Data Protection & Privacy

Privacy Policy

Effective Date: September 11, 2026Last Updated: September 11, 2026Operator: Eser Tech

Summary of Operator & Privacy Contacts

Operating Entity: Eser Tech ("ESER AI")
Privacy Inquiries & Deletion Requests: esertech2025@gmail.com
Business Contact Address: Srijana Chowk, Pokhara, Kaski, Nepal

1. Scope and Overview

This Privacy Policy describes how Eser Tech ("ESER AI", "we", "us", or "our") collects, uses, stores, shares, and protects your personal information when you access or use the ESER AI web application, developer APIs, Model Context Protocol (MCP) server endpoints, background workers, and associated services (collectively, the "Platform" or "Services").

This policy applies to all users of ESER AI, including workspace owners, invited collaborators, API consumers, and creators who connect third-party social media accounts. Please read this policy carefully to understand our practices regarding your data and how we safeguard it.

2. Information We Collect

We collect information directly from you, automatically through your interaction with the Platform, and via authorized third-party platform integrations that you choose to connect.

3. Account and Profile Information

When you register an account or create a workspace on ESER AI, we collect:

  • Contact Details: Your email address, full name or display name, and securely salted and hashed password credentials.
  • Workspace Identification: Workspace name, team member invitations, role designations, and avatar preferences.
  • Account Preferences: Language, time zone, notification configurations, and default publishing options.

4. Connected Social Platform Information

When you connect external social media accounts (including TikTok, YouTube, Instagram, Facebook, Threads, X, Pinterest, LinkedIn, or Bluesky) to ESER AI via standard OAuth 2.0 authorization flows, we receive authorized profile metadata:

  • Provider Account Identifiers: Unique provider account identifier (e.g., TikTok open_id or union_id), handle/username, and public display name.
  • Profile Media: Public avatar/profile picture URL.
  • Account Metadata: Channel subscriber/follower counts and channel connection status, used exclusively to display connected account cards in your dashboard.

5. OAuth Tokens and Authentication Credentials

To interact with third-party social networks on your behalf, ESER AI receives and securely stores authentication credentials:

  • OAuth Access Tokens: Short-lived tokens used to execute authorized API calls (such as retrieving profile information or dispatching video posts).
  • OAuth Refresh Tokens: Long-lived tokens used to refresh expired access tokens without requiring manual re-authentication.
  • Token Security at Rest: All OAuth access tokens, refresh tokens, and provider signing secrets are encrypted at rest using AES-256 symmetric encryption. Tokens are decrypted only in memory during authorized provider requests and are never exposed in client-side bundles or public API responses.

6. User Content and Media Assets

When you use the Platform, we process content you upload or input:

  • Uploaded Assets: Video files, image files, audio tracks, thumbnail graphics, and document sources (PDFs, text notes) stored for processing and publishing.
  • Draft Copy & Transcripts: Post captions, hashtags, video descriptions, and speech-to-text transcriptions.

7. AI Prompts and Generated Content

When you interact with ESER AI’s generative AI capabilities:

  • Input Prompts: Text prompts, topic concepts, remix instructions, and creative guidance submitted to generate content.
  • Generated Outputs: AI-generated video scripts, captions, image compositions, synthesized speech audio, and rendered video clips.
  • Non-Training Commitment: We process your prompts and outputs through isolated commercial API endpoints. Your private workspace content, video drafts, and creative prompts are not sold to third parties or used to train public foundation models without your explicit prior authorization.

8. Publishing and Scheduling Data

We record data necessary to manage your publishing queue, including scheduled publication dates and times, target platform distribution selections, channel privacy settings, publication delivery status receipts, remote platform post URLs, and error diagnostics where delivery fails.

9. Developer API and MCP Data

For users utilizing developer features, we record generated API keys (stored as cryptographic hashes), request logs, IP addresses, endpoint access paths, tool invocation parameters, and response latency metrics.

10. Billing and Payment Information

When you purchase an online subscription plan through our Merchant of Record partner (Paddle), payment details (card numbers, expiration dates, CVV, billing addresses) are collected directly by Paddle through tokenized, PCI-DSS compliant interfaces. For invitation-only or manually provisioned accounts, payments or credits may be managed directly without third-party card processing. ESER AI does not store raw credit card numbers or CVV codes on its servers. We retain only non-sensitive transaction metadata: customer account identifier, subscription tier, billing period dates, invoice payment status, and credit transaction balances.

