Privacy · Effective 28 July 2026
Privacy Policy
A global privacy notice for Promeo’s website, business accounts, TikTok connection, scheduling workflow, support, and security activity.
Promeo Privacy Policy
Effective date: 28 July 2026
This Privacy Policy explains how Alcaeus Development AB collects and uses personal data when a business representative visits or uses Promeo, a hosted service for scheduling and submitting approved content to TikTok.
1. Who is responsible
For account administration, service operation, security, support, and our own legal obligations, the data controller is:
Alcaeus Development AB
Registration number: 559461-9727
Fjällbrudens väg 11
132 45 Saltsjö-Boo, Sweden
Privacy contact: noel@alcaeus.app
When a business uploads content containing personal data and instructs Promeo to process it for a scheduled post, that business is normally the controller and Alcaeus acts as its processor or service provider. People appearing in a customer's post should contact that business first about the content. We will assist the business where required.
TikTok independently determines how it processes data within TikTok after a user connects an account or content is submitted. TikTok is an independent controller for that processing.
2. Scope
This policy applies to Promeo's website, business accounts, TikTok connection, scheduling workflow, support, and related security and operational activity.
At launch, the public scheduling workspace supports TikTok photo slideshows.
It does not govern TikTok, Google/Firebase, Bunny, or another third party acting for its own purposes. Their own privacy notices apply to their independent processing.
Promeo is intended only for businesses represented by adults. It is not directed to children or to personal or household users.
3. Personal data we process
Account and business data
We may process:
- business name and account status;
- the representative's name and email address;
- Firebase user identifier, authentication provider, email-verification state, and sign-in timestamps;
- IP address, user-agent and browser information, device and session information, and security events; and
- communications, support requests, and privacy requests.
Firebase Authentication manages authentication credentials. Depending on the sign-in method, Firebase may process passwords, email addresses, phone numbers, provider identifiers, IP addresses, and user-agent information. Alcaeus does not receive a readable copy of a Firebase-managed password.
TikTok connection data
When the representative connects TikTok, we may process:
- TikTok account identifier, username, display name, and profile image;
- granted scopes and permission state;
- access and refresh tokens and their expiry;
- creator settings and available privacy and interaction options;
- post or publish identifiers, processing status, and failure information; and
- connection, disconnection, and token-refresh events.
We request only TikTok permissions needed to connect the authorised account, present required posting controls, submit approved content, and report status. At launch, the core posting scope is video.publish; any additional basic account scope will be requested only when needed and shown on TikTok's authorisation screen.
Post and scheduling data
We may process:
- uploaded photos, captions, hashtags, and cover or ordering choices;
- proposed posting date, time, time zone, and status;
- privacy, interaction, music, commercial-content, own-brand, and branded-content choices;
- preview and express-approval records;
- submission attempts, TikTok responses, errors, and cancellation information; and
- technical metadata associated with uploaded files.
Uploaded media may contain images, voices, names, likenesses, or other personal data about employees, creators, customers, or other people. The business that uploads the media is responsible for having a valid legal basis, giving required notices, and obtaining necessary rights and consent.
Essential website data
Promeo uses only storage and similar technologies needed for authentication, security, session continuity, load balancing, and user preferences at launch. We do not currently use advertising cookies or optional analytics cookies.
If we later introduce non-essential analytics or advertising technology, we will update this policy and provide consent or opt-out controls where required before using it.
4. Where the data comes from
We receive personal data:
- directly from the business representative during registration, upload, scheduling, approval, support, or privacy requests;
- from TikTok when the representative authorises the connection or Promeo checks posting capabilities and status;
- from Firebase when it authenticates and secures the account;
- automatically from the representative's browser, device, and use of Promeo; and
- from the business that uploads media concerning other people.
We do not obtain data from data brokers.
