基心AI

基心AI隐私政策Jixin AI Privacy Policy

生效日期 / Effective date:2026年7月26日July 26, 2026
最后更新 / Last updated:2026年7月26日July 26, 2026

如中英文版本存在解释冲突,以简体中文版本为准(Chinese version prevails in case of conflict)。

简体中文

适用范围和运营主体

本隐私政策适用于 基心AIJixin AI)网站、视频生产、素材管理、多平台账号绑定与自动发布等功能,包括但不限于 ai.shuyunpingtai.com 及相关子路径。

运营主体为 一心一意(杭州)企业管理有限公司(以下简称「我们」)。联系方式见本政策「联系方式」一节。

TikTok、抖音、快手、小红书、视频号、Google/YouTube 等第三方平台拥有各自独立的隐私政策与服务条款。您使用这些平台时,同时受其规则约束;我们不是上述平台的官方产品、合作伙伴,也未获得其背书。

收集的信息

用户与账号信息。我们可能处理:基心AI 账号标识、租户标识、手机号登录信息、会话令牌(浏览器 localStorage 中的登录状态标识)、您主动填写的资料与联系方式,以及合伙人套餐/额度相关信息。

TikTok OAuth 与发布信息(在您授权并使用 Content Posting 相关能力时)。当您通过 TikTok 官方 OAuth 页面主动授权,且我们在已获批的权限范围内调用接口时,可能处理:

  • 授权产生的 open_id、授权范围(scopes)与账号绑定状态;
  • 在申请并获批 user.info.basic 时读取的昵称、头像等基础资料;
  • OAuth access token、refresh token、过期时间与撤销/解绑状态(仅保存在服务端,不写入前端公开环境变量或浏览器存储);
  • 您主动选择发布的视频、封面、标题、标签与发布设置;
  • creator_info 返回的可用隐私级别、评论、Duet、Stitch、最长视频时长等能力信息;
  • publish_id、上传进度、处理状态、成功或失败结果;
  • 您选择的 video.uploadvideo.publish 授权范围。

我们不会读取您的 TikTok 私信、通讯录、密码,或其他未申请的数据。Client Secret 仅保存在服务端环境变量中,不会出现在 HTML、前端代码或浏览器存储。

抖音开放平台(已上线 H5 投稿相关能力)。在您授权抖音开放平台时,我们可能处理 open_id、昵称、头像、授权状态、投稿任务标识、标题/话题/描述、发布进度与结果。抖音 Client Secret 仅服务端使用。

国内多平台自动发布(扫码会话)。自动发布当前支持抖音、快手、小红书、视频号。登录方式主要为平台扫码会话(非 TikTok OAuth)。我们处理您选择的成片、发布文案、目标账号、定时任务与发布记录状态,以及会话健康检查所需的技术信息。

YouTube。当前产品未上线 YouTube 自动发布 OAuth;若日后上线,将在更新本政策并取得您授权后再披露具体字段。

技术与安全信息。登录与操作时间、IP、浏览器/设备类型(User-Agent)、错误码与安全/审计日志。我们使用浏览器 localStorage(及部分场景 sessionStorage)保存登录态与界面偏好;未宣称「不使用 Cookie」——如基础设施或第三方组件设置必要 Cookie,将按实现披露。

信息使用目的

  • 完成用户登录、OAuth 授权与账号绑定;
  • 向您展示当前绑定的平台账号与能力信息;
  • 在您明确选择视频并确认后执行上传或发布;
  • 展示上传进度、处理状态与发布记录;
  • 防止欺诈、重复发布、滥用与安全事件;
  • 故障排查、性能改进与合规审计;
  • 提供合伙人套餐、额度与客服支持。

