Privacy policy
MCP SMM connects your YouTube and TikTok accounts to the AI apps you use. This policy explains what data that involves, what we do with it, how long we keep it and how you stay in control.
Who we are
MCP SMM (mcpsmm.com) is operated by an independent developer, referred to here as “we” or “us”. For any question about your data, write to privacy@mcpsmm.com.
Data we collect
- Your MCP SMM account: email address, name, a hash of your password (never the password itself) and sign-in sessions with the IP address and browser they came from.
- Connected social accounts: channel or account ID, handle, display name, avatar URL, account type, the permissions you granted, and the OAuth access and refresh tokens. Tokens are encrypted with AES-256-GCM. We also keep a few profile counters, such as subscriber, follower and video counts, to show them on your dashboard.
- AI app connections: which AI apps you allowed to use your account and the tokens issued to them. API keys are stored only as SHA-256 hashes.
- Activity log: for each tool call, the tool, result, a short summary, the app that made the call, how long it took and a copy of the request with tokens, passwords and other secrets removed.
- Media: files you upload, or ask your AI to import from a link, so they can be published to YouTube or TikTok.
- Settings: your time zone, which tools are switched on, saved prompts and daily usage counters.
Data from YouTube and TikTok
MCP SMM fetches data from YouTube and TikTok on demand, when you or your AI ask for it, and passes it to you or your AI app. We don’t build a copy of your channel. The exceptions are short-lived caches that keep the service fast and within platform quotas, and comments and TikTok direct messages cached for your inbox for up to 90 days. TikTok only returns recent messages through its API, so message history comes from TikTok’s notifications to MCP SMM. YouTube data follows the stricter rule in the YouTube section below.
How we use data
We use your data only to run MCP SMM: to perform the actions your AI requests, show your dashboard, enforce limits, keep the service secure and answer your questions. We don’t sell your data, don’t show ads, don’t use your data to train AI models and don’t build profiles about you or your audience.
Your AI provider
When your AI app calls an MCP SMM tool, we send the result of that call to the app, and the app’s provider (for example Anthropic, OpenAI or xAI) handles it under its own terms and privacy policy. MCP SMM sends data only in response to tool calls made through apps you connected. You can see every call in the activity log and revoke an app at any time.
Who else receives data
- YouTube and TikTok receive the requests needed to perform the actions you or your AI start.
- Our hosting provider stores the service’s servers, database and backups.
- Our email provider delivers account emails, such as password resets.
- Authorities, only when the law requires it.
We don’t share your data with anyone for advertising or marketing.
YouTube API Services
MCP SMM uses YouTube API Services. By connecting a YouTube channel, you agree to be bound by the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.
- What we access: your channel details, videos, playlists, comments, captions and YouTube Analytics reports, using the permissions “manage your YouTube videos, comments and captions” and “view YouTube Analytics reports”.
- How we use it: to show it to you and your AI app and to make the changes you ask for, such as editing a video, uploading or replying to a comment.
- How long we keep it: YouTube data, including cached comments, is refreshed or deleted within 30 days. Tokens are deleted as soon as you disconnect the channel.
- How to revoke access: disconnect the channel under Social accounts, or remove MCP SMM on Google’s third-party access page.
MCP SMM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
TikTok
Connecting a TikTok account uses TikTok API for Business. TikTok’s handling of your data is described in the TikTok Privacy Policy.
- What we access: your profile and account insights, your videos and their metrics, comments, publishing and, for Business accounts, direct messages in conversations people start with you.
- How to revoke access: disconnect the account under Social accounts, or remove MCP SMM from the apps connected to your TikTok account in TikTok’s settings.
How long we keep data
- Account, settings and saved prompts: until you delete your account.
- Platform tokens: until you disconnect the account or delete your MCP SMM account.
- Activity log: 90 days.
- Uploaded and imported media: 14 days after upload.
- Cached comments and messages: up to 90 days (YouTube data: 30 days).
- Backups: overwritten on a rolling basis within 7 days.
Security
Connections to MCP SMM are encrypted with TLS. Platform tokens are encrypted at rest, passwords and API keys are stored only as hashes, and AI apps get access only after you allow it on the consent screen. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
Your choices and rights
- See what your AI did in the activity log and export it as JSON.
- Correct your name under Settings.
- Disconnect accounts, revoke AI apps and API keys at any time.
- Delete your account and all data under Settings. Data deletion explains what is removed.
- Ask for a copy of your data, a correction or deletion, or object to processing, by writing to privacy@mcpsmm.com. We answer within 30 days.
Children
MCP SMM is not intended for anyone under 16, and we don’t knowingly collect their data.
Changes to this policy
When we change this policy, we update the date at the top. If a change affects how we use your data in a significant way, we tell you by email before it takes effect.