Simon HQ

Privacy Policy

Last updated: September 11, 2026

This Privacy Policy explains how Up Access ("we", "us", or "our") collects, uses, and shares information when you use Simon HQ and related posting integrations, including TikTok via our self-hosted Postiz stack.

1. Information we collect

  • Account data: email address, authentication credentials or tokens, and workspace membership details needed to sign you in and authorize access.
  • Usage and operations data: logs related to publishing jobs, clip processing, API requests, and error diagnostics.
  • Content you provide: media files, titles, captions, schedules, and other inputs you upload or generate in the product.
  • Connected social accounts: when you connect YouTube, TikTok, or other platforms, we receive OAuth tokens and profile / channel identifiers permitted by the scopes you approve, such as basic channel information needed to identify the connected account.

2. How we use information

We use information to:

  • Operate, secure, and improve Simon HQ
  • Connect accounts and publish or schedule content you authorize (including YouTube Data API uploads and TikTok Login Kit / Content Posting flows)
  • Deliver media to platforms you select
  • Provide support and investigate abuse or technical issues
  • Comply with legal obligations

3. YouTube-specific processing

If you connect a YouTube channel via Google OAuth, we process data solely to provide the publishing features you request. Depending on the scopes enabled in our Google Cloud OAuth client, this may include:

  • Channel identity (for example channel id and title) — to list and select the connected YouTube channel in Postiz / Simon HQ
  • OAuth access and refresh tokens — to keep the connection alive and call YouTube APIs on your behalf
  • Upload and manage videos you explicitly choose to publish or schedule (YouTube Data API upload / manage scopes you approve)

We do not sell YouTube user data. We do not use YouTube data for unrelated advertising. You can revoke access in your Google Account security settings and by disconnecting the channel in Postiz / Simon HQ.

4. TikTok-specific processing

If you connect TikTok, we process data solely to provide the features you request. Depending on the products and scopes enabled in our TikTok developer app, this may include:

  • user.info.basic / user.info.profile — to identify and display the connected TikTok account
  • video.upload, video.publish, and video.create — to upload and publish videos or drafts you choose to post

We do not sell TikTok user data. We do not use TikTok data for unrelated advertising. You can revoke access in TikTok account settings and by disconnecting the channel in Postiz / Simon HQ.

5. Sharing

We share information only as needed to run the service, including:

  • With platforms you connect (e.g., YouTube / Google, TikTok) to complete OAuth and posting
  • With infrastructure providers that host the app, media storage, or tunnels (under appropriate safeguards)
  • When required by law or to protect rights and safety

Self-hosted components (such as Postiz) store connection tokens in your deployment environment under your operational control.

6. Retention

We retain account, content, and connection data for as long as needed to provide the service, fulfill publishing requests, maintain backups, resolve disputes, and meet legal requirements. You may request deletion of your account data by contacting us; some logs or backups may persist for a limited period.

7. Security

We use reasonable technical and organizational measures to protect information, including access controls and encrypted transport (HTTPS). No method of transmission or storage is completely secure.

8. Your choices

  • Disconnect social channels at any time
  • Revoke Google / YouTube app access from your Google Account settings
  • Revoke TikTok app access from your TikTok account settings
  • Contact us to request access, correction, or deletion of personal data we hold, subject to applicable law

9. Children

The service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.

10. Changes

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use after changes means you accept the updated policy.

11. Contact

Privacy questions or requests: kris@simonhq.dev

Website: https://upaccess.store · https://upaccess.store/privacy