Last updated: August 18, 2026
This Privacy Policy describes how Ehliyet ("we", "our", or "the Service"), operated at n8n-flow.space, collects, uses, and protects your information when you use our service, including our mobile applications and integrations on platforms such as YouTube, Instagram, TikTok, and other social media services.
What we collect depends on how you create your account. We offer three sign-in methods and each one is limited to the minimum needed to identify you.
If you choose Continue with TikTok, we use TikTok Login Kit and request two permission scopes: user.info.basic, to know which account is connected, and video.upload, so that you can send one of our videos to your own TikTok inbox as a draft. From user.info.basic we receive and store exactly four values:
We do not request or receive your TikTok videos, followers, statistics, bio, or email address.
We also store the access token and refresh token TikTok issues when you connect. They are what allow the "send as draft" feature to work without asking you to sign in again each time. They are encrypted at rest with AES-256-GCM, are never sent to your browser, and are deleted the moment you disconnect TikTok or delete your account — at which point we also ask TikTok to revoke them.
The permission we hold lets us place a video in your inbox as a draft. It does not let us publish anything: we do not request video.publish and we do not use Direct Post. A draft stays unpublished until you open TikTok and post it yourself.
Each time you send a video we keep a short record: which video, when, and whether TikTok accepted it. We keep it so we can show you the result and investigate failures. It contains no personal data beyond the link to your account, and it is deleted with your account.
We use the collected information solely for the following purposes:
We retain your account information only for as long as your account exists. You can delete your account yourself at any time from your account page; deletion is immediate and irreversible, and removes your email address, password hash, any TikTok profile information, your stored TikTok tokens, your send history, and all active sessions. If you would rather we did it for you, email us and we will complete the deletion within 30 days. Sign-in attempt records used for brute-force protection are discarded automatically after 24 hours.
You have the right to:
Ehliyet integrates with third-party social media platforms including YouTube, Instagram, TikTok, Facebook, and LinkedIn for content publishing. Your use of these platforms is subject to their respective privacy policies. We only access your accounts on these platforms with your explicit authorization and within the scope of permissions you grant.
We do not integrate with any advertising networks or analytics services that track your personal information.
Ehliyet uses TikTok in two separate and independent ways.
Our own content. We upload our own original educational videos to the single TikTok account we operate. This does not involve your account in any way. We do not hold the Direct Post permission, so nothing is published automatically — on our account or on anyone else's.
Signing you in. If you choose to sign in with TikTok, we use TikTok Login Kit with the scope user.info.basic and receive only the four values listed in section 1.2. We do not access, display, or aggregate content from your TikTok account, and we do not request Display API permissions.
Sending a video to your inbox at your request. With the video.upload scope, and only when you press the button yourself, we upload one of our question videos to your TikTok inbox through the Content Posting API. It arrives as a draft. You write the caption and decide whether to publish it, inside the TikTok app. We do not use Direct Post, we do not request video.publish, and we never publish anything to your account.
How we handle the TikTok data we receive:
Withdrawing your authorisation. You can disconnect TikTok from Ehliyet on your account page, which erases the four values above and the stored tokens from our records and asks TikTok to revoke them. If TikTok is your only sign-in method, add a password first or delete the account instead, so that disconnecting cannot lock you out. You can independently withdraw the authorisation on TikTok's side at Profile → Settings and Privacy → Security and login → Manage app permissions → Remove access. Doing either one is enough to stop any further access; doing both is the most complete.
Your use of TikTok itself remains governed by TikTok's Privacy Policy.
We set exactly one cookie, __Host-sid. It holds a random session identifier, nothing else — no personal data is stored inside it. It is marked HttpOnly (unreadable by scripts), Secure (sent only over HTTPS) and SameSite=Lax (not sent from other sites), and it expires after 30 days or when you sign out. We use no tracking, analytics, or advertising cookies.
The Service is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Email: turkeyehliyet@gmail.com