An account owner connects each channel once, through that platform's own authorisation screen. BuildXFlow never asks for or stores a social media password. Access can be revoked at any time from the Accounts page or from the platform itself.
BuildXFlow publishes video to the connected account's own TikTok profile, and reads that account's public profile details and the view, like, comment and share counts of its own posts for the weekly report.
Before anything is posted, BuildXFlow shows the creator's nickname, avatar and available privacy options in the composer, and the person publishing selects the privacy level and confirms the post themselves.
BuildXFlow does not read other users' content, does not post without an explicit action by a signed-in team member, and does not use TikTok data for advertising or resale.
| Scope | Used for |
|---|---|
user.info.basic | Identify the connected account and show the creator nickname and avatar in the composer before publishing. |
user.info.profile | Display the connected profile so the publisher can confirm which account they are posting as. |
user.info.stats | Follower, like and video counts for the account's own weekly report card. |
video.list | Read the account's own posts and their metrics to build the weekly report and the best-time-to-post view. |
video.upload | Send a video the team has composed to TikTok. |
video.publish | Publish an approved video at its scheduled time, at the privacy level the publisher selected. |
Publish to the connected Page and Instagram Business account, and read their own post and audience insights for reporting. BuildXFlow does not read other users' content or private messages.
Upload video to the connected channel and read that channel's own analytics, including audience retention, so the team can see how much of a video was actually watched.
Publish to the connected company presence and read the engagement figures for those posts.
Publish updates to the connected business listings and read profile performance, such as impressions, calls and direction requests.
Read website traffic and search performance for the connected property, so social activity can be lined up against site visits and search demand.
Every connection is limited to accounts the customer owns and has authorised. BuildXFlow has no access to any account that has not been explicitly connected by that account's own administrator.
Every post is composed by a signed-in team member and approved by a named person before it can be queued. Nothing is generated and published without human review.
We read the connected account's own profile and its own posts' metrics. We do not collect, browse or analyse other users' content, followers or personal information.
Platform data is used to show customers their own numbers inside the application. It is never sold, shared with third parties, or used to build advertising or tracking profiles.
All connections use the platform's official OAuth flow. Tokens are stored server side, are used only for the actions described above, and are deleted when an account is disconnected.
Retention and deletion details are in the Privacy Policy. Questions about data handling or a deletion request: k.weldon@buildx.com.