Last updated: August 5, 2026
Mind-Blowing Facts ("the Service," "we," "us") is an independently operated content service, developed and operated by an individual developer. The Service produces short-form, original educational fact videos (science, history, and psychology topics) and publishes them, on behalf of a small number of consenting creator accounts, to YouTube, TikTok, and Instagram. This policy explains what data the Service collects when a creator connects their account, how that data is used, and how it can be removed. You can reach the developer using the contact details in Section 9.
This policy applies to the data the Service collects and processes for the small number of creator accounts that have explicitly connected to it through each platform's own OAuth authorization flow. It does not apply to the platforms themselves (YouTube, TikTok, Instagram) — each of those has its own privacy policy governing your relationship with them directly. It also does not apply to end viewers who simply watch the published videos; the Service does not collect any personal data from viewers.
When a creator connects their TikTok account, the Service uses TikTok's official OAuth 2.0 login flow. We never see or store the creator's TikTok password. After the creator grants consent on TikTok's own consent screen, TikTok issues us the following, which we store:
| Data | Source | Why we store it |
|---|---|---|
TikTok open_id | TikTok OAuth response | Identifies which connected account to publish to; TikTok does not disclose the account's real username or profile to us through this identifier. |
| OAuth access token & refresh token | TikTok OAuth response | Used solely to call TikTok's Content Posting API on that account's behalf. The access token is short-lived and is refreshed automatically using the refresh token. |
| Granted scope list | TikTok OAuth response | Recorded so we never attempt an action the account owner didn't authorize. |
| A short human-readable label | Set by the developer at onboarding time | Internal reference only (e.g. "creator 1"); never shown publicly. |
The scopes we request and actually use are user.info.basic (to confirm the connected
account during onboarding) and video.publish