Menu

Privacy Policy — Pumpkii Media Hub

How we handle data in our internal content publishing tool

Effective Date: 2026-05-05

Last Updated: 2026-05-06

Operator: Pumpkii (the "Company", "we", "us")

Contact: dev@pumpkii.com

Plain-language Summary

Pumpkii Media Hub is an internal tool used only by Pumpkii's own operations team to publish marketing videos to our own brand accounts on YouTube, Instagram, and TikTok. It does not serve external users. We collect the minimum data needed to make publishing work and we do not sell, share, or use this data for any purpose other than running this tool.

1. Scope of This Policy

Pumpkii Media Hub (the "Service") is a private, internal-use content management tool operated by Pumpkii. The Service is not offered to the public, third-party brands, or end consumers. It is used solely by authorized Pumpkii employees and contractors. This policy is separate from the general Pumpkii product privacy policy and applies only to the Media Hub Service.

  • Upload, schedule, and publish marketing videos featuring Pumpkii products to brand-owned accounts on YouTube, Instagram, and TikTok.
  • Aggregate publicly-available performance data (views, likes, comments, follower counts) from those same brand-owned accounts for internal analytics.

The Service does not collect, store, or process personal data belonging to end users of YouTube, Instagram, or TikTok (such as their viewers, followers, or commenters), beyond what is publicly visible as aggregate engagement metrics on Pumpkii's own posts.

2. Data We Collect

2.1 Account Data (Pumpkii staff)

  • Email address and display name
  • Password hash (we never store passwords in plain text)
  • Login timestamps and IP address (for security audit)
  • Role (admin, operator, viewer)

2.2 OAuth Tokens

When a Pumpkii staff member connects a Pumpkii brand account on YouTube, Instagram, or TikTok, we store:

  • OAuth access_token and refresh_token (encrypted at rest)
  • Platform identifier of the brand account (YouTube Channel ID, Instagram Business Account ID, TikTok Open ID)
  • Token expiry timestamps and granted OAuth scopes

We never request OAuth tokens from any account other than Pumpkii's own brand accounts.

2.3 Content and Analytics

  • Video files (deleted 30 days after successful publication), cover images, titles, descriptions, hashtags
  • AI generation prompts (if used) — for internal archival
  • Publish status per platform and the platform's post ID after success
  • Daily snapshots of view count, like count, comment count, follower count for Pumpkii's own posts (fetched from each platform's official API)

2.4 What We Do NOT Collect

  • Personal data of YouTube / Instagram / TikTok end users (viewers, followers, commenters)
  • Direct messages, private content, or content from accounts other than Pumpkii's brand accounts
  • Payment information
  • Device sensors, location, or contacts from any user's device

3. How We Use Data

We use the data described above only to:

  • Operate the Service: authenticate Pumpkii staff, publish videos, display analytics dashboards.
  • Maintain security: detect unauthorized access, rotate OAuth tokens, audit admin actions.
  • Improve internal workflows: assess content performance against our own goals.

We do not sell data, share with advertisers or analytics brokers, train ML models on this data, or send marketing communications based on it.

4. Third-Party Data Sharing

The Service interacts with the following third parties strictly to perform its core function:

Third PartyPurposeData SentPrivacy Policy
Google (YouTube Data API v3)Publish videos to Pumpkii YouTube channels; fetch analyticsVideo files, metadata, OAuth tokens for our channelhttps://policies.google.com/privacy
Meta (Instagram Graph API)Publish Reels to Pumpkii IG account; fetch insightsVideo files, metadata, OAuth tokens for our IG Business accounthttps://www.facebook.com/privacy/policy
TikTok (Content Posting API)Publish videos to Pumpkii TikTok account; fetch analyticsVideo files, metadata, OAuth tokens for our TikTok accounthttps://www.tiktok.com/legal/page/global/privacy-policy/en
Cloud infrastructure providersHost the Service (database, object storage, compute)All Service data, encrypted in transit and at rest(varies by provider)

We do not share data with any other third parties.

