AI Football — Privacy Policy

Last updated: 19 September 2026

AI Football (the “Service”) is a personal, single-operator content automation project. It publishes gaming content about EA SPORTS FC Ultimate Team to social platforms. This policy explains what data the Service handles and why.

1. Summary

The Service has no end users and no sign-up. It authenticates only to social accounts owned by the operator, in order to publish the operator’s own content. It does not collect, request, buy, sell or share personal data of any third party.

2. Data the Service handles

DataWhyWhere it is kept
OAuth access and refresh tokens for the operator’s own TikTok, X, YouTube, Twitch, Telegram and Discord accounts To publish posts and videos to those accounts Encrypted-at-rest key store on the operator’s private machine; never transmitted to third parties
The operator’s own account identifiers, display name and avatar returned by the platform after authorisation To show which channel a post will go to Local configuration file on the operator’s machine
Content created by the Service (text, images, video) and the resulting post IDs To publish content and to avoid publishing duplicates Local project storage
Aggregated public metrics of the operator’s own posts (views, likes, comments count) To measure which content performs well Local project storage

3. Data the Service does NOT handle

4. TikTok data

Where the Service uses TikTok APIs, it requests the minimum scopes required to publish video to the operator’s own account (for example user.info.basic and video.publish). TikTok data is used only to perform the publication the operator requested. It is not used for profiling, advertising, model training or resale, and it is not disclosed to any third party.

5. Sharing

Data is not sold, rented or shared. It leaves the operator’s infrastructure only as API calls to the platform that the content is being published to.

6. Retention and deletion

Tokens are kept only while the corresponding channel is connected and are deleted when it is disconnected. Published content and its metrics are kept for as long as the project runs. The operator can revoke the Service’s access at any time in the security settings of the relevant platform, which immediately invalidates the stored tokens.

7. Security

Credentials are stored outside of source control on private infrastructure with restricted access. All API traffic uses HTTPS.

8. Children

The Service is not directed at children under 13 and does not knowingly process any data relating to them.

9. Changes

Updates to this policy are published at this address with a new “last updated” date.

10. Contact

Privacy questions or deletion requests: vitalyfifasvetlov@gmail.com