Privacy Policy — Pumpkii Media Hub
How we handle data in our internal content publishing tool
Effective Date: 2026-05-05
Last Updated: 2026-05-06
Operator: Pumpkii (the "Company", "we", "us")
Contact: dev@pumpkii.com
Plain-language Summary
Pumpkii Media Hub is an internal tool used only by Pumpkii's own operations team to publish marketing videos to our own brand accounts on YouTube, Instagram, and TikTok. It does not serve external users. We collect the minimum data needed to make publishing work and we do not sell, share, or use this data for any purpose other than running this tool.
1. Scope of This Policy
Pumpkii Media Hub (the "Service") is a private, internal-use content management tool operated by Pumpkii. The Service is not offered to the public, third-party brands, or end consumers. It is used solely by authorized Pumpkii employees and contractors. This policy is separate from the general Pumpkii product privacy policy and applies only to the Media Hub Service.
- Upload, schedule, and publish marketing videos featuring Pumpkii products to brand-owned accounts on YouTube, Instagram, and TikTok.
- Aggregate publicly-available performance data (views, likes, comments, follower counts) from those same brand-owned accounts for internal analytics.
The Service does not collect, store, or process personal data belonging to end users of YouTube, Instagram, or TikTok (such as their viewers, followers, or commenters), beyond what is publicly visible as aggregate engagement metrics on Pumpkii's own posts.
2. Data We Collect
2.1 Account Data (Pumpkii staff)
- Email address and display name
- Password hash (we never store passwords in plain text)
- Login timestamps and IP address (for security audit)
- Role (admin, operator, viewer)
2.2 OAuth Tokens
When a Pumpkii staff member connects a Pumpkii brand account on YouTube, Instagram, or TikTok, we store:
- OAuth access_token and refresh_token (encrypted at rest)
- Platform identifier of the brand account (YouTube Channel ID, Instagram Business Account ID, TikTok Open ID)
- Token expiry timestamps and granted OAuth scopes
We never request OAuth tokens from any account other than Pumpkii's own brand accounts.
2.3 Content and Analytics
- Video files (deleted 30 days after successful publication), cover images, titles, descriptions, hashtags
- AI generation prompts (if used) — for internal archival
- Publish status per platform and the platform's post ID after success
- Daily snapshots of view count, like count, comment count, follower count for Pumpkii's own posts (fetched from each platform's official API)
2.4 What We Do NOT Collect
- Personal data of YouTube / Instagram / TikTok end users (viewers, followers, commenters)
- Direct messages, private content, or content from accounts other than Pumpkii's brand accounts
- Payment information
- Device sensors, location, or contacts from any user's device
3. How We Use Data
We use the data described above only to:
- Operate the Service: authenticate Pumpkii staff, publish videos, display analytics dashboards.
- Maintain security: detect unauthorized access, rotate OAuth tokens, audit admin actions.
- Improve internal workflows: assess content performance against our own goals.
We do not sell data, share with advertisers or analytics brokers, train ML models on this data, or send marketing communications based on it.
4. Third-Party Data Sharing
The Service interacts with the following third parties strictly to perform its core function:
| Third Party | Purpose | Data Sent | Privacy Policy |
|---|---|---|---|
| Google (YouTube Data API v3) | Publish videos to Pumpkii YouTube channels; fetch analytics | Video files, metadata, OAuth tokens for our channel | https://policies.google.com/privacy |
| Meta (Instagram Graph API) | Publish Reels to Pumpkii IG account; fetch insights | Video files, metadata, OAuth tokens for our IG Business account | https://www.facebook.com/privacy/policy |
| TikTok (Content Posting API) | Publish videos to Pumpkii TikTok account; fetch analytics | Video files, metadata, OAuth tokens for our TikTok account | https://www.tiktok.com/legal/page/global/privacy-policy/en |
| Cloud infrastructure providers | Host the Service (database, object storage, compute) | All Service data, encrypted in transit and at rest | (varies by provider) |
We do not share data with any other third parties.