我们不会将您的内容默认用于广告画像出售,也不会在未获您单独明确同意的情况下用于模型训练。若未来需要将用户内容用于模型训练,将单独披露并取得独立同意。

用户授权与发布控制

  • 连接 TikTok/抖音等平台前,会跳转至平台官方 OAuth 或官方扫码流程;
  • 您可查看请求的权限并自主同意或拒绝;
  • 我们不会获取您的平台密码;
  • 视频仅在您选择目标平台、确认账号与发布设置后发送;
  • 您可在发布前编辑标题、标签、隐私级别及适用设置;
  • TikTok Upload API(video.upload)会将视频发送到 TikTok 收件箱,由您在 TikTok 内继续编辑并最终发布;
  • Direct Post(video.publish)仅在您明确确认后执行;未经审核的 Direct Post 客户端能力可能仅能使用 SELF_ONLY 等受限隐私级别;
  • 我们不保证 TikTok/抖音/其他平台一定接受、处理或公开展示内容;
  • 我们不会承诺绕过 SELF_ONLY、用户上限、创作者上限或平台发布配额;
  • 使用 PULL_FROM_URL 时,视频 URL 必须属于已在 TikTok Developer Portal 验证的域名或 URL 前缀。

信息共享和第三方处理

  • 在您明确发起发布时,向 TikTok、抖音、快手、小红书、视频号等目标平台传输视频与发布元数据;
  • 阿里云对象存储(OSS,杭州等区域)、云服务器、SQLite/业务数据库、阿里云短信、日志与监控相关基础设施——仅在实现功能所必需时处理数据;
  • 法律法规、司法或监管要求下的披露;
  • 公司合并、重组或资产转让时,个人信息可能作为交易的一部分转移,我们将要求继受方继续受本政策约束或另行通知您。

我们不会以模糊的「商业合作伙伴」名义出售您的个人信息。

数据保存和删除

  • OAuth / 发布临时 state 与投稿短链 token:按配置的短有效期保存(例如抖音 H5 投稿 token 默认约 30 分钟量级),过期后不可再用;
  • access token:按平台返回的过期时间处理,过期后刷新或要求重新授权;
  • refresh token 与绑定关系:保存至您解绑、在平台侧撤销授权、注销基心AI 账号,或达到合法保存期限为止;
  • 原始/成品视频、发布任务与错误日志:按业务需要与账号生命周期保存;您提出删除请求并经身份核验后,我们将在合理期限内删除或匿名化,法律要求或争议解决所需除外;
  • 备份系统可能存在延迟清除。我们不在本政策中承诺无法由现有备份/存储体系兑现的固定「N 日内物理删除」时限。

数据安全

  • 网站传输使用 HTTPS;
  • 平台 token 保存在服务端;
  • Client Secret 不写入前端或公开仓库;
  • 按账号/租户进行权限隔离与最小必要访问;
  • 记录必要的访问与安全审计日志;
  • 发生安全事件时,我们将依法评估并采取补救与通知措施。

互联网环境无法保证绝对安全,我们不会使用「永不泄露」等保证性表述。请妥善保管您的账号与验证码。

用户权利

在适用法律允许范围内,您可以:

  • 查询、更正、导出或删除相关个人信息;
  • 撤回同意(可能导致相关功能不可用);
  • 在基心AI 中解绑已连接的平台账号(自动发布页可重新扫码/切换账号;抖音 H5 相关授权可按产品内流程或联系客服处理);
  • 在 TikTok / 抖音 / Google 等官方账号设置中撤销第三方授权;
  • 请求删除上传素材与发布记录;
  • 申请注销基心AI 账号:请发送邮件至 m18516123021@163.com wangzhenyong@shuyunpingtai.com,并提供可核验的账号信息;我们将在核实身份后处理。

当前产品未提供「一键注销」独立按钮时,邮件请求即为正式路径。我们不会在政策中描述不存在的界面按钮。

未成年人

本产品主要面向企业与具备完全民事行为能力的成年人使用。若您未满 18 周岁,请在监护人同意与指导下使用,并确保监护人已阅读本政策。我们不会将产品定位为专门面向儿童的服务。

