Privacy Policy

Version 1, effective from 2026-10-01

This is an English translation. The Polish version is binding. In case of any discrepancy, the Polish version prevails.

1. Data controller

The controller of your personal data is SEOPRO Marcin Szynkowski, ul. Koralowa 12, 64-930 Kotuń, tax ID (NIP) 7642369288 ("we"). For data protection matters write to kontakt@pleja.pl. We have not appointed a data protection officer.

If you upload videos containing other people's data as their controller, we process that data on your behalf as a processor under the data processing agreement in Annex 2 to the Terms of Service.

2. What data we process

  • Account: email address, first name, password hash (Argon2id, we do not know your password), language, time zone, dates you accepted the Terms and this Policy, and confirmation that you are 18 or over.
  • Sessions: the session identifier in a cookie and, for the "Active sessions" list, IP address and browser name.
  • Content: uploaded video files, their technical parameters (format, resolution, length), thumbnails, post captions, chosen settings and publishing times.
  • Data from TikTok (after you connect a TikTok account): account identifier (open_id), display name, granted permissions, encrypted access keys (access token and refresh token) with their expiry times; when you approve a post: the account nickname, available visibility options, whether comments, duets and stitches are turned off, maximum video length; after publishing: publish ID, status, failure reason and the ID of the published post; notifications from TikTok (event type, account identifier, publish ID). We do not store the avatar: we fetch it from TikTok only for display.
  • Post approval: date, IP address, browser, language and the text of the TikTok policy confirmation.
  • Technical logs: application events (for example errors, logins), IP address. Rate-limit counters store a hash of the IP address, not the address itself.
  • Correspondence: contact form data (name, email, subject, message, IP address), complaints, illegal content reports (location of the content, explanation, name and email of the reporting person).

An email address and a password are required to conclude the agreement. Other data is voluntary, but without it some features will not work (for example you cannot publish without connecting a TikTok account).

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Running your account, storing videos, publishing and scheduling posts on your instructionArticle 6(1)(b) (contract)
Emails about your account and posts (email verification, password reset, publishing status)Article 6(1)(b) (contract)
Security, login attempt limits, abuse prevention, technical logsArticle 6(1)(f) (our legitimate interest: protecting the service and its users)
Recording post approval and the TikTok account settings at that momentArticle 6(1)(f) (showing that publishing happened on your instruction)
Replying to messages and complaintsArticle 6(1)(b), (c) and (f)
Handling illegal content reportsArticle 6(1)(c) (obligations under the Digital Services Act)
Establishing, pursuing and defending legal claimsArticle 6(1)(f)

We do not profile you and do not make decisions about you based solely on automated processing (Article 22 GDPR). We do not show ads and do not use analytics tools.

4. TikTok

  • We send the video, caption and chosen settings to TikTok only when you click "Post" or "Schedule" (for scheduled posts: at the scheduled time). Nothing is sent to TikTok before that.
  • TikTok processes data as a separate, independent controller under its privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en.
  • We use data from TikTok only to show which account is connected, for the posting screen and for post status. We do not build profiles or databases about people from it.
  • You can disconnect your TikTok account in Pleja (Connected accounts, "Disconnect") or in the TikTok app, in the app permissions settings. After disconnecting we immediately revoke and delete the access keys and profile data.

5. Recipients and processors

  • Hosting: OVHcloud (OVH SAS / OVH sp. z o.o.). Pleja runs on this provider's servers in the European Union, where data, files and encrypted backups are stored.
  • Resend (Resend, Inc., USA): sending emails. Resend receives your email address and the content of the message. We limit email content: instead of video titles and account names we send links to Pleja.
  • TikTok: on your instruction, as an independent controller (section 4).
  • Public authorities: only where required by law.

6. Transfers outside the EEA

Our only processor outside the European Economic Area is Resend. Account data at Resend and the content of sent emails are stored in the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework and on standard contractual clauses. You can get a copy of the safeguards by writing to kontakt@pleja.pl.

7. How long we keep data

We keep account data until the account is deleted. Detailed periods:

DataPeriodWhat happens next
TikTok access keys (access token and refresh token, encrypted)until you disconnect the TikTok account in Pleja, revoke access in TikTok or delete your Pleja accountwe revoke them in TikTok and delete them immediately
TikTok account identifier (open_id), display name, granted permissionsas abovedeleted
TikTok account avatarnot storedfetched from TikTok only for display
Record of post approval: TikTok account settings at that moment, date, IP address, browser, confirmation texttogether with the postwhen the TikTok account is disconnected we remove the account identifier and name from the record, then as the post
Posts and publishing attempts: publish ID, status, failure reason, TikTok post ID90 days after the final statusdeleted
Unused post drafts30 days without changes (email 3 days before)deleted together with the file
Video file of a published post7 days after publishing or sending to the TikTok inboxfile deleted
Video file after failed publishing14 daysfile deleted
Notifications from TikTok: event type, account identifier, publish ID30 daysdeleted
Application logs (without the content of TikTok responses about the account, only error codes)30 daysdeleted
Download logs of the media.pleja.pl file server30 daysdeleted
Security log (for example logins, password and email changes)90 daysdeleted
Account data after account deletionTikTok keys immediately, the rest within 30 daysdeleted
Database backups (encrypted)14 daysoverwritten
Correspondence, complaints, illegal content reports3 years (limitation period for claims)deleted

8. Your rights

You have the right to access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest and withdraw consent where processing is based on it. You can change or delete most data yourself in your account settings.

We will email you a copy of your data (Articles 15 and 20 GDPR) within 30 days of a request sent to kontakt@pleja.pl from your account address. Deletion instructions are on the Data deletion page.

You can lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl) or with the supervisory authority in your country.

9. Other information

  • Security: encrypted connections (HTTPS), passwords stored as Argon2id hashes, TikTok access keys encrypted, access to data only for authorised persons, encrypted backups.
  • Age: Pleja is for people aged 18 or over. We delete the account of a minor once we learn about it.
  • Cookies: we only use strictly necessary cookies. Details: Cookie Policy.
  • Changes: we will inform you of significant changes to this Policy by email. Current version: 1, effective from 2026-10-01.