lofigangs app icon lofigangs
lofigangs/Legal/Privacy
lofigangs app icon

lofigangs Privacy Policy

How lofigangs collects, uses, stores and deletes personal data.

Effective date: 30 July 2026
Last updated: 30 July 2026
Data controller: Omar Toure, publisher of Vigneux en Vrai, France
Contact: contact@lofigangs.store
Full identification: see the Legal Notice page

01Who we are

lofigangs ("lofigangs", "we", "the Service") is an editorial publishing tool operated by Omar Toure, publisher of Vigneux en Vrai, a local news outlet covering Vigneux-sur-Seine (Essonne, France). lofigangs prepares editorial content and publishes it to the social media accounts of the outlets that use it.

The data controller for the processing described here is identified in full on our Legal Notice page. Contact: contact@lofigangs.store.

02Who this applies to

This Privacy Policy covers:

lofigangs does not process personal data about the readers of the published posts, and does not collect data about any TikTok user other than the holder of a connected account.

03Data we collect

We collect only what is needed to publish to a connected account.

DataSourceWhy we need it
TikTok open ID and union ID TikTok Login Kit To identify which connected account a post belongs to.
Display name and avatar URL TikTok Login Kit (user.info.basic) To show which account is connected, so the editor does not publish to the wrong one.
Access token and refresh token TikTok OAuth To publish on the account holder's behalf without asking them to log in again.
Granted permissions (scopes) TikTok OAuth To know what the account holder actually authorised.
Content we publish: images, videos, captions, privacy setting Created by the editorial user This is the post itself.
Publication identifiers, status and timestamps TikTok Content Posting API response To confirm a post went out, and to prevent publishing it twice.
Aggregate post metrics (views, interactions) Platform APIs To report performance per post and per format. No individual reader is identified.
Technical logs (execution ID, error messages, timestamps) Our own servers To detect and fix failures, and to keep the Service secure.
Website request data (IP address, user agent) Our web server and Google Fonts — see section 09 Unavoidable in serving the page. Not used to build a profile.

What we do not collect

04Permissions we request

lofigangs requests the minimum TikTok scopes needed to do its job:

These permissions are granted explicitly during the TikTok authorisation flow and can be withdrawn at any time. Withdrawal takes effect immediately: the tokens we hold stop working.

05How we use the data

We do not use the data for profiling, for automated decision-making producing legal effects, or for advertising. We do not sell it.

06Legal basis (GDPR)

lofigangs is operated from France and complies with Regulation (EU) 2016/679 (GDPR).

ProcessingLegal basis
Providing the Service: authentication, storing tokens, preparing and publishing content, reporting results Performance of a contract — Art. 6(1)(b). The user asks us to publish to their account; we cannot do it without this data.
Connecting a social media account and granting platform permissions Consent — Art. 6(1)(a), given in the platform's own authorisation screen and withdrawable there at any time.
Technical logs, security, abuse prevention, duplicate-publication guards Legitimate interest — Art. 6(1)(f), in keeping the Service working and secure.
Retaining records where the law requires it Legal obligation — Art. 6(1)(c).

Withdrawing a platform authorisation ends our ability to publish and triggers deletion of the tokens. It does not by itself erase everything we hold; to request full erasure, see section 11.

07Where data is stored

The Service runs on infrastructure located in the European Union: a dedicated virtual server hosted by Hetzner Online GmbH (Germany) and a managed PostgreSQL database and object storage hosted by Supabase in an EU region.

Access to the servers is restricted to the operator, over authenticated connections. All traffic to and from this website and to platform APIs uses HTTPS/TLS. Access and refresh tokens are held in a restricted database table, are never displayed publicly, and are never shared.

08International transfers

Our own hosting and database are in the European Union. However, some processing necessarily involves parties that may operate or provide support from outside the European Economic Area:

Where such a transfer occurs, it relies on the mechanisms available under Chapter V GDPR, typically Standard Contractual Clauses or an adequacy decision, as set out by the provider concerned. We do not claim that no data ever leaves the EEA.

09Cookies, analytics and web fonts

This website sets no cookies and runs no analytics, advertising or tracking scripts. There is no consent banner because there is nothing to consent to on that front.

Typefaces are loaded from Google Fonts (Google Ireland Limited, and Google LLC). As a result, your browser sends a request to Google's servers when you open a page, and Google receives your IP address, user agent and the referring page as part of serving the font files. Google acts as a separate provider for that request, may process it outside the EEA under the mechanisms described in section 08, and we have no access to what it records. The legal basis is our legitimate interest in presenting the site legibly and consistently — Art. 6(1)(f).

If you would rather avoid this, a browser extension that blocks third-party font requests will prevent it; the site remains readable with fallback typefaces.

10Retention

DataKept for
Access and refresh tokensWhile the account is connected. Deleted within 7 days of disconnection or revocation.
Profile data (open ID, union ID, display name, avatar URL)While the account is connected; deleted with the connection.
Published content and publication identifiersUp to 24 months as an editorial archive, then deleted.
Aggregate post metricsUp to 24 months.
Technical logs90 days maximum.
Records we must keep by law, or must retain to establish or defend a legal claimThe period required by the applicable law, then deleted.

11Your rights, and how to delete your data

Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time.

Full step-by-step instructions, including what happens at each stage and how long it takes, are on our dedicated page: lofigangs data deletion instructions. In summary:

  1. Revoke the authorisation in TikTok: Settings and privacy → Security and permissions → Manage app permissions. This invalidates our tokens immediately.
  2. Email contact@lofigangs.store to request erasure of everything else we hold. We confirm in writing.

We answer requests within one month, extendable by two further months for complex requests, in which case we will tell you why.

If you believe your data has been handled unlawfully, you may lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr), or with the authority of your habitual residence.

12Security incidents

If a personal data breach occurs that is likely to result in a risk to your rights, we notify the CNIL within 72 hours of becoming aware of it, and inform affected users directly where the risk is high.

13Children

lofigangs is a professional editorial tool and is not directed at children. Authorised users must be at least 18. We do not knowingly collect data from anyone under 18.

14Changes to this policy

We may update this Privacy Policy. The effective date at the top of this page always reflects the current version. Material changes affecting how personal data is used are announced on this page before they take effect, and notified by email to connected users.

15Contact

Omar Toure — lofigangs
contact@lofigangs.store
Full identification and hosting details: Legal Notice