跨境处理

运营主体位于中华人民共和国境内,主要基础设施位于中国(含阿里云杭州等区域)。当您使用 TikTok 等境外平台的开放接口时,相关数据将按您的指令传输至该平台,并受该平台隐私政策与其所在法域规则约束。我们仅在实现您确认的发布/授权所必需的范围内进行此类传输。

政策更新

我们可能根据业务、法律或监管要求更新本政策。重大变更将通过网站公示等方式告知,并更新「最后更新日期」。若您在更新后继续使用服务,即表示知悉更新内容;如不同意,请停止使用并联系我们处理账号事宜。

联系方式

如对本隐私政策或个人信息处理有疑问、请求或投诉,请联系:

  • 运营主体:一心一意(杭州)企业管理有限公司
  • 统一社会信用代码:91330110MA2KH3AG48
  • 隐私邮箱:m18516123021@163.com
  • 客服邮箱:wangzhenyong@shuyunpingtai.com
  • 联系地址:浙江省杭州市余杭区良渚街道花苑新村2幢2-4# 湃商商务秘书托管2021270号

English

Scope and Operator

This Privacy Policy applies to Jixin AI (基心AI) websites and features for AI content production, media management, multi-platform account linking, and auto-publishing, including ai.shuyunpingtai.com and related paths.

The operator is 一心一意(杭州)企业管理有限公司 (“we”, “us”). Contact details are listed in the Contact section.

TikTok, Douyin, Kuaishou, Xiaohongshu, WeChat Channels, Google/YouTube and other third-party platforms have their own privacy policies. You remain subject to those rules. Jixin AI is not an official TikTok product, partner, or endorsed service.

Information We Collect

Account information. We may process Jixin AI account IDs, tenant IDs, phone-based login data, session markers in browser localStorage, profile details you submit, and membership/quota metadata.

TikTok OAuth and publishing data (only when you authorize and use Content Posting features within approved scopes):

  • open_id, granted scopes, and binding status;
  • display name and avatar when user.info.basic is approved and requested;
  • OAuth access token, refresh token, expiry, and revocation status (server-side only; never in frontend env vars or browser storage);
  • videos, covers, captions, tags, and publish settings you choose;
  • creator capability data from creator_info (privacy levels, comment/Duet/Stitch, max duration, etc.);
  • publish_id, upload progress, processing status, success/failure;
  • whether you grant video.upload and/or video.publish.

We do not read TikTok DMs, contacts, passwords, or other unrequested data. The Client Secret stays in server-side configuration only.

Douyin Open Platform (live H5 publish flows). When you authorize Douyin, we may process open_id, nickname, avatar, auth status, task IDs, captions/topics, and publish results. Douyin Client Secret is server-only.

Domestic multi-platform auto-publish (QR sessions). Supported platforms today: Douyin, Kuaishou, Xiaohongshu, and WeChat Channels via QR-based sessions (not TikTok OAuth). We process selected videos, captions, target accounts, schedules, and publish records.

YouTube. YouTube auto-publish OAuth is not live. If launched later, this Policy will be updated before related processing begins.

Technical and security data. Login/operation timestamps, IP, User-Agent, error codes, and audit logs. We use localStorage (and in some flows sessionStorage) for session/UI state. We do not claim “we never use cookies.”

How We Use Information

  • Authenticate users, complete OAuth, and bind accounts;
  • Show linked platform accounts and creator capabilities;
  • Upload or publish only after you select content and confirm;
  • Show progress, status, and publish history;
  • Prevent fraud, duplicate posts, abuse, and security incidents;
  • Troubleshoot, improve reliability, and meet compliance audits;
  • Provide membership plans, quotas, and support.

We do not sell advertising profiles of your content, and we do not use your content for model training by default. Any future training use would require a separate disclosure and explicit consent.

