Landing PixelLanding Pixel

← Back to home

Security & privacy

This page describes the security and privacy posture of Landing Pixel in factual terms. It does not disclose internal implementation details or secret keys.

Authentication

Connection to TikTok uses the official TikTok Login Kit via standard OAuth. Passwords are never exchanged with Landing Pixel — only an authorization code that is exchanged server-side for an access token.

Server-side tokens

Access tokens are stored and used exclusively on the server. They are never exposed to the browser, never embedded in page HTML, and never rendered as part of any public endpoint.

No client secret in the browser

The OAuth client secret is held server-side only. The public site never includes credentials in client-side assets or markup.

User control

Each user connects their own account, can disconnect it from the studio, and can revoke the integration directly from TikTok at any time. Revocation stops further actions immediately.

Consent before every action

The studio requires an explicit confirmation step before any send or publish. Privacy, interaction controls, disclosure flags and music consent must all be set by the user before submission.

HTTPS everywhere

The entire public site and the Content Studio are served over HTTPS under the verified app.landingpixel.com domain. Media files are delivered from the same HTTPS host.

No data sale

Landing Pixel does not sell personal data. Information is shared only with TikTok to execute actions explicitly requested by the user, and with the technical providers needed to operate the service.

Minimal retention

We retain only the data needed to operate the service: the access token for the active session, the configuration metadata of the Content Studio, and the minimum audit trail required to operate the integration safely.

What you can do to keep your account safe

Questions about security? See Support or Contact. The legal bases for processing are described in our Privacy Policy.