Privacy Policy
Last updated: 26 September 2026
This policy explains how R2H handles information in R2H Social Core and on this website (r2h-ai.tech). R2H is an independent product studio operated by Ramy Elattar. In this policy, "R2H", "we" and "us" refer to R2H and its operator.
1. What R2H Social Core is
R2H Social Core lets a creator connect their own TikTok account and publish a video to that account. The connection uses TikTok Login Kit. The post is sent directly through TikTok's Content Posting API. A post is sent only after the creator chooses the video, caption, and settings and confirms the post. R2H Social Core does not post automatically and does not cross-post from the public publisher.
2. Information we access through TikTok
When you connect TikTok, R2H Social Core requests only these permissions:
- user.info.basic: your TikTok open ID, display name, and avatar. We use this to show which account is connected.
- video.publish: permission to post a video to the connected account and to read that post's processing status. We use it only for a post you confirm.
Before you can post, R2H Social Core asks TikTok for your creator posting options. Those options can include your username, nickname, avatar, the privacy levels your account can use, whether comments, duets, or stitches are turned off, and the maximum video duration. The publisher shows those options. It does not invent privacy choices.
We do not request access to your TikTok messages, followers, or contacts. We do not receive your TikTok password.
3. What you provide
- The video file you select, which must be an MP4 up to 32 MB.
- The caption, privacy choice, comment, duet, and stitch choices, and commercial-content choice you enter.
- Your confirmation that the post should be sent.
The video is stored on Cloudflare R2 and served from media.r2h-ai.tech under a path for your connected account, so TikTok can retrieve it when you confirm a post.
4. How tokens and the sign-in session are stored
- TikTok access tokens and refresh tokens are encrypted with AES-GCM before they are stored in Cloudflare D1. They are used only to call TikTok's API for the connected account: to read creator info, publish a confirmed video, check post status, and refresh an access token shortly before it expires.
- After you connect, the browser stores a session identifier in session storage and sends it to R2H Social Core. The session expires after 7 days or when you log out. It is not a TikTok token.
- Tokens and the session identifier are not shown in the publisher and are not written into public pages.
- TikTok app credentials stay in encrypted worker secrets.
5. Disconnect and deletion
- Log out ends the browser session. The TikTok connection remains until you disconnect it.
- Disconnect ends the session and disables the stored connection so R2H Social Core stops using it.
- Revoke on TikTok: you can remove the app in your TikTok settings. After that, R2H Social Core can no longer publish or read creator info for that account.
- Deletion request: email admin@r2h-ai.tech to ask for deletion of the stored connection, tokens, and profile fields. We will confirm when that deletion is done. A publication record without tokens may be kept so the same video is not submitted twice.
6. What we do not do
- We do not sell personal data.
- We do not use TikTok data to build advertising profiles or to share it for advertising.
- We do not use TikTok data for any purpose other than connecting your account, showing your creator options, and publishing a video you confirm.
7. Service providers
This website and R2H Social Core run on Cloudflare (Workers, D1, and R2). Cloudflare processes requests under its own terms. Publishing requests go to TikTok's API. Video files you upload are fetched by TikTok from media.r2h-ai.tech when you confirm a post.
8. Children
R2H Social Core is not directed to children and is not intended for anyone under 18.
9. Changes
If this policy changes, the updated version will be posted on this page with a new "Last updated" date.
10. Contact
Privacy questions and deletion requests: admin@r2h-ai.tech.