Privacy Policy
Last updated: August 27, 2026
This Privacy Policy explains how KSP (“we”, “us”) collects, uses, stores, and protects information when you use the KSP application and website (the “Service”). By using the Service, you agree to the practices described here.
1. Information We Collect
- Account data. The email address you register with and a cryptographic hash of your password. We never store your password in plain text.
- Tracker credentials. If you choose to sync costs to your own tracker, we store the tracker domain and API key you provide, encrypted at rest, and use them solely to write your cost data.
- TikTok authorization data. When you connect your account, we receive an access token and the identifiers of the advertiser accounts you authorize. We do not receive your TikTok password.
- Advertising reporting data. We retrieve advertising metrics such as campaign, ad group and ad identifiers and names, spend, impressions, clicks, and the associated time periods (including hourly breakdowns).
- Campaign structure and review status. We read the settings and the review status of your campaigns, ad groups and ads so we can display them and alert you when a status changes. Where you use the campaign builder, we also process the settings you define — objective, budget, schedule, targeting and optimization event — in order to submit them to TikTok on your behalf.
- Creative assets. Videos, images and ad text you upload through the Service, together with the identifiers TikTok returns for them. These are used only to create the ads you asked for.
- Pixels, audiences and conversions. The names and identifiers of your pixels, custom and saved audiences and custom conversions, so you can pick them when configuring an ad group. We do not receive the underlying customer lists behind an audience.
- Ad comments. Where you use comment moderation, the comments on your own ads and the moderation actions you take on them.
- Telegram notification settings. If you enable alerts, the bot token and chat ID you provide, stored encrypted at rest and used solely to deliver your own notifications. The bot belongs to you; we do not read messages from it.
- Technical data. Basic server and session information (such as a session cookie) needed to operate the Service securely.
2. How We Use Information
- To authenticate you and maintain your session.
- To retrieve and display your TikTok advertising spend and performance reports.
- To write your advertising costs into the tracker you configured, when you request a sync.
- To run the sync automatically on the schedule you choose. Automatic sync is off by default; when you enable it, the Service repeats the same read-and-write cycle at your chosen interval until you turn it off.
- To notify you when the review status of one of your ads changes, or when a sync cannot complete — in the dashboard and, if you configured one, through your own Telegram bot. Notifications are off by default.
- To create and manage campaigns, ad groups, ads and creative assets in your authorized ad accounts, when you ask the Service to do so or according to rules you configured yourself.
- To operate, secure, maintain, and improve the Service.
We do not sell your personal data, we do not use your advertising data for advertising to you, and we do not use one customer's data to benefit another. We never act on an ad account you have not connected.
3. Data Sharing
We do not share your data with third parties except: (a) with infrastructure providers that host the Service and act on our instructions; (b) when required by law or to protect the rights, safety, and security of the Service; or (c) with your explicit consent. TikTok data is handled in accordance with TikTok’s developer and platform policies.
4. Data Retention
Access tokens are stored only for as long as needed to provide the Service and are cleared when you disconnect or when your session ends. Reporting data is retrieved on demand and is not retained longer than necessary for the reporting and reconciliation features you use. You may request deletion of any stored data at any time.
5. Data Security
Credentials such as the app secret, access tokens, tracker API keys and Telegram bot tokens are kept on our server and are never exposed to the browser. Stored secrets are encrypted at rest with AES-256-GCM, passwords are hashed, and each account's data is isolated from other accounts. We use industry-standard measures, including encrypted transport (HTTPS), to protect data in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Your Rights and Choices
- You can revoke KSP’s access to your TikTok account at any time through your TikTok settings.
- You can disconnect within the Service, which clears the stored access token for your session.
- You can request access to, correction of, or deletion of your data by contacting us.
7. International Users
Depending on where the Service is hosted, your data may be processed in a country different from your own. We take steps to ensure your data is treated in accordance with this Policy wherever it is processed.
8. Children’s Privacy
The Service is intended for business use by advertisers and is not directed to children. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
10. Data Deletion
You can delete your data from KSP at any time in either of the following ways:
- Disconnect in the app. Open the dashboard and click “Disconnect”. This immediately clears the stored access token for your session so KSP can no longer access your TikTok data.
- Revoke access in TikTok. Remove KSP's authorization from your TikTok for Business account settings. This revokes the token on TikTok's side.
- Email request. Send a deletion request to support@ksp.rest and we will permanently delete any data associated with your account within 30 days and confirm once completed.
11. Contact
For privacy questions or data requests, contact support@ksp.rest.