect their own TikTok account only.
Every post must be manually reviewed, confirmed and scheduled with a date and time
by the user. For TikTok, the user additionally confirms, before every post, the visibility,
the interaction settings, any commercial disclosure, and TikTok's required consent line – none
of it pre-selected by us.
Only after this active approval is the post automatically published to TikTok at the
scheduled time via a scheduled server-side process (cron job).
No post is ever published without prior, explicit user confirmation. Neither the AI
nor the system ever publishes content on its own, and none of our AI features pre-set
visibility, interaction settings or the consent line.
Note on approval status: Until TikTok grants our Content Posting API audit, TikTok restricts every post published through our app to "Only me", regardless of the setting chosen, and at most 5 users can post through our app within any 24-hour window. This restriction is applied by TikTok itself; our app shows it on the connection card once the account is connected, and in the editor.
video.publish)
Both formats use the same OAuth flow and the same TikTok connection. There is no separate
upload/inbox mode (video.upload): posts are never handed to the TikTok app "to finish";
they are always published directly and completely from our app.
user.info.basic – basic account identification: open_id and display name (a
profile picture address is received but not displayed). Our interface shows the display name of the
connected account as initials and text, so the user can see before every publish which account the post
will appear on. The @username shown next to it comes from creator_info (Content Posting API,
video.publish), not from this scope.video.publish – direct publishing of video and photo posts to the connected account
(Content Posting API, Direct Post).We do not request any other permissions.
In line with the TikTok Content Sharing Guidelines, our editor shows, before every TikTok post:
creator_info when
the editor opens and again right before publishing)We never add our own watermarks, logos or promotional text to posts.
video.list scope)creator_info and triggers publishing via the TikTok Content Posting API at the scheduled
time. TikTok fetches the video or image file from our domain verified with TikTok via a time-limited,
signed link (PULL_FROM_URL).
We store: the TikTok account identifier (open_id), display name, username, a profile
picture address (not displayed), the encrypted access and refresh tokens, and their expiry times. Tokens are
stored exclusively AES-256-GCM encrypted; our database runs in the EU region (eu-central-1, Frankfurt).
Scheduled and published posts additionally carry a copy of the account identifier and display name so the
calendar can show which account a post belongs to; these copies are deleted together with the connection
(section 8).
The creator_info (nickname, allowed visibility levels, interaction restrictions, maximum video
length) is held only transiently in memory (at most 60 seconds) and fetched again before every publish. We do
not store third-party post content, followers, comments, or messages.
Users have two independent ways to revoke their connection:
a) Via our app: Backstage → Connections offers "Disconnect". On confirmation, we actively revoke the token with TikTok and immediately remove from our database the tokens, the stored account data (account identifier, display name, username) and the copies of account identifier and display name on scheduled and published posts. What remains in your calendar are the posts themselves (text, media, status) and the link to a post already published on TikTok. Posts already published on TikTok are unaffected.
b) Via the user's TikTok settings: TikTok app → Settings and privacy → Security → Apps and websites connected to TikTok → remove companycore.
Alternatively, a short email to jan@companycore.ai is sufficient.
For questions about the integration, permissions, or data handling:
jan@companycore.ai
companycore ai UG (haftungsbeschränkt)
Sömmeringstraße 69, 50823 Cologne, Germany
HRB 124109 (Cologne local court)
Managing director: Jan Bennefeld
This page is updated continuously as the TikTok APIs, permissions, or processes we use change. Every change is documented here transparently.