Privacy Policy

Last updated: July 8, 2026

Overview

Slayo (“Slayo”, “we”, “us”), operated by The Leo Apps, helps you publish a single video to YouTube, TikTok, and Instagram in one step and view your performance analytics in one place. To do that, we hold the minimum data needed to call those platforms’ APIs on your behalf. We do not sell your data and do not share it beyond what’s required to perform the actions you ask for. This policy explains what we collect, how we use it, how long we keep it, and the choices you have.

Platform data we access

When you connect a platform, you authorize Slayo through that platform’s official OAuth flow. The data we may access is limited to the scopes you approve:
  • TikTok: your basic profile and public profile info (display name, username, avatar, verification status and aggregate follower/following/like/video counts), your list of videos and their public metrics, and the ability to upload and post videos on your behalf (TikTok Login Kit, Display API, and Content Posting API).
  • YouTube (Google): your channel info, the ability to upload videos on your behalf, and read-only channel/video analytics (YouTube Data API and YouTube Analytics API).
  • Instagram (Meta): your professional account info, media, and insights, and the ability to publish content (Instagram Graph API).
Slayo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Our use of TikTok data complies with the TikTok Developer Terms of Service and TikTok’s platform policies.

What we store

  • OAuth access/refresh tokens issued by YouTube, TikTok, and Instagram when you connect each platform. These let Slayo call the respective APIs as you.
  • A short-lived signed cookie carrying the OAuth state value during sign-in (for CSRF protection).
  • Your saved hashtag library and per-platform publish preferences.
  • Upload job status (per-platform progress + result) for a short period after each publish.
  • Aggregated analytics returned by the platforms when you load the Analytics page.

What we don't store

  • Your YouTube / TikTok / Instagram passwords (auth uses OAuth, so we never see them).
  • Your video file long-term. It lives in object storage only while the publish is running and is deleted afterward.
  • Any cross-site tracking identifiers or third-party advertising cookies.

How we use your data

  • To publish the videos you choose to the platforms you select.
  • To display your analytics and generate the content insights you request.
  • To keep you signed in to connected platforms and refresh access as needed.
  • To operate, secure, and troubleshoot the service.
We do not use your content or platform data for advertising, and we do not sell it or share it with data brokers.

Where data is stored

OAuth tokens, hashtag library, publish preferences, and job state live in Upstash Redis (managed via Vercel). The video itself is uploaded from your browser to Vercel Blob (public URL with an unguessable token in the path), passed to the platforms, then deleted.

Who we share with

  • YouTube (Google): we call the YouTube Data and Analytics APIs using your token.
  • TikTok: we call the TikTok Login Kit, Display, and Content Posting APIs using your token.
  • Meta / Instagram: we call the Instagram Graph API using your token.
  • Vercel and Upstash, as infrastructure providers, may process this data on our behalf under their respective terms.
Each platform handles your content under its own privacy policy once Slayo hands it off. We do not otherwise share your personal data with third parties.

Data retention

  • OAuth tokens: kept until you disconnect the platform in Settings or revoke access, after which they are deleted.
  • Uploaded video files: deleted immediately after the publish completes.
  • Upload job status: retained for roughly one hour after a publish, then discarded.
  • Hashtag library and preferences: kept until you change or delete them, or request account deletion.

Your rights and choices

  • Disconnect a platform in Settings, and Slayo deletes the stored OAuth token for that platform.
  • Revoke Slayo’s access directly from each platform: TikTok → Profile → Settings and privacy → Security & permissions → Manage app permissions; Google Account → Security → Third-party access; Meta → Business Settings / Apps and websites.
  • Request access to, correction of, or deletion of any data we hold about you by emailing us.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. To exercise any of them, contact us at the address below.

Data deletion requests

To delete the data Slayo holds about you, disconnect your platforms in Settings (which removes the stored tokens) and email admin@theleoapps.com with the subject “Data deletion”. We will delete the associated data we control within 30 days and confirm once complete.

Children's privacy

Slayo is not directed to children. The service is intended for users who are at least 18 years old (or the age of majority in their jurisdiction), and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

Cookies

Slayo sets a single signed, http-only cookie during the OAuth sign-in flow to verify the state parameter on the callback. It’s short-lived and used only for CSRF protection, with no analytics or advertising cookies.

Security

Tokens are stored in managed Redis with TLS in transit and encryption at rest. Connections between your browser and Slayo use HTTPS. We follow standard OAuth best practices for token handling. No method of transmission or storage is 100% secure, but we work to protect your data using reasonable safeguards.

International users and governing law

Slayo is operated from, and your data may be processed in, the United States and other countries where our infrastructure providers operate. This policy is governed by the laws applicable to The Leo Apps’ place of operation, without regard to conflict-of-laws rules.

Changes

We may update this policy as the service evolves. The “Last updated” date at the top reflects the most recent change; material changes will be reflected here.

Contact

Questions or data requests? Reach out at admin@theleoapps.com.