11. Technical, Log, and Diagnostic Data

When you navigate the Platform, our servers automatically record standard technical log data: IP addresses, browser type and version, operating system, device identifiers, referring URLs, access timestamps, page views, session error traces, and diagnostic performance metrics necessary to maintain infrastructure stability and defend against abusive traffic.

12. How We Use Your Information

We use the collected information solely for legitimate operational purposes, including:

  • Service Delivery: Providing, operating, maintaining, and improving ESER AI creation, rendering, and publishing tools.
  • Social Publishing: Transmitting approved video and multimedia posts to your connected social channels in accordance with your explicit scheduling instructions.
  • Account Management: Authenticating users, managing workspaces, processing subscription billings, and provisioning AI credit allocations.
  • Platform Security: Monitoring for abusive activity, defending against unauthorized access, enforcing rate limits, and investigating security incidents.
  • Customer Support: Diagnosing technical issues, responding to support inquiries, and delivering essential service notifications.

13. Third-Party Social Platform Integrations

ESER AI acts as an authorized technical intermediary between your workspace and third-party social networks. We transmit data to these platforms only when you explicitly connect an account or dispatch a publication action.

14. TikTok Data Practices (Specific Disclosure)

In compliance with TikTok Developer Terms and Review Policies, this section details our handling of TikTok user data:

1. Requested Products & Scopes:

  • Login Kit (user.info.basic): Accessed when you connect your TikTok account. We retrieve and store your TikTok open_id, union_id, display_name, and avatar_url. This data is used exclusively to verify your identity and display your connected TikTok account details on the ESER AI Social Accounts settings page (/dashboard/settings/social-accounts).
  • Content Posting API (video.upload, video.publish): Planned for video publishing workflows. When you schedule or publish videos to TikTok, we transmit video media, caption text, and creator settings (such as privacy level and commercial content indicators) directly to TikTok’s publication endpoints via secure server-to-server calls. (Note: Content Posting API features activate only upon formal TikTok developer approval).

2. Data Usage Limitations: We do not use TikTok user data for any purpose other than providing the specific features requested by you within ESER AI. We do not sell, lease, or transfer TikTok user data to data brokers, advertising networks, or unauthorized third parties, nor do we use TikTok data to build user profiles for external commercial advertising.

3. Disconnection and Credential Deletion: When you disconnect your TikTok connection in ESER AI, the system immediately and permanently deletes all stored TikTok OAuth access and refresh tokens from our active database. Following disconnection, ESER AI retains no active credentials to access your TikTok account.

15. Other Third-Party Providers

Depending on the features you configure, ESER AI interacts with:

  • Google / YouTube API Services: ESER AI uses YouTube API Services to allow you to connect your YouTube channel and publish videos and Shorts. By using these YouTube features, you agree to be bound by the YouTube Terms of Service and acknowledge that your data is handled in accordance with the Google Privacy Policy. You may manage or revoke ESER AI's access to your Google/YouTube account data at any time via the Google Security Settings page. When you disconnect your YouTube account from ESER AI, stored OAuth access tokens and credentials are deleted immediately.
  • Meta Platforms (Instagram, Facebook, Threads): Utilizing Meta Graph APIs for publishing and media containers.
  • X (formerly Twitter), Pinterest, LinkedIn, Bluesky: Utilizing official developer APIs for publishing and media transmission.
  • AI Model & Voice Providers: External AI inference APIs (commercial LLMs, image/video generators, and voice synthesis providers) used to process prompt requests in ephemeral execution environments.

16. Service Providers and Infrastructure Partners

We engage trusted third-party service providers to support our operations under strict confidentiality and security commitments: cloud server hosting, managed PostgreSQL database infrastructure, Redis caching, authorized payment processing and Merchant of Record services (Paddle, where online checkout is active), and transactional email delivery.

17. Data Sharing and Disclosure Boundaries

We do not sell your personal data. We disclose information only under the following limited circumstances:

  • With Your Direction: Transmitting posts, media, and metadata to third-party social networks you have authorized.
  • To Service Providers: Sharing necessary information with verified hosting, database, payment, and AI inference vendors bound by data protection obligations.
  • For Legal and Safety Compliance: Disclosing information when reasonably necessary to comply with valid legal processes, subpoenas, court orders, or applicable regulations, or to protect the safety, rights, or property of ESER AI, our users, or the public.
  • Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of our business, subject to customary confidentiality protections.

