Privacy Policy for Lily
Last Updated: January 15, 2025
1. Introduction
Welcome to Lily ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform that integrates with TikTok. We are committed to protecting your privacy and handling your data in an open and transparent manner.
By using Lily, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
2.1 Information You Provide to Us
When you register and use Lily, we collect:
- Account Information: Email address, username, and password
- Profile Information: Creator profile details, payment information for payouts
- Campaign Participation: Your submissions to brand campaigns
2.2 Information from TikTok
When you connect your TikTok account to Lily, we access and collect:
- Public Profile Information: TikTok username, profile picture, bio, and follower count
- Video Metrics: View count, like count, comment count, and share count for videos submitted to campaigns
- Video Identifiers: TikTok video IDs for tracking campaign performance
We only access videos that you explicitly submit to campaigns through our platform.
2.3 Automatically Collected Information
- Usage Data: How you interact with our platform
- Device Information: Browser type, operating system, IP address
- Cookies and Similar Technologies: To enhance user experience and analyze platform usage
3. How We Use Your Information
We use the collected information to:
3.1 Platform Operations
- Facilitate connections between creators and brands
- Track campaign performance and video metrics
- Calculate and distribute points/rewards to creators
- Process payout requests
3.2 TikTok Data Usage
- Video Metrics Collection: We periodically fetch public metrics (views, likes, comments, shares) for videos you've submitted to campaigns to calculate your earned points
- Campaign Analytics: Provide brands with aggregated performance data about their campaigns
- Reward Distribution: Determine point awards based on video performance thresholds
3.3 Service Improvement
- Improve and optimize our platform
- Develop new features and services
- Provide customer support
3.4 Communications
- Send you campaign notifications and platform updates
- Respond to your inquiries and requests
- Send administrative information and important notices
4. Data Sharing and Disclosure
4.1 We Share Your Information With:
Brands/Advertisers: When you participate in a campaign, we share:
- Your TikTok username and profile information
- Video metrics and performance data for submitted videos
- Campaign participation status
Service Providers: We work with third-party service providers who assist us with:
- Payment processing (for creator payouts)
- Cloud hosting and data storage
- Analytics and performance monitoring
Legal Requirements: We may disclose your information if required by law or to:
- Comply with legal processes
- Protect our rights and property
- Ensure safety and security
4.2 We Do NOT:
- Sell your personal information to third parties
- Share your TikTok access tokens with anyone
- Access or collect data from videos not submitted to our campaigns
- Use your TikTok account to post content without your permission
5. TikTok Integration and Permissions
5.1 TikTok OAuth Connection
When you connect your TikTok account to Lily:
- We use TikTok's official OAuth 2.0 authentication
- We request only the minimum permissions necessary:
video.list: To identify videos you've submitted to campaignsuser.info.basic: To display your public profile information
5.2 Access Token Management
- Token Storage: We securely store your TikTok access tokens encrypted in our database
- Token Refresh: We automatically refresh tokens to maintain connection without re-authentication
- Token Revocation: You can disconnect your TikTok account at any time through your Lily account settings
- Limited Access: We only access public information available through TikTok's API
5.3 Automated Metrics Collection
- We collect video metrics every 10 minutes for active campaigns
- We only track videos you explicitly submit through our platform
- Metrics collected are public data (views, likes, comments, shares)
- No private or non-public information is accessed
6. Data Retention
- Active Accounts: We retain your data while your account is active
- Campaign Data: Video metrics and campaign participation history retained for analytical purposes
- Closed Accounts: Upon account deletion, we remove personal information within 30 days (some data may be retained for legal compliance)
- TikTok Tokens: Deleted immediately upon account disconnection or deletion
7. Data Security
We implement appropriate technical and organizational security measures:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Secure token storage with limited access
- Regular security audits and updates
- Access controls and authentication requirements
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
8. Your Rights and Choices
8.1 You Have the Right To:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Data Portability: Request your data in a portable format
- Opt-Out: Unsubscribe from marketing communications
- TikTok Disconnection: Disconnect your TikTok account at any time
8.2 How to Exercise Your Rights:
Contact us at michael.f.tomasik@gmail.com or through your account settings.
9. Children's Privacy
Lily is intended for users aged 13 and older. We comply with the Children's Online Privacy Protection Act (COPPA) and take special precautions regarding users under 18.
For Users Aged 13-17:
- We require parental or guardian consent
- We collect only necessary information for platform functionality
- Parents can review, modify, or delete their child's information
- Payout requests require parental approval and verification
For Users Under 13:
- Lily is not intended for children under 13
- We do not knowingly collect personal information from children under 13
- If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately
- We will delete such information promptly upon verification
Parental Rights:
Parents and guardians of users under 18 may:
- Review their child's account information
- Request deletion of their child's data
- Revoke consent for their child's use of the Service
- Contact us at michael.f.tomasik@gmail.com for any concerns
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
11. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our platform
- Sending an email notification
- Displaying a prominent notice
Your continued use of Lily after changes constitutes acceptance of the updated Privacy Policy.
13. TikTok-Specific Disclosures
13.1 Compliance with TikTok Policies
Lily complies with TikTok's Developer Terms and API policies. We:
- Only use TikTok data as described in this Privacy Policy
- Do not attempt to recreate or substitute any TikTok features
- Respect TikTok's rate limits and technical requirements
- Honor user disconnection requests immediately
13.2 TikTok Data Deletion
If you disconnect your TikTok account or delete your Lily account:
- We immediately revoke access tokens
- We stop collecting new metrics for your videos
- Historical campaign data may be retained in anonymized/aggregated form
- You can request complete deletion by contacting us
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
- Email: michael.f.tomasik@gmail.com
- Support: michael.f.tomasik@gmail.com
- Website: https://lily.app/privacy
For TikTok-specific privacy concerns, you may also contact TikTok directly through their privacy channels.