Paradise PostPrep privacy
Projects on your device
The app keeps imported videos, transcripts, content briefs, drafts, and publishing history in its local project library. Preparation runs on your device. This OAuth service does not receive or store those projects or their content. Mac and iPhone libraries are separate.
Use Delete project in the app to remove that project's app-managed video and metadata from the current device. This does not remove copies you exported or shared, a copy in a device backup, or a post already published on a platform.
Optional Qwen model download
Apple's installed language model is the default. If you choose Download Qwen in Settings → Models, the app requests six required Qwen model asset files from the pinned MLX Community repository on Hugging Face. It downloads a file only when the local copy is absent or fails validation, then keeps verified files in the app's storage for local generation. The model files total approximately 3.1 GB.
Those requests identify the model files and contact Hugging Face over the network. No recording, audio, transcript, notes, content brief, draft, skill document or generation prompt is included in the model-file request. Hugging Face may collect service-use, session, IP address, cookie and device information under its privacy policy. Its policy does not specify the exact analytics recorded for each model-file download. Paradise PostPrep does not receive or store Hugging Face download analytics.
You can remove the Qwen files from this device in Settings → Models. Removing local files does not erase records held by Hugging Face; contact Hugging Face under its policy for questions about its data.
Connected accounts
Meta and TikTok authorization codes and token responses pass through this service only during a connection request. The service checks the signed state and code verifier, exchanges the code with the selected provider, and returns a short-lived access token to the app. It discards any TikTok refresh token instead of returning it. This version does not persist provider authorization codes, user tokens, selected account identifiers, device-issued capability secrets or connected-account records, and it cannot refresh a connection. Meta and TikTok app credentials and the state-signing key are stored as Heroku config variables for code exchange.
The app saves the access token and selected provider account on this device in Keychain. Mac and iPhone account connections are separate. When the token expires, the app asks you to authorize the account again.
Publishing and deletion
Only after you approve publishing does the app send the selected video and metadata directly to the selected platform. The platform processes and retains that content under its own privacy rules. Deleting a local project or disconnecting an account does not remove a published post; delete the post in the platform if you want it removed there.
Disconnect removes that device's saved access token. It does not revoke the provider's authorization. For TikTok, use Profile → Menu → Settings and privacy → Security & permissions → Apps and services permissions → Paradise PostPrep → Remove access. TikTok explains how to remove a connected app. You can remove Meta or Google grants in their account settings. This service cannot delete a credential from a lost device because it keeps no connected-account record.
This service has no Paradise PostPrep user account.
Service providers
Heroku hosts the Meta and TikTok account-connection service. Authorization codes and token responses pass through it during a connection. An Essential-0 Postgres add-on from the earlier design was removed on 21 September 2026. This stateless service never connected to it or wrote connected-account records. The add-on's historical contents were not inspected before removal. Heroku's router records connection IP addresses, request paths, request IDs, response status and timing in operational logs. The deployment is configured to redact OAuth callback query strings from Heroku router logs; the operator verifies the router feature and a harmless log probe before enabling provider sign-in. The IP address remains in those logs. For a Cedar app, Heroku documents a limited Logplex buffer of the most recent 1,500 consolidated log lines, roughly a week; new log volume can displace lines sooner. This is not a fixed deletion time or a complete record. Logging add-ons or drains can forward copies elsewhere with separate retention. On 21 September 2026, the deployment's v21 build reported Heroku-24, a Heroku CLI check counted zero configured log drains, and the Resources page showed no add-ons. These dated checks do not establish that Cedar Logplex applies to this deployment; operators can later change add-ons or drains. Paradise PostPrep uses operational logs for troubleshooting, not advertising analytics, and this service does not use advertising trackers.
On iPhone, TikTok Login Kit is used when you choose Connect TikTok. It handles TikTok authorization under TikTok's privacy policy. The app does not use Login Kit to upload your recording.
When an approved upload proceeds, the selected platform—YouTube, Instagram, or TikTok—receives the approved video, including any audio, and the approved metadata directly from your device. Each platform may keep the upload and resulting post under its own rules: Google's policy for YouTube, Meta's policy for Instagram, and TikTok's policy. Deleting the local project or disconnecting the account in Paradise PostPrep does not erase content already sent to a platform; manage that content on the platform.
For questions or deletion guidance, email barrett@sosuke.com. Do not send authorization codes, access tokens, or passwords by email.