Privacy Policy

Last updated: July 28, 2026

Zac Publisher ("the application") is a private, single-user publishing tool operated by William Zachary Morris ("the operator") to manage his own social media presence (Profe Zac and related profiles).

What data the application handles

The only data processed is the operator's own content — videos, photos, and captions he creates — which is transmitted to social platforms (Meta Platforms, YouTube, TikTok) solely to publish it to accounts and channels the operator owns.

The application does not collect, store, sell, or share any data from or about any other person. It has no users other than the operator. No cookies, analytics, or tracking of any kind are used.

Google user data

The application uses Google OAuth to access the YouTube Data API with the youtube.upload and youtube.readonly scopes. This access is used exclusively to (a) upload the operator's own videos to the operator's own YouTube channels and (b) read the channel's basic identity to label the connection. Google account credentials are never seen by the application; OAuth tokens are stored encrypted at rest on the operator's own private server and are never shared with any third party.

The application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The application uses YouTube API Services; see the YouTube Terms of Service and the Google Privacy Policy.

TikTok user data

The application uses TikTok's Login Kit and Content Posting API with the user.info.basic and video.publish scopes. This access is used exclusively to (a) post the operator's own videos to the operator's own TikTok accounts and (b) read the account's basic identity (display name) to label the connection. TikTok account credentials are never seen by the application; OAuth tokens are stored on the operator's own private server with restricted file permissions and are never shared with any third party.

Data retention and deletion

Published media is transmitted to the target platform and then deleted or archived on the operator's own server. OAuth tokens are retained until the operator disconnects the account. To request deletion of any data or revoke access, contact the operator at [email protected], revoke Google access at myaccount.google.com/permissions, or revoke TikTok access in the TikTok app under Settings → Security → Apps and websites.