1. Scope and operator
ECHOMORROW Publisher (the “Publisher”) is a private desktop workflow operated by ECHOMORROW. It prepares and publishes original ECHOMORROW music videos to YouTube and TikTok accounts that the operator has explicitly authorized through those platforms' OAuth screens.
The Publisher is for one ECHOMORROW operator. It has no public user registration, no remote user database, and no advertising profile system.
2. Data we process
Depending on the platform and action, the Publisher may process:
- OAuth access and refresh tokens, approved scopes, and token expiry information;
- authorized account or channel identifiers and basic creator information such as channel title, TikTok username, or nickname;
- video files selected by the operator, titles, descriptions, captions, privacy settings, and other publishing metadata;
- platform responses such as upload, publish, or post identifiers and processing status; and
- local operational receipts, including timestamps, file paths, content hashes, and success or error details needed to verify a publishing attempt.
This public website does not use first-party analytics, advertising pixels, account forms, or first-party tracking cookies. Our hosting provider, Cloudflare, may process basic network and request logs to deliver and secure the site under its own privacy practices.
3. How we use data
We use platform data only to:
- authenticate the authorized operator;
- confirm the destination account or channel and available publishing capabilities;
- upload and publish content the operator has selected;
- check processing status and prevent accidental duplicate uploads; and
- maintain local receipts for troubleshooting, audit, and operational continuity.
We do not sell platform data, use it for targeted advertising, broker it, or use it to train machine-learning models.
5. Storage, security, and retention
OAuth credentials are stored in the authorized operator's macOS Keychain. Operational receipts are stored locally on that operator's Mac. The Publisher does not place these credentials or receipts in a public website or remote user database.
- OAuth credentials are retained while the connection remains active or until they are revoked or deleted.
- Cached profile or status information derived from platform APIs is refreshed or deleted within 30 days when no longer needed.
- After a valid revocation or deletion request, applicable local credentials and API-derived data are deleted as soon as practical and no later than 7 days.
- Minimal non-platform operational records may be retained when needed for security, legal compliance, or to document a publishing event.
Important: deleting local credentials or receipts does not delete a video already hosted on YouTube or TikTok. Hosted content must be managed separately through the relevant platform account.
6. Your controls
The authorized operator can stop future API access by revoking the Publisher in the relevant platform's account settings. Google permissions can be reviewed through Google Account third-party access. TikTok permissions can be reviewed or removed in TikTok's connected-app settings.
To request deletion of locally stored credentials and API-derived records, email rupinpc5@gmail.com with the subject “ECHOMORROW Publisher data deletion.” We may ask for enough information to confirm that the request comes from the authorized operator.
7. Changes to this policy
We may update this policy when the Publisher's behavior, platform requirements, or applicable rules change. The “Last updated” date above identifies the current version. Material changes will be reflected on this page before they apply to new processing.
8. Contact
Privacy, access, revocation, and deletion questions can be sent to rupinpc5@gmail.com.
ECHOMORROW is also available through its official Instagram profile.