Privacy Policy
What we collect
Miss Kay’s HQ reads content and performance data — posts and videos, view and engagement counts, follower counts, and the public comments left on our own posts — from social media accounts owned and operated by Miss Kay’s. It reads them only after an authorised member of our team connects that account and grants permission.
We do not collect data about accounts we do not own. We do not purchase, scrape, or otherwise obtain data about other people’s accounts.
TikTok
Through TikTok Login Kit and the Display API, on TikTok accounts Miss Kay’s owns, we read these fields and no others. For each of our own videos: id, create_time, title, video_description, duration, cover_image_url, share_url, view_count, like_count, comment_count and share_count. For the account itself: open_id and follower_count each time we sync, and — once, when the account is first connected — its username and display_name, which we keep so the tool can show which of our TikTok accounts is connected. We do not request user.info.profile.
It is read-only. We never post, comment, reply, delete or change anything on TikTok. The Display API does not expose comments, so we hold no TikTok comment and no TikTok commenter’s username — only the number of comments a video has.
Those counts are stored once a day as a snapshot stamped with that date, which is what lets us see what a video gained over a period rather than only its lifetime total. We keep that history for as long as we run the tool; nothing expires on a schedule, because the history is the whole point of it. Disconnecting a TikTok account inside the tool deletes its stored access token immediately and stops all further reading. To have stored data removed, email gatlin@misskays.com — see Data Deletion.
Through the Instagram API with Instagram Login, on Instagram accounts Miss Kay’s owns, we read: for each of our own posts and reels, id, caption, media_type, media_product_type, permalink, thumbnail_url, media_url, timestamp, like_count and comments_count; their insights, from the set views, reach, likes, comments, shares, saved, replies, ig_reels_video_view_total_time and ig_reels_avg_watch_time (Meta retires these on a rolling basis, so we ask for what applies to each kind of post and drop whatever the API rejects); the account’s followers_count; and the account-level daily reach insight, which is how many people saw anything from the account on a given day.
Instagram is the only platform we read comments from. For a public comment on one of our own posts we store its id, text, username, timestamp, like_count and parent_id, so our team can read comments from several accounts in one place. It is still read-only: replies are written in Instagram’s own app, and this tool only links out to it and records that somebody dealt with it. We never post, comment, reply, hide, or delete anything on Instagram.
One permission we ask for is named instagram_business_manage_comments, and the name overstates what we do with it. On the Instagram API with Instagram Login there is no read-only equivalent — it is the only permission that lets an app read the comments on its own posts at all. We use it to read them and nothing else; no part of this tool calls an endpoint that writes, hides or deletes a comment.
Performance figures are kept as dated snapshots with no scheduled expiry, as above. A stored comment is kept until it is deleted on request or the post it belongs to is removed from our database. Disconnecting the account deletes its stored access token and stops all further reading. To have a stored comment removed, email gatlin@misskays.com — see Data Deletion.
YouTube
Through the YouTube Data API, on channels Miss Kay’s owns or manages, we read the channel’s own uploads list and then, for each video, its snippet (title, description, publication date, thumbnail), its contentDetails (duration) and its statistics — of which we store viewCount, likeCount and commentCount. For the channel we read statistics and store the subscriberCount.
The scope we request is read-only and we never post, comment, reply or change anything on YouTube. We do not read YouTube comments: we store only how many a video has, never their text and never who wrote them.
Counts are stored once a day as dated snapshots with no scheduled expiry. Access can be revoked at any time from the Google account that granted it, and disconnecting the channel in the tool deletes its stored tokens and stops all further reading. To have stored data removed, email gatlin@misskays.com — see Data Deletion.
On Facebook Pages Miss Kay’s administers, we read, for each post the Page itself published: id, message, created_time, permalink_url, full_picture, status_type and the media_type of its attachments. For each post’s insights we ask for post_impressions, post_impressions_unique, post_clicks, post_reactions_by_type_total and post_video_views, and store impressions, reach, video views and reactions from them. For the Page we read fan_count and followers_count, and the Page insights page_impressions and page_impressions_unique.
We read the Page’s own posts rather than its feed, so posts other people write on the Page are not collected. We do not read Facebook comments or private messages, and we never post, comment, reply or change anything on the Page.
Figures are stored once a day as dated snapshots with no scheduled expiry. Disconnecting the Page in the tool deletes its stored token and stops all further reading. To have stored data removed, email gatlin@misskays.com — see Data Deletion.
What we do not do
We never publish, post, comment, reply, or send messages through a connected account. We do not use connected data for advertising targeting. We never sell or rent it, and we never transfer it to an advertising network or a data broker.
There is one exception and it is worth stating plainly, because it would otherwise contradict the sentence above. We can send a retail buyer a summary of how our own content is performing — view totals, how many posts, and which of our posts did best — through a link that expires and that we can switch off at any time. It contains no comments, no usernames and no information about any other person. Nobody else receives platform data from us in any form.
Where it is stored
In a single private database, reachable only by authorised Miss Kay’s staff, each signing in as themselves. Access tokens for connected accounts are encrypted at rest, so a copy of the database is not a copy of our account credentials.
How long we keep it
We keep performance history so we can show trends over time, and nothing in the tool deletes it on a schedule — a dated snapshot exists precisely so that last month’s figures are still there next year. A connected account can be disconnected at any time from within the tool, which deletes the stored access token for that account and stops all further collection. Anything we hold is removed on request.
Revoking our access at the platform’s end — in TikTok’s or Instagram’s own app settings, or from the Google account that granted a YouTube channel — has the same effect on collection: we can read nothing further. It does not by itself erase the history already gathered, which stays as dated snapshots until somebody removes it. Email us and we will delete it.
Comments from other people
The tool stores public comments left on our own posts, including the commenter’s public username, so our team can read and respond to them in the native app. In practice that means Instagram — it is the only platform of the four we read comments from. If you have commented on one of our posts and want that copy removed, see Data Deletion — it says exactly what we hold and how to have it removed.
