Privacy Policy

Last updated: March 1, 2026

Overview

Noctin Media ("we", "us") operates Noctin Scheduler. This Privacy Policy explains what data we collect when you use the Service, how we use it, and your rights regarding that data. We are committed to handling your data responsibly and transparently.

Data We Collect

When you connect a social media account via OAuth 2.0, we receive and store:

  • OAuth access token — used to publish content on your behalf
  • OAuth refresh token — used to maintain your session without requiring re-authentication
  • Platform user ID — to identify your account within our system
  • Display name & profile photo URL — displayed in your dashboard

We do not collect your platform password, payment information, location data, or any data beyond what is listed above.

How We Use Your Data

  • To authenticate API requests to connected social platforms on your behalf
  • To display your connected account information in the dashboard
  • To maintain your session across page visits (via a secure, HttpOnly cookie)

We do not sell, rent, or share your data with any third parties. We do not use your data for advertising.

Data Storage & Security

OAuth tokens and session data are stored in Cloudflare Workers KV, a globally distributed key-value store with encryption at rest. Session cookies are HttpOnly, Secure, and SameSite=Lax. Sessions automatically expire after 7 days of inactivity.

TikTok Data

When you connect your TikTok account, we request the following scopes: user.info.basic, video.publish, video.upload. These are used solely to retrieve your basic profile info and to upload and publish videos you submit. We do not access your followers, messages, or any data beyond these scopes.

Your Rights & Data Deletion

You may request deletion of your data at any time by emailing hello@noctinmedia.com. We will delete your stored tokens and session data within 48 hours. You can also revoke the Service's access directly from each platform's connected apps settings, which immediately invalidates our stored tokens.

Cookies

We use a single session cookie (nm_sess) to maintain your login state. No analytics, advertising, or tracking cookies are used.

Changes to This Policy

We may update this Privacy Policy occasionally. We will update the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance.

Contact

Privacy questions or data deletion requests: hello@noctinmedia.com