Privacy Policy
Last updated: April 1, 2026
LucyCool ("we", "our", or "us") is a multi-platform video publishing application operated from Strasbourg, France. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our application and website at https://lucycool.pro and https://app.lucycool.pro.
By using LucyCool, you agree to the terms described in this Privacy Policy. If you do not agree, please do not use our service.
1. Information We Collect
1.1 Account Information
When you sign up or log in to LucyCool, we collect the following information through third-party OAuth authentication:
- Name — Your display name as provided by the authentication provider (Google, TikTok, or Instagram/Meta).
- Email address — Your email address associated with your Google account.
- Profile picture — Your avatar from the connected platform.
1.2 Connected Platform Data
When you connect your social media accounts (TikTok, YouTube, Instagram), we collect:
- Platform user ID — Your unique identifier on each platform.
- Platform username — Your public username on each platform.
- Platform avatar — Your profile picture on each platform.
- OAuth tokens — Access tokens and refresh tokens necessary to publish content on your behalf. These tokens are encrypted and stored securely.
- Follower count — Your public follower count on each connected platform.
1.3 Content Data
When you upload videos to publish through LucyCool, we temporarily store:
- Video files — The video files you upload for publishing.
- Metadata — Titles, descriptions, tags, and hashtags you provide for your publications.
- Publication history — Records of your past publications including status, platform, and timestamps.
1.4 Technical Data
We may automatically collect:
- Browser type and version
- Session cookies necessary for authentication
- Timestamps of your interactions with the service
2. How We Use Your Information
We use the information we collect exclusively for the following purposes:
- Providing the service — To authenticate you, connect your social media accounts, and publish your content on TikTok, YouTube, and Instagram on your behalf.
- Account management — To manage your account, display your connected platforms, and maintain your session.
- Publication management — To upload, schedule, and track the status of your video publications across platforms.
- Service improvement — To understand how our service is used and improve the user experience.
- Communication — To respond to your inquiries or provide important service-related notices.
3. Third-Party API Usage
LucyCool integrates with the following third-party APIs through their official channels:
3.1 TikTok API
We use the official TikTok Login Kit and Content Posting API to authenticate users and publish videos. We comply with TikTok's Terms of Service and TikTok's Developer Terms. We only access the permissions explicitly granted by the user during the OAuth consent flow.
3.2 YouTube / Google API
We use Google OAuth 2.0 and the YouTube Data API v3 to authenticate users and upload videos to YouTube. Our use of Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the scopes necessary for the service to function (user profile information and YouTube video upload).
3.3 Instagram / Meta API
We use the Facebook Login and Instagram Graph API to authenticate users and publish content to Instagram. We comply with Meta's Platform Terms and only access data that the user has explicitly authorized.
4. Data Storage and Security
We take the security of your data seriously and implement the following measures:
- Encrypted connections — All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- Secure token storage — OAuth access tokens and refresh tokens are stored securely on our servers and are never exposed to the client-side application.
- Session security — User sessions use secure, HTTP-only cookies with appropriate SameSite attributes to prevent cross-site request forgery.
- Limited access — Only authorized personnel have access to user data, and only when necessary for service operation or support.
- Temporary video storage — Uploaded video files are stored temporarily on our servers only for the duration necessary to complete the publication process.
5. Data Sharing
We do not sell, rent, trade, or otherwise share your personal data with third parties for marketing or advertising purposes.
Your data is shared only in the following limited circumstances:
- With connected platforms — When you publish content, your video and metadata are transmitted to the platforms you have selected (TikTok, YouTube, Instagram) through their official APIs.
- Legal requirements — If required by law, regulation, or legal process, we may disclose your data to comply with applicable legal obligations.
- Service providers — We use trusted hosting providers (Hostinger for the website, Render for the backend server) that may process data on our behalf under strict data processing agreements.
6. Data Retention
- Account data — Retained as long as your account is active. You may request deletion at any time.
- OAuth tokens — Stored as long as the platform connection is active. Tokens are deleted when you disconnect a platform.
- Video files — Temporarily stored during the publication process and deleted after successful publication or after 30 days, whichever comes first.
- Publication history — Retained as long as your account is active to provide you with a record of your publications.
7. Your Rights
In accordance with applicable data protection laws (including the European General Data Protection Regulation — GDPR), you have the following rights:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can request correction of inaccurate data.
- Right to erasure — You can request deletion of your account and all associated data.
- Right to data portability — You can request your data in a structured, machine-readable format.
- Right to withdraw consent — You can disconnect your social media accounts at any time from the application's Platforms page.
- Right to object — You can object to certain processing of your data.
To exercise any of these rights, please contact us at alsacedev@gmail.com.
8. Cookies
LucyCool uses only essential cookies necessary for the functioning of the service:
- Session cookie — Used to maintain your authenticated session. This cookie is HTTP-only and secure. It expires after 7 days of inactivity.
We do not use advertising cookies, tracking cookies, or any third-party analytics cookies.
9. Children's Privacy
LucyCool is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify users of significant changes by posting a notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact Information