Last updated: 19 September 2026
AI Football (the “Service”) is a personal, single-operator content automation project. It publishes gaming content about EA SPORTS FC Ultimate Team to social platforms. This policy explains what data the Service handles and why.
The Service has no end users and no sign-up. It authenticates only to social accounts owned by the operator, in order to publish the operator’s own content. It does not collect, request, buy, sell or share personal data of any third party.
| Data | Why | Where it is kept |
|---|---|---|
| OAuth access and refresh tokens for the operator’s own TikTok, X, YouTube, Twitch, Telegram and Discord accounts | To publish posts and videos to those accounts | Encrypted-at-rest key store on the operator’s private machine; never transmitted to third parties |
| The operator’s own account identifiers, display name and avatar returned by the platform after authorisation | To show which channel a post will go to | Local configuration file on the operator’s machine |
| Content created by the Service (text, images, video) and the resulting post IDs | To publish content and to avoid publishing duplicates | Local project storage |
| Aggregated public metrics of the operator’s own posts (views, likes, comments count) | To measure which content performs well | Local project storage |
Where the Service uses TikTok APIs, it requests the minimum scopes required to publish video to
the operator’s own account (for example user.info.basic and
video.publish). TikTok data is used only to perform the publication the operator
requested. It is not used for profiling, advertising, model training or resale, and it is not
disclosed to any third party.
Data is not sold, rented or shared. It leaves the operator’s infrastructure only as API calls to the platform that the content is being published to.
Tokens are kept only while the corresponding channel is connected and are deleted when it is disconnected. Published content and its metrics are kept for as long as the project runs. The operator can revoke the Service’s access at any time in the security settings of the relevant platform, which immediately invalidates the stored tokens.
Credentials are stored outside of source control on private infrastructure with restricted access. All API traffic uses HTTPS.
The Service is not directed at children under 13 and does not knowingly process any data relating to them.
Updates to this policy are published at this address with a new “last updated” date.
Privacy questions or deletion requests: vitalyfifasvetlov@gmail.com