5. Platform-Specific Notices

5.1 YouTube API Services

The Service uses YouTube API Services. By using the Service to publish to YouTube, the authorizing Pumpkii staff member acknowledges that use is also subject to the YouTube Terms of Service (https://www.youtube.com/t/terms) and Google Privacy Policy (https://policies.google.com/privacy). You may revoke the Service's access to your Google account at any time via Google Security settings (https://security.google.com/settings/security/permissions). The Service complies with the YouTube API Services Terms of Service and Developer Policies.

5.2 Instagram / Meta

The Service uses the Instagram Graph API provided by Meta Platforms, Inc. By authorizing the Service, you agree to Meta's Platform Terms (https://developers.facebook.com/terms) and Privacy Policy (https://www.facebook.com/privacy/policy). You may revoke access at any time via Instagram → Settings → Apps and Websites.

5.3 TikTok

The Service uses the TikTok Content Posting API. By authorizing the Service, you agree to TikTok's Developer Terms (https://developers.tiktok.com/legal/development-terms-of-service) and Privacy Policy (https://www.tiktok.com/legal/page/global/privacy-policy/en). You may revoke access via TikTok → Settings → Privacy → Apps that can post.

6. Data Retention

Data TypeRetention
Pumpkii staff account dataUntil deleted, or 90 days after the staff member leaves Pumpkii
OAuth tokensUntil the user revokes authorization or the platform account is removed
Video files (raw uploads)30 days after successful publication, then deleted
Video metadata, prompts, publish historyIndefinitely (internal archival), unless deletion is requested
Platform analytics snapshotsIndefinitely (internal trend analysis)
Login / audit logs1 year, then deleted

7. Data Security

  • All data is transmitted over HTTPS (TLS 1.2+).
  • OAuth tokens, passwords, and platform credentials are encrypted at rest.
  • Access is restricted to authenticated Pumpkii staff via Better Auth with role-based permissions.
  • The Service is hosted on private infrastructure under Pumpkii's control.
  • We log administrative actions for audit and review.

We follow industry-standard practices but no system is perfectly secure. If we detect a breach affecting any data covered by this policy, we will notify affected parties and the relevant platforms within 72 hours.

8. Your Rights

If you are a Pumpkii staff member with an account on the Service, you may at any time:

  • Access the personal data we hold about you (email dev@pumpkii.com)
  • Correct inaccurate data
  • Delete your account, which removes your account record and login history
  • Revoke OAuth authorizations you previously granted, immediately invalidating tokens stored on the Service
  • Export your data in a machine-readable format

To exercise any of these rights, email dev@pumpkii.com. We respond within 14 days. End users of YouTube, Instagram, or TikTok with concerns about a Pumpkii post may contact the same email or use the platform's built-in reporting tools.

9. Legal Notices

For California residents (CCPA)

Pumpkii does not "sell" personal information as defined under the CCPA. Pumpkii staff using the Service have rights to know, delete, and opt-out as described in Section 8.

For EU/UK residents (GDPR)

The legal basis for processing is legitimate interest (operating an internal business tool) for staff data, and contractual necessity for OAuth tokens used to publish to platforms the user has authorized. You have the rights to access, rectify, erase, restrict, port, and object as described in Section 8. You may also lodge a complaint with your local supervisory authority.

International Data Transfers

Pumpkii is based in China. Some data is processed by international platforms (Google, Meta, TikTok) whose servers may be located in the United States, the European Union, or other regions. The authorizing Pumpkii staff member acknowledges that data may cross national borders as part of normal API operation.

10. Changes to This Policy

We may update this policy when the Service changes or when platform policies require us to. Material changes will be communicated to current users via email. The "Last Updated" date at the top reflects the most recent revision.

Contact

For questions, requests, or complaints about this policy:

dev@pumpkii.com · https://pumpkii.com

Media Hub Privacy Policy - Pumpkii | Pumpkii