What ClipPort handles
When you connect TikTok, TikTok gives ClipPort an account identifier, basic creator profile details, and access and refresh tokens for the permissions you approve. ClipPort requests only user.info.basic, video.publish, and video.upload. Direct Post needs the publish permission; a TikTok inbox draft needs the upload permission. The tokens are held encrypted in secure, HttpOnly browser cookies. They are sent back to this service only when needed to perform your request.
The posting screen handles your delivery-mode choice, local caption note, file size, duration, and media type. For Direct Post it also handles the privacy, interaction, AI, commercial-content, and declaration settings you choose. In inbox draft mode, ClipPort sends no caption or Direct Post metadata to TikTok; the caption is not transferred, and you complete every final setting inside TikTok.
How a selected video moves
Your browser previews the local file. Nothing is uploaded merely because you selected it. Only after you choose Direct Post or TikTok inbox draft, give explicit consent, and press the final delivery button does the selected video stream from your browser, through our Cloudflare Worker relay, directly to the one-time upload address supplied by TikTok. ClipPort does not retain the selected video, create a stored copy, or add a watermark.
Who receives data
TikTok receives creator-profile requests and the video you direct ClipPort to send. TikTok also receives your selected Direct Post settings in Direct mode, but receives only the video-init metadata and video in inbox draft mode. Cloudflare provides the network runtime used by the relay and may process routine request metadata under its own service terms. ClipPort never sells personal data. We do not sell videos, captions, creator information, or tokens.
Retention and security
ClipPort's application code does not create an account database or video library. Encrypted authorization cookies remain in your browser until they expire, you disconnect, or you clear site data. Encrypted upload tickets expire after 15 minutes. Encrypted status tickets expire after 24 hours and bind a TikTok publish identifier to your connected session and chosen delivery mode, so the browser cannot ask about arbitrary identifiers. The active encrypted status ticket may be kept in this tab's session storage so status checking can resume after a reload; it is cleared after a terminal result or disconnect and cannot authorize an upload.
ClipPort's separate duplicate-init guard keeps an opaque attempt fingerprint and state, and after initialization it keeps the delivery mode, TikTok publish identifier, expiry metadata, and encrypted upload/status tickets for up to 24 hours solely to prevent a repeated click or manual retry from creating a second TikTok initialization. This does not contain the video or caption and is separate from webhook event storage. No security measure is perfect, but secrets are not placed in page source or returned in API errors.
Revocation and deletion
Use Disconnect in ClipPort to delete ClipPort's authorization cookies from this browser. You can revoke the app's TikTok permission in TikTok's security settings. You may also clear this site's cookies in your browser. To ask about deletion or privacy, email hello@sauce101.co.kr. Because ClipPort does not retain selected videos or maintain a creator account database, deletion usually consists of removing browser cookies and revoking TikTok access.
Your choices and contact
You control whether to connect TikTok, which local file to select, whether to use Direct Post or inbox draft, every applicable setting, and whether to press the final button. ClipPort does not schedule or automatically retry a delivery. Do not use ClipPort if you do not agree with this data flow. Questions, access requests, or deletion requests can be sent to hello@sauce101.co.kr.