Privacy Policy
Last updated: 22 July 2026
Boost by DracoBlue ("Boost", "the Service") is an invite-only social media scheduling service operated by DracoBlue (Jan Schütze) ("we", "us"). It lets its users connect their own social media accounts and plan, schedule and publish their content from one place. This Privacy Policy explains what personal data we process and why.
1. Controller
The controller responsible for data processing is the operator named in the Impressum. Use the contact details there for any privacy request.
2. Who uses the Service
Boost is offered on an invite basis to independent projects, creators and partner organisations ("users"). Each user connects and manages their own social media accounts.
3. Account data
To create a user account we process your name and email address and authentication data (login credentials, stored hashed). This is needed to provide access to the Service.
4. Connected social accounts & the TikTok integration
When a user connects a social account, we store the authorisation (OAuth) tokens needed to act on that account on the user's behalf. For TikTok we use the official TikTok Login Kit and TikTok Content Posting API and access the following data, solely to provide the scheduling and publishing function the user requests:
| Scope | Data / purpose |
|---|---|
user.info.basic, user.info.profile | The connected TikTok display name, avatar and account identifier, to show the user which account is connected. |
video.upload, video.create | To upload the video files the user schedules. |
video.publish | To publish those videos to the user's TikTok account at the chosen time. |
We do not read private messages and do not collect followers or analytics beyond what is needed to display the connection status.
5. What we store
- User account data (name, email, hashed credentials).
- OAuth tokens for each connected social account.
- Basic profile information of connected accounts (name, avatar, id).
- The content users schedule (media, captions, times) until published or deleted.
All data is stored on infrastructure we control (self-hosted, located in the EU/Germany). We do not sell personal data and do not share it with third parties, except transmitting a user's content to the respective platform's API (e.g. TikTok) to perform the action that user requested.
6. Legal basis (GDPR)
Processing is based on the performance of our contract with the user (Art. 6(1)(b) GDPR) and our legitimate interest in operating and securing the Service (Art. 6(1)(f) GDPR). Connecting any social account is voluntary and can be revoked at any time.
7. Retention & deletion
OAuth tokens and connected-account data are kept until the user disconnects the account in the Service or revokes access in the platform's settings (for TikTok: Settings and privacy → Security & permissions → Manage app permissions). Account data is deleted on account closure; scheduled content is deleted after publishing or on request.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability and objection, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us via the Impressum.
9. Cookies & security
The Service uses only functional cookies required for login/session management — no advertising or cross-site tracking. Access tokens are stored with access controls on our own infrastructure.
10. Children
The Service is intended for professional/organisational use by adults and is not directed at children.
11. Changes
We may update this Privacy Policy. The current version is always available at this URL with its "Last updated" date.
12. Contact
For any privacy question or request, contact jans@dracoblue.de (see also the Impressum).