5. Platform-Specific Notices
5.1 YouTube API Services
The Service uses YouTube API Services. By using the Service to publish to YouTube, the authorizing Pumpkii staff member acknowledges that use is also subject to the YouTube Terms of Service (https://www.youtube.com/t/terms) and Google Privacy Policy (https://policies.google.com/privacy). You may revoke the Service's access to your Google account at any time via Google Security settings (https://security.google.com/settings/security/permissions). The Service complies with the YouTube API Services Terms of Service and Developer Policies.
5.2 Instagram / Meta
The Service uses the Instagram Graph API provided by Meta Platforms, Inc. By authorizing the Service, you agree to Meta's Platform Terms (https://developers.facebook.com/terms) and Privacy Policy (https://www.facebook.com/privacy/policy). You may revoke access at any time via Instagram → Settings → Apps and Websites.
5.3 TikTok
The Service uses the TikTok Content Posting API. By authorizing the Service, you agree to TikTok's Developer Terms (https://developers.tiktok.com/legal/development-terms-of-service) and Privacy Policy (https://www.tiktok.com/legal/page/global/privacy-policy/en). You may revoke access via TikTok → Settings → Privacy → Apps that can post.
6. Data Retention
| Data Type | Retention |
|---|---|
| Pumpkii staff account data | Until deleted, or 90 days after the staff member leaves Pumpkii |
| OAuth tokens | Until the user revokes authorization or the platform account is removed |
| Video files (raw uploads) | 30 days after successful publication, then deleted |
| Video metadata, prompts, publish history | Indefinitely (internal archival), unless deletion is requested |
| Platform analytics snapshots | Indefinitely (internal trend analysis) |
| Login / audit logs | 1 year, then deleted |
7. Data Security
- All data is transmitted over HTTPS (TLS 1.2+).
- OAuth tokens, passwords, and platform credentials are encrypted at rest.
- Access is restricted to authenticated Pumpkii staff via Better Auth with role-based permissions.
- The Service is hosted on private infrastructure under Pumpkii's control.
- We log administrative actions for audit and review.
We follow industry-standard practices but no system is perfectly secure. If we detect a breach affecting any data covered by this policy, we will notify affected parties and the relevant platforms within 72 hours.
8. Your Rights
If you are a Pumpkii staff member with an account on the Service, you may at any time:
- Access the personal data we hold about you (email dev@pumpkii.com)
- Correct inaccurate data
- Delete your account, which removes your account record and login history
- Revoke OAuth authorizations you previously granted, immediately invalidating tokens stored on the Service
- Export your data in a machine-readable format
To exercise any of these rights, email dev@pumpkii.com. We respond within 14 days. End users of YouTube, Instagram, or TikTok with concerns about a Pumpkii post may contact the same email or use the platform's built-in reporting tools.
9. Legal Notices
For California residents (CCPA)
Pumpkii does not "sell" personal information as defined under the CCPA. Pumpkii staff using the Service have rights to know, delete, and opt-out as described in Section 8.
For EU/UK residents (GDPR)
The legal basis for processing is legitimate interest (operating an internal business tool) for staff data, and contractual necessity for OAuth tokens used to publish to platforms the user has authorized. You have the rights to access, rectify, erase, restrict, port, and object as described in Section 8. You may also lodge a complaint with your local supervisory authority.
International Data Transfers
Pumpkii is based in China. Some data is processed by international platforms (Google, Meta, TikTok) whose servers may be located in the United States, the European Union, or other regions. The authorizing Pumpkii staff member acknowledges that data may cross national borders as part of normal API operation.
10. Changes to This Policy
We may update this policy when the Service changes or when platform policies require us to. Material changes will be communicated to current users via email. The "Last Updated" date at the top reflects the most recent revision.
Contact
For questions, requests, or complaints about this policy:
