Wellnotes Studio
HomePrivacyTerms Open the studio

Privacy Policy

Last updated: May 25, 2026

Wellnotes ("we", "us") operates an AI-assisted study application and associated content creation and publishing tools. This policy explains what data we collect, why, and how you can control it.

1. Data we collect

  • Account: email address and sign-in credentials when you create an account.
  • Study content: the files you upload (PDFs, photos, audio, videos, documents) and the content generated from them (notes, mind maps, quizzes, flashcards), in order to provide the service.
  • Usage data: technical information (device type, logs, anonymized statistics) to improve the application.
  • TikTok data (optional): if you connect a TikTok account, see section 3.

2. Use of data

  • Provide and operate the features (generating notes, quizzes, flashcards, publishing).
  • Sync your content across your devices.
  • Improve and secure the service.

3. TikTok integration

The TikTok integration is optional and entirely controlled by you. It only activates if you explicitly connect your account via TikTok's official authorization flow (OAuth / Login Kit). We only use TikTok's official APIs (Login Kit and Content Posting API).

3.1 Scopes requested and purpose

  • user.info.basic — retrieves your display name and profile picture, for the sole purpose of showing you which TikTok account is connected before you publish. This information is not reused elsewhere.
  • video.upload — sends the content you created in the application (photo carousels) to your TikTok inbox as a draft, which you finalize and publish yourself inside the TikTok app.
  • video.publish — publishes the content you created directly to your own TikTok account, only when you explicitly trigger direct publishing.

3.2 TikTok data we process and store

  • OAuth access and refresh tokens: stored securely on the server, linked to your TikTok identifier (open_id), so we can keep you signed in and publish on your request. Never exposed to the browser.
  • Basic profile (display name, avatar): shown during your session; not resold, not used for profiling.
  • Publishing status of the content you send (success/failure), so we can display its state in the application.

3.3 What we do NOT do

  • No publishing without your explicit action.
  • No sale, rental, or sharing of TikTok data for advertising purposes.
  • No use of TikTok data to train AI models.
  • No access to your TikTok data beyond the scopes listed above.

3.4 Revocation and deletion

You can sign out at any time via the "Sign out" button in the application: your TikTok tokens are then immediately deleted from our servers. You can also revoke access from TikTok (Settings → Security and permissions → Manage app permissions). Revocation on TikTok's side invalidates our tokens.

Use of TikTok data is also governed by TikTok's Privacy Policy and the TikTok Developer Terms of Service.

4. Sharing with third parties

We do not sell your data. We use subprocessors:

  • AI providers (e.g. OpenAI) to generate notes, summaries, quizzes, and flashcards.
  • TikTok, when you publish via the integration.
  • Hosting / infrastructure providers to store and serve the application.

5. Retention

  • Your content is retained as long as your account is active; you can delete it at any time.
  • TikTok tokens: deleted immediately on sign-out or revocation on TikTok's side.
  • The TikTok basic profile is only displayed during your session and is not retained after sign-out.

6. Security

We apply reasonable technical and organizational measures to protect your data.

7. Your rights

Under the GDPR, you have the right to access, rectify, delete, and port your data. To exercise these rights, contact us.

8. Contact

Questions: contact@wellnotes.ai.

© 2026 Wellnotes. All rights reserved.
Privacy PolicyTerms of ServiceTikTok