MODE LABS PUBLISHER
Privacy Policy
Last updated July 2, 2026
Overview
Mode Labs ("we," "us," or "our") operates Mode Labs Publisher ("Publisher") to publish content on social media platforms on behalf of authorized Mode Labs operator accounts. This policy explains what data Publisher accesses, why we need it, how long we keep it, and your choices.
Publisher is not a public multi-user SaaS product. It is used internally to manage our own connected social accounts. We do not sell personal information and we do not collect data from other platforms' users beyond what is necessary to operate the connected account.
Who This Applies To
This policy applies when you (the Mode Labs operator or an authorized representative) connect a social account to Publisher through a platform's OAuth or API authorization flow. It does not apply to visitors who only read this page without connecting an account.
Information We Collect
Depending on which platforms you connect, Publisher may access and store:
- Account identifiers and basic profile informationreturned by each platform's authorization APIs (for example, display name, username, avatar URL, and account ID);
- OAuth access tokens and refresh tokens issued when you authorize Publisher to act on your behalf;
- Content you submit for publishing — video files, images, captions, titles, and scheduling metadata;
- Technical logs — timestamps, API response status, and error messages needed to operate and debug the publishing pipeline (we do not use these logs for advertising).
We do not request or store passwords for your social accounts. Authentication is handled by each platform's official login and consent screens.
TikTok Data
When you connect a TikTok account to Publisher through TikTok's Login Kit and Content Posting API, we access only the data scopes you approve during authorization. For the Mode Labs Publisher app, this typically includes:
- user.info.basic — basic profile information (such as open ID, display name, and avatar URL) to identify the connected account;
- video.upload (and, if separately authorized and approved by TikTok, direct-post scopes) — permission to upload video content to the authorized TikTok account on your behalf.
How we use TikTok data: solely to authenticate the connection, display which account is connected, upload videos you choose to publish, and maintain the authorized session. We do not use TikTok data for advertising, profiling unrelated users, or any purpose outside operating Publisher for the connected account.
How we store TikTok tokens: OAuth access tokens and refresh tokens are stored server-side in encrypted secret management infrastructure (Doppler) and on our self-hosted publishing server. Tokens are not exposed in client-side code, public repositories, or marketing databases.
Revoking access:You may disconnect Publisher at any time by removing the integration in our publishing dashboard, and you may revoke Publisher's access in TikTok at TikTok Settings → Security → Manage app permissions. After revocation, we delete or invalidate stored tokens as soon as practicable.
We do not sell TikTok user data. We do not share TikTok data with third parties except as needed to transmit your content to TikTok's APIs (i.e., to TikTok itself as the platform operator) or as required by law.
Other Platform APIs
Publisher may also connect to the following platforms for the same internal publishing purpose:
YouTube (Google)
When connected, we access account identifiers and upload permissions granted via Google OAuth (including the YouTube Data API) to upload videos and set metadata on the authorized channel. Use of YouTube data is subject to the YouTube Terms of Service and YouTube API Services Terms.
Meta (Instagram, Facebook, Threads)
When connected, we access the profile and publishing permissions you grant through Meta's OAuth flow (for example, instagram_basic, instagram_content_publish, pages_show_list, threads_basic, threads_content_publish). We use this data only to publish content to the authorized accounts.
When connected, we access basic profile information and posting permissions granted via LinkedIn OAuth (openid, profile, email, w_member_social) to publish posts on the authorized member account.
X (Twitter)
If connected, we access the posting permissions granted via X's API authorization to publish posts on the authorized account.
For all platforms above, tokens are stored server-side under the same security practices described in the Storage & Security section. We access only operator-authorized accounts; we do not collect data belonging to other users of those platforms.
How We Use Information
We use the information described above to:
- Authenticate and maintain connections to authorized social accounts;
- Upload, schedule, and publish content you direct us to post;
- Diagnose failures, maintain security, and improve reliability of the publishing pipeline;
- Comply with legal obligations and respond to lawful requests.
We do not use platform data for targeted advertising or to build profiles on unrelated individuals.
Storage & Security
Publisher runs on self-hosted infrastructure operated by Mode Labs. OAuth tokens and API secrets are stored in Doppler (encrypted secrets management) and injected at runtime into our publishing services — they are not committed to source control or embedded in client applications.
Media files staged for posting may be stored temporarily on our servers or object storage (for example, Cloudflare R2) until publishing completes, then removed according to our retention practices.
We apply reasonable technical and organizational measures to protect stored data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Data Retention
We retain OAuth tokens while a platform connection remains active. When you disconnect an account or revoke authorization, we delete or invalidate the associated tokens as soon as practicable.
Published content remains on the respective platform according to that platform's policies. Operational logs may be retained for a limited period for security and debugging, then deleted or aggregated.
Media files uploaded for pending posts are retained only as long as needed to complete publishing or troubleshoot a failed post, then removed from our storage.
Your Rights & Revocation
You may:
- Disconnect any platform integration through Publisher or the platform's own app-permissions settings;
- Request information about data we hold related to your connected accounts by emailing us;
- Request deletion of stored tokens and associated operational data, subject to legal retention requirements.
To exercise these rights, contact contact@modelabs.studio. We will respond within a reasonable time.
Changes
We may update this Privacy Policy to reflect changes in our practices, connected APIs, or legal requirements. We will update the "Last updated" date at the top of this page. Material changes may also be communicated through our internal operations channels.
Contact
Questions about this Privacy Policy or Mode Labs Publisher data practices may be directed to contact@modelabs.studio.
This policy applies specifically to Mode Labs Publisher. For general Mode Labs website and product privacy practices, see modelabs.studio/privacy.
Questions? Contact access@modelabs.studio.