Privacy Policy

AIDriven Bands — last updated: August 2026

Who operates this service

AIDriven Bands is a private social media scheduling and automation platform for music artists, operated by Diogo Nonato, based in Brazil. Contact: diogocn@gmail.com.

What data is accessed and why

The service connects social media accounts belonging to music artists to publish content on a scheduled basis. For this purpose, the following data is accessed and stored:

  • YouTube OAuth refresh token: allows publishing videos to the connected channel on behalf of the account holder without requiring a new login for each publication. No data about viewers or subscribers is accessed.
  • Instagram access token (Meta Graph API): allows publishing posts, Reels and Stories to the connected account. Includes the account identifier required for API calls. No follower data, direct messages or third-party information is accessed.
  • TikTok OAuth access and refresh tokens: obtained through TikTok's official OAuth 2.0 authorization flow. Used only to publish video content to the connected TikTok account via the TikTok Content Posting API. The account identifier required for API calls is also stored. No follower data, DMs, analytics or other TikTok user information is accessed.
  • Instagram session (cookies): for accounts using browser-based automation (Playwright), session cookies representing the authenticated state of the account holder are stored. Passwords are not stored in plain text; if stored at all, they are encrypted and used only for automatic session renewal.
  • Scheduled content: captions, media files uploaded by the operator, and the scheduled publish time for each campaign. Media files are stored on the server during the scheduling period and deleted after successful publication.
  • Performance metrics: after publication, basic engagement metrics (likes, comments, reach, impressions, plays) are collected via the platforms' APIs and stored for display in internal reports. No data about individual followers is stored.
  • Streaming data (read-only): listener counts and stream statistics from the Spotify API and Last.fm API, for correlation with campaign performance. Only aggregate artist-level metrics are collected — no user-level data from those platforms.

How data is stored

  • OAuth tokens and session credentials are stored encrypted at rest using AES-256-GCM with a 256-bit key. The encryption key is not stored alongside the data.
  • The database (SQLite) is backed up daily, with 7-day retention.
  • Media files uploaded by the operator are stored on the server until the post is published, then deleted. The server uses HTTPS with a Let's Encrypt TLS certificate.
  • No data is sent to third parties other than the platforms the accounts belong to (Meta, Google/YouTube, TikTok), strictly to carry out the publication requested by the operator. OpenAI is used for text analysis in reports; only report text — no tokens or credentials — is sent to OpenAI.

Data retention

  • Platform tokens and credentials are retained while the artist account is active in the system.
  • Published campaigns are retained for historical reporting.
  • Media files are deleted from the server after successful publication.

How to revoke access and request deletion

Account holders can revoke platform access at any time:

To request complete deletion of your data from our database, email diogocn@gmail.com with the subject line Data deletion request. Requests are processed within 30 days.

Minors

This service is intended exclusively for adult operators managing artist accounts. We do not knowingly collect data from minors.

Changes to this policy

Any changes will be published on this page. Continued use of the service after changes are published constitutes acceptance of the updated policy.

Contact

For privacy questions: diogocn@gmail.com.