18. Data Retention Policy

ESER AI maintains the following data retention standards:

1. Active Account Data: Account profile, workspace settings, source documents, drafts, and media assets are retained while reasonably necessary to operate your active account and provide the requested Services.

2. Social OAuth Disconnect: When a connected social account is disconnected by the user in dashboard settings, stored OAuth access tokens and refresh tokens associated with that connection are immediately and permanently removed from our active database.

3. Account Deletion Requests: Ordinary account, profile, source, and user media database records are deleted upon request processing, with physical media object purge across external cloud storage targeted for completion within thirty (30) days of receiving a verified account deletion request submitted to esertech2025@gmail.com where operationally feasible.

4. Residual Backups: Encrypted residual backup snapshots and volume archives age out through standard automated infrastructure rotation cycles within up to ninety (90) days.

5. Legitimate Exceptions: Billing transaction records, tax and accounting invoices, platform security telemetry, fraud prevention logs, dispute archives, and provider delivery receipts may be retained for longer statutory periods as required or permitted by applicable law.

19. Account Disconnection vs. Account Deletion

We distinguish between two distinct user actions:

  • Disconnecting a Social Account: Initiated via /dashboard/settings/social-accounts. Immediately purges OAuth access and refresh tokens from our database. Historical published post logs remain visible in analytics for reporting, but no further actions can be taken on that social channel.
  • Deleting Your ESER AI Account: Initiated by submitting a written request to esertech2025@gmail.com. Terminates your user identity, revokes active authentication sessions, purges stored OAuth credentials across all connected networks, and queues workspace media assets and project drafts for removal.

20. User Privacy Rights & Deletion Requests

Depending on your jurisdiction (such as under the General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA)), you may possess legal rights regarding your personal data, including the right to access, rectify, or request erasure of your personal information, the right to data portability, and the right to withdraw consent.

To submit an account deletion request or exercise any privacy right, please contact our privacy desk at:esertech2025@gmail.com

We respond to verified requests within thirty (30) days or the timeframe required by applicable law.

21. Security Safeguards

ESER AI implements technical, administrative, and physical safeguards designed to protect personal data against unauthorized access, loss, alteration, or disclosure:

  • Encryption in Transit: All traffic between user browsers, APIs, and external servers is encrypted using modern TLS (HTTPS) protocols.
  • Encryption at Rest: Sensitive provider OAuth tokens and signing secrets are encrypted in database tables using AES-256 symmetric encryption.
  • Tenant Isolation: Multi-tenant workspace data is strictly isolated at the database query layer.
  • Access Controls: Server infrastructure access is restricted to authorized personnel via secure authentication channels.

22. International Data Transfers

ESER AI infrastructure is hosted on cloud servers. If you access the Services from outside the host region, your information will be transferred to and processed in jurisdictions that may have different data protection standards than your home country. By using the Platform, you acknowledge such transfers in accordance with this policy.

23. Children’s Privacy

The Platform is intended exclusively for content creators, businesses, and individuals who are at least 18 years of age. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal information from a child under 16 without parental consent, we will take immediate steps to delete such information.

24. Cookies and Local Storage

ESER AI uses essential cookies and browser local storage strictly necessary to maintain your authenticated session and workspace context, remember user interface preferences (such as light/dark mode and collapsed sidebars), and defend against cross-site request forgery (CSRF) attacks. We do not utilize third-party cross-site tracking cookies for external behavioral advertising.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our legal obligations, data practices, or platform features. When revisions occur, we will update the "Last Updated" date at the top of this document and notify users through dashboard alerts or email when material changes take effect. Your continued use of the Services following notice constitutes acceptance of the revised policy.

26. Contact and Privacy Inquiries

If you have questions, feedback, or requests regarding this Privacy Policy or our data protection practices, please contact our privacy desk:

Operating Entity: Eser Tech

Attention: Data Privacy & Compliance

Working Privacy Contact: esertech2025@gmail.com

General Inquiries: esertech2025@gmail.com

Business Contact Address: Srijana Chowk, Pokhara, Kaski, Nepal