Authorization and Publishing Controls

  • Before linking TikTok/Douyin, you are redirected to the platform’s official OAuth or QR flow;
  • You can review requested scopes and accept or deny;
  • We never obtain your platform passwords;
  • Videos are sent only after you choose the platform, account, and settings;
  • You may edit captions, tags, privacy, and applicable options before send;
  • TikTok Upload API (video.upload) delivers to the TikTok inbox for further in-app editing and final publish by you;
  • Direct Post (video.publish) runs only after explicit confirmation; unaudited Direct Post clients may be limited to SELF_ONLY;
  • We do not guarantee platforms will accept, process, or publicly display content;
  • We do not promise to bypass SELF_ONLY, user/creator caps, or publish quotas;
  • For PULL_FROM_URL, video URLs must use domains/prefixes verified in the TikTok Developer Portal.

Sharing and Third-Party Processors

  • When you initiate a publish, we transmit video and metadata to the destination platform (TikTok, Douyin, Kuaishou, Xiaohongshu, WeChat Channels, etc.);
  • Processors used in production include Alibaba Cloud OSS, cloud hosts, SQLite / operational databases, Alibaba Cloud SMS, and logging/monitoring tooling—only as needed to operate the service;
  • Disclosures required by law, courts, or regulators;
  • In a merger, reorganization, or asset transfer, personal data may transfer as part of the transaction under continued protection or with notice.

We do not sell personal information under vague “business partner” labels.

Retention and Deletion

  • OAuth/publish temporary state and short-lived publish tokens are kept for a short TTL (e.g., Douyin H5 publish tokens on the order of ~30 minutes) and then become unusable;
  • Access tokens follow platform expiry; refresh or re-auth as needed;
  • Refresh tokens and bindings are kept until you unlink, revoke on the platform, delete your Jixin AI account, or a lawful retention period ends;
  • Source/output videos, publish jobs, and error logs are kept as needed for the product lifecycle; after a verified deletion request we delete or anonymize within a reasonable period, except where law or disputes require retention;
  • Backups may lag. We do not promise a fixed “deleted within N days” physical purge that our systems cannot honor.

Security

  • HTTPS in transit;
  • Platform tokens stored server-side;
  • Client Secrets never shipped to the frontend or public repos;
  • Account/tenant isolation and least-privilege access;
  • Security and access audit logging where applicable;
  • Incident response and legal notifications when required.

No system is perfectly secure; we do not claim absolute or permanent protection. Please protect your credentials and verification codes.

Your Rights

Subject to applicable law, you may:

  • Access, correct, export, or delete personal data;
  • Withdraw consent (related features may stop working);
  • Unlink platform accounts in Jixin AI (re-scan/switch accounts on Auto Publish; Douyin H5 bindings via in-product flows or support);
  • Revoke third-party access in TikTok/Douyin/Google account settings;
  • Request deletion of uploaded media and publish records;
  • Request account closure by emailing m18516123021@163.com or wangzhenyong@shuyunpingtai.com with verifiable account details.

If a one-click “delete account” button is not available, email is the supported path. We do not document non-existent UI controls.

Minors

The service is primarily intended for businesses and adults with full legal capacity. If you are under 18, use it only with guardian consent and guidance. We do not market the product as directed to children.

Cross-Border Processing

The operator is established in the PRC, with primary infrastructure in China (including Alibaba Cloud regions such as Hangzhou). When you use overseas platform APIs such as TikTok, data is transmitted to that platform under your instruction and subject to that platform’s policies and applicable jurisdictions. We transfer only what is necessary to complete the authorization or publish you confirmed.

Policy Updates

We may update this Policy for product, legal, or regulatory reasons. Material changes will be posted on the site with an updated “Last updated” date. Continued use after an update means you acknowledge the changes; if you disagree, stop using the service and contact us about your account.

Contact

For questions, requests, or complaints about this Policy or personal data:

  • Operator: 一心一意(杭州)企业管理有限公司
  • Unified Social Credit Code: 91330110MA2KH3AG48
  • Privacy email: m18516123021@163.com
  • Support email: wangzhenyong@shuyunpingtai.com
  • Address: 浙江省杭州市余杭区良渚街道花苑新村2幢2-4# 湃商商务秘书托管2021270号