MONETA · Legal
← Back to app
Privacy Policy

How Moneta handles your data.

Effective date: 24 August 2026 · Last updated: 24 August 2026
Draft under legal review. This policy was prepared to accurately describe how the application actually works, but it has not yet been reviewed by a qualified attorney and should not be treated as final legal advice. Do not rely on this as a completed compliance document until that review is done.
Contents
  1. Who we are
  2. Information we collect
  3. TikTok account data, specifically
  4. How we use your information
  5. How we share information
  6. Data retention
  7. How you disconnect TikTok or delete data
  8. Your rights (GDPR / UK GDPR / CCPA)
  9. Security
  10. Children's privacy
  11. International transfers
  12. Changes to this policy
  13. Contact us

1. Who we are

Moneta (the "App," "we," "us") is operated by LR MOBI, a business registered in South Africa, trading as part of Ideal Client Alliance. This policy explains what personal data the App collects, why, how it's stored, and the choices you have — including the specific handling of TikTok account data, since the App integrates with the TikTok API.

2. Information we collect

CategoryWhat it includesSource
Account dataEmail address, hashed password (authentication only — we never see or store your plain-text password)You, via sign-up
Content you uploadVideo files, captions, titles, notes you attach to a scheduled postYou, via the editor/calendar
Scheduling dataChosen date/time, timezone, destination platform, post statusYou, via the calendar
TikTok connection dataSee section 3 belowTikTok, once you connect your account
Technical dataStandard server logs (IP address, timestamps, error traces) used for debugging and abuse preventionAutomatically, from your device

3. TikTok account data, specifically

If you choose to connect a TikTok account (for the App's Upload/Draft or Direct Post posting modes), we store the following, tied to your Moneta account:

  • Your TikTok open ID and union ID (TikTok's own identifiers for your account — not your TikTok password, which we never see)
  • OAuth access and refresh tokens issued by TikTok, and their expiry times
  • The specific permission scopes you granted during authorization
  • Cached creator information: display name, avatar image, and posting capabilities (whether comments/duet/stitch are enabled on your account, maximum video length, available privacy levels) — refreshed periodically rather than assumed indefinitely

These tokens are stored server-side only. They are never sent to, or accessible from, your browser, and are protected by the same database access controls as the rest of your account data — readable only by our backend service, not by other users or by unauthenticated requests.

We use this data solely to authenticate your posting requests to TikTok on your behalf, at the time and in the manner you scheduled. We do not use it for advertising, do not sell it, and do not share it with any party other than TikTok itself (as the platform the data originates from and is used to post to).

If you use Manual Handoff mode instead of connecting a TikTok account directly, none of the above applies — Manual Handoff never requests or stores any TikTok (or other platform) login credentials or OAuth tokens. It only stores the scheduling metadata you entered (caption, timing, platform label), and marks the post "ready" for you to publish yourself, by hand, on the platform's own app or site.

4. How we use your information

  • To operate your account and let you sign in
  • To store, edit, and schedule the videos and posts you create
  • To publish content to TikTok at your scheduled time, when you've connected a TikTok account and chosen Upload/Draft or Direct Post mode
  • To show you the status of your scheduled and published posts
  • To maintain and secure the App (error logging, abuse prevention)

5. How we share information

We do not sell your personal data. We share information only with the following service providers, each acting on our behalf to run the App:

ProviderRole
SupabaseAuthentication, database, and private file storage for your account, videos, and scheduling data. Account-related emails (e.g. password reset) are sent through Supabase's authentication service.
TikTokReceives your OAuth authorization and the video/caption/settings for posts you schedule and choose to publish through your connected TikTok account.
RailwayHosts the application server.
PexelsProvides optional stock video/image content if you choose to use it inside the video editor. No personal account data is sent to Pexels.

We do not currently use any analytics or advertising third parties, and no payment processor is connected to this App at this time. If that changes, this policy will be updated before the change takes effect.

We may also disclose information if required to by law, or to protect the rights, safety, or property of Moneta, our users, or the public.

6. Data retention

  • Uploaded videos are kept only as long as needed: once every scheduled post referencing a video reaches a final state (published, cancelled, or failed with no further retry), the underlying video file is automatically deleted from storage.
  • Scheduled post records (captions, timing, status history) are retained as part of your account history so you can review past activity, until you delete them or close your account.
  • TikTok tokens are retained while your TikTok connection is active. Disconnecting (section 7) immediately stops the App from using them for future posts.
  • Account data is retained until you request deletion.

7. How you disconnect TikTok or delete data

You can disconnect your TikTok account at any time from within the App. Disconnecting immediately revokes the connection — the App stops using it for any future posting, and it no longer appears as an active TikTok connection on your account.

To request full deletion of your stored TikTok tokens and connection data, or deletion of your account and associated data generally, contact us at support@idealclientalliance.com. We will action deletion requests without undue delay, consistent with the rights described in section 8.

8. Your rights (GDPR / UK GDPR / CCPA)

Depending on where you live, you may have some or all of the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate data
  • Deletion — ask us to delete your personal data (see section 7)
  • Portability — request your data in a portable format, where applicable
  • Objection / restriction — object to or ask us to restrict certain processing
  • Withdraw consent — where processing is based on consent (such as connecting TikTok), you may withdraw it at any time by disconnecting
  • Non-discrimination (California residents) — we will not discriminate against you for exercising your privacy rights

To exercise any of these rights, contact support@idealclientalliance.com. We may need to verify your identity before actioning a request.

9. Security

We use industry-standard safeguards — including encrypted connections, access-controlled databases, and server-side-only handling of authentication tokens — to protect your data. No system is perfectly secure, but access to TikTok tokens and other sensitive fields is restricted to our backend service and is never exposed to end users' browsers or to other accounts.

10. Children's privacy

Moneta is intended for business and marketing use by adults. You must be at least 18 years old to create an account or use the App. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

11. International transfers

We operate globally and our service providers (Supabase, TikTok, Railway) may process data in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

12. Changes to this policy

We may update this policy as the App changes. Material changes will be reflected by updating the "Last updated" date above. Continued use of the App after a change means you accept the updated policy.

13. Contact us

Moneta is operated by LR MOBI, South Africa.
Email: support@idealclientalliance.com
Website: moneta.idealclientalliance.com

Moneta · Terms of Service