5. Why we use personal data
| Purpose | Data generally used | Legal basis where GDPR-style law applies | Is it required? |
|---|---|---|---|
| Create and authenticate the business account | Account identifiers, email, verification, session and security data | Performance of the agreement with the Customer and our legitimate interest in secure access | Yes. Promeo cannot provide an account without it. |
| Connect and maintain the authorised TikTok account | TikTok identifiers, scopes, tokens, connection events | Performance of the agreement and the user's authorised request | Yes for TikTok scheduling. Without it, Promeo cannot submit posts. |
| Prepare, schedule, and submit approved posts | Media, captions, settings, schedules, approvals, publish status | Performance of the agreement; processing on the Customer's instructions where Alcaeus acts as processor | Yes for each scheduled post. Omitted settings or media may prevent submission. |
| Display posting controls and report results | Creator settings, privacy options, status and errors | Performance of the agreement and compliance with TikTok requirements | Yes for Direct Post. |
| Secure and troubleshoot Promeo | IP address, user agent, logs, failures, account and session events | Our legitimate interests in preventing abuse, maintaining reliability, and protecting users and systems | Collected automatically. Blocking essential security data may prevent use. |
| Provide support and communicate about the Service | Contact details, messages, relevant account and post information | Performance of the agreement and our legitimate interests in customer support | Optional, but we may be unable to answer without relevant information. |
| Establish, exercise, or defend legal claims and comply with law | Relevant account, transaction, communication, security, and content records | Legal obligation and legitimate interests in protecting legal rights | Required where applicable. |
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the individual's rights. Where local law requires consent for a particular activity, we will request it separately and it may be withdrawn prospectively.
We do not use personal data to make decisions producing legal or similarly significant effects about business representatives. TikTok may independently moderate or restrict content and accounts under its own rules.
6. How media is transferred to TikTok
TikTok requires photo posts submitted through its Content Posting API to be retrieved from a verified public URL. For this purpose, Promeo may temporarily upload approved media to Bunny storage and expose it through a hard-to-guess public URL.
Anyone who obtains that URL may technically be able to access the file while it remains active. Customers must not upload unnecessary sensitive or confidential material. Promeo removes the temporary copy according to the retention periods below after TikTok completes its retrieval, the post reaches a final failure, or the schedule is cancelled.
TikTok receives the approved content, caption, settings, and related submission information when Promeo submits the post. TikTok then processes that information under TikTok's own privacy policy and platform terms.
7. Service providers and other recipients
We disclose personal data only as needed for the purposes described in this policy.
| Recipient | Role and purpose | Data involved |
|---|---|---|
| Google/Firebase | Processor providing Firebase Authentication, Firestore, Cloud Functions, Hosting, and associated security and infrastructure | Account, authentication, schedule, post metadata, logs, and operational data as configured |
| Bunny | Processor providing temporary storage and public delivery of approved post media | Uploaded media, object paths, and technical request data |
| TikTok | Independent platform and controller receiving authorised content through Login Kit and the Content Posting API | TikTok connection data, approved media, captions, settings, schedules when submitted, and publish status |
| Professional advisers and technical contractors | Confidential support, security, legal, accounting, and incident response where necessary | Only the data reasonably needed for the task |
| Authorities, courts, and transaction parties | Legal compliance, protection of rights, or a corporate transaction subject to appropriate safeguards | Relevant data required by law or due diligence |
We require processors to protect personal data and process it only under appropriate instructions and contractual safeguards.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising or targeted advertising, and we do not disclose it to data brokers.
We do not use uploaded content or other Customer Content to train artificial-intelligence models, and we do not use personal data for unrelated profiling.
8. International transfers
Alcaeus is established in Sweden, but providers may process personal data in other countries.
Firebase Authentication processes data in the United States. Google states that Firebase Authentication uses data such as email addresses, passwords, phone numbers, user agents, and IP addresses for authentication, security, and abuse prevention. More information is available in Firebase's Privacy and Security documentation.
TikTok, Bunny, Firebase, and their subprocessors may process data outside the country where the business representative is located. When transfer restrictions apply, we use or rely on appropriate mechanisms such as:
- an adequacy decision or recognised data-protection framework;
- approved standard contractual clauses or equivalent contractual safeguards; or
- another transfer mechanism permitted by applicable law.
Individuals may contact noel@alcaeus.app for information about the safeguards relevant to their data.
9. Retention
We keep personal data only for as long as needed for the stated purpose, including to provide the Service, meet legal obligations, resolve disputes, and protect the Service.
| Data | Normal retention |
|---|---|
| Uploaded post media | Retained through the scheduled submission and deleted within 7 days after TikTok reports completion or final failure, or after the schedule is cancelled |
| Captions, schedules, approval records, settings, publish identifiers, and status history | 12 months after the scheduled posting time |
| TikTok access and refresh tokens | Until TikTok is disconnected or the Promeo account is closed, then promptly revoked where supported and removed from Promeo-controlled systems |
| Active business account and representative data | For the account lifetime; Promeo-controlled active copies are deleted within 30 days after account closure |
| Security and operational logs | 90 days, unless needed longer to investigate an active security incident, abuse, or legal claim |
| Support correspondence | 2 years after the support matter closes |
| Promeo-controlled backups | Expire within 30 days after deletion from active systems |
| Data needed for legal claims or statutory obligations | For the applicable limitation or legally required period, then deleted or anonymised |
Google states that Firebase Authentication keeps logged IP addresses for a few weeks and retains other authentication information until the Firebase customer initiates deletion of the user. Google may take up to 180 days after that deletion request to remove Firebase Authentication information from its live and backup systems. This provider-controlled period may therefore extend beyond Promeo's 30-day active-system deletion target.
If a submission is still processing or its outcome is uncertain, temporary media may be retained beyond the normal period only as long as reasonably necessary to prevent a failed transfer, investigate the outcome, or permit safe cleanup.
We may retain anonymised or aggregated information that can no longer reasonably identify an individual.
10. Security
We use reasonable technical and organisational measures designed to protect personal data, including access controls, encrypted network connections, provider security features, logging, least-privilege practices, and procedures for handling incidents and deletion.
No online service can guarantee absolute security. Customers must protect their Firebase and TikTok credentials, use secure devices, promptly remove access from former representatives, and notify us of suspected compromise.
If a personal-data breach occurs, we will investigate and notify affected customers, individuals, TikTok, or authorities when required by applicable law or our contractual obligations.
11. Privacy choices and rights
Depending on location and applicable law, an individual may have the right to:
- know whether and how we process personal data;
- access or receive a copy of personal data;
- correct inaccurate or incomplete data;
- delete personal data;
- restrict or object to processing;
- receive portable data in a commonly used format;
- withdraw consent without affecting earlier lawful processing;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- appeal our refusal of a privacy request; and
- receive equal service without unlawful discrimination for exercising privacy rights.
Promeo does not currently sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or conduct profiling that produces legal or similarly significant effects.
EEA, United Kingdom, and Switzerland
Individuals in these regions may exercise rights of access, correction, deletion, restriction, portability, and objection under applicable data-protection law. They may withdraw consent where consent is the basis and complain to their local supervisory authority.
United States
Residents of US states with applicable privacy laws may request access, correction, deletion, or a copy of covered personal information and may use an authorised agent where permitted. They may also appeal a denied request by replying to our decision. Because Promeo does not sell covered personal information or use it for targeted advertising, no sale or targeted-advertising opt-out is currently necessary.
Rights may be subject to legal exceptions. For example, we may retain data needed for security, legal obligations, disputes, or the rights of another person.
12. Exercising rights, deleting an account, and disconnecting TikTok
Privacy requests may be sent to noel@alcaeus.app. The request should identify the Promeo account and the right being exercised.
We may request information reasonably necessary to verify identity, authority to act for the business, or an authorised-agent request. We will respond within the period required by applicable law and explain any denial and available appeal or complaint route.
The business representative may:
- disconnect TikTok through available Promeo controls or TikTok's permission settings;
- cancel pending schedules through Promeo;
- request export or deletion of account data; and
- close the Promeo account.
Disconnecting TikTok stops future authorised submissions but does not delete content already sent to TikTok. Account deletion does not delete posts from the connected TikTok account. Those posts must be managed through TikTok.
When an account closes, we will cancel pending schedules, revoke TikTok authorisation where supported, remove tokens, and delete or retain data according to Section 9.
13. Children
Promeo is a business service for representatives aged 18 or older. We do not knowingly create accounts for children or collect children's personal data for their own use of the Service.
Customer Content must not include children's personal data unless the Customer has a valid legal basis, all required parental or guardian permissions, and has confirmed that the content and planned publication are lawful and appropriate.
If you believe a child has created an account or personal data was submitted unlawfully, contact noel@alcaeus.app.
14. Changes to this policy
We may update this policy when Promeo, our providers, legal requirements, or privacy practices change. The effective date at the top identifies the current version.
For material changes, we will provide reasonable notice through the Service or by email before they take effect unless an earlier change is required for legal, security, or platform-compliance reasons.
15. Complaints and contact
Questions, requests, or complaints may be sent to:
Alcaeus Development AB
Registration number: 559461-9727
Fjällbrudens väg 11
132 45 Saltsjö-Boo, Sweden
Email: noel@alcaeus.app
Individuals in the EEA may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority. Individuals elsewhere may contact the privacy or data-protection regulator responsible for their location.
Swedish Authority for Privacy Protection (IMY)
Integritetsskyddsmyndigheten
Box 8114
104 20 Stockholm, Sweden
Email: imy@imy.se
Phone: +46 (0)8 657 61 00
IMY contact page