How we protect your account
Last updated: July 13, 2026
When you connect a TikTok, Instagram or YouTube account to MyClippingViews, you stay in control the whole way through. You sign in on the platform's own website — your password never reaches our servers — and you grant read-only access to the public statistics of your own videos, which you can revoke at any time. This page explains exactly how that works, in plain terms.
1. You sign in on the platform, never on us
We use each platform's official sign-in flow (OAuth). When you tap
Connect in the app, we open the platform's own login
page — tiktok.com, instagram.com or
google.com — inside a secure in-app browser. You type your
password there, on their site.
2. Read-only access, by design
The access we ask for is read-only. This is not just a promise — it is what the token technically allows. It cannot post, comment, like, follow, message, delete, or change anything on your account. It can only read the public statistics of your own videos.
✓ What we can read
- Your account's basic public profile (name, @handle, avatar)
- The list of your own videos
- Their public metrics — views, likes, comments, shares — and thumbnails
✗ What we can never do
- Post, comment, like, follow or send messages
- Edit or delete your videos or profile
- Read your private messages or drafts
- Access your password or your monetization / payout data
3. Exactly what we access, per platform
Below is the precise, technical scope we request on each platform — in plain language and as the raw permission strings, so there is no ambiguity.
TikTok
-
user.info.basic— your basic public profile (account id, display name, avatar). -
user.info.profile— your public @username (handle), so your account is shown by its real name in the app. -
video.list— the list of your public videos and their public statistics (views, likes, comments, shares).
We access this data through the official TikTok API in read-only mode, in accordance with the TikTok Developer Terms and Platform Policies. We read public view metrics only — never any monetization or earnings data from your TikTok account.
Instagram connection uses the official API with Instagram Login and requires a Business or Creator account (a free setting inside the Instagram app). It does not require a Facebook Page or a Facebook account.
-
instagram_business_basic— your basic public profile and the list of your media. -
instagram_business_manage_insights— the view counts and public engagement metrics (likes, comments, shares) of your media.
We access this data through the official Meta Graph API in read-only mode, in accordance with the Meta Platform Terms and Developer Policies.
YouTube
-
https://www.googleapis.com/auth/youtube.readonly— read-only access to your channel's public videos and their statistics (views, likes, comments). We never upload, modify or delete content.
MyClippingViews uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and our use of information received from these APIs follows the Google Privacy Policy.
4. How your access tokens are stored
The access token a platform gives us is the only credential we hold, and we treat it accordingly:
- It is encrypted at rest using AES-256-GCM — it is never stored in plain text.
- It only grants the read-only scopes listed above. On its own it can do nothing else.
- When you disconnect an account in the app, the token is deleted immediately.
5. Revoke access whenever you want
You are never locked in. There are two independent ways to cut access:
- In the app — disconnect the account. Its stored token is deleted right away and we stop reading any statistics from it.
-
On the platform itself — you can revoke
MyClippingViews from your own account settings at any time, without
touching the app:
- TikTok — Settings and privacy → Security and login → Apps and services.
- Instagram — Settings → Apps and websites → remove MyClippingViews.
- YouTube / Google — your Google security permissions.
6. No risk to your account
Connecting MyClippingViews does not put your account at risk. We reach each platform through its official API, using an application that the platform itself reviews and approves. This is the standard, supported way for a third-party tool to read statistics — the same mechanism used by the analytics dashboards you may already know. Because you never share your password and we never act on your behalf, there is nothing for the platform to flag.
7. Your data and deleting your account
What we do with the data we read, the processors we rely on, and your rights are covered in full in our Privacy Policy. You can delete your account and all associated data at any time — see the Data Deletion page.
8. Questions
If anything here is unclear, email us at contact@myclippingviews.com — we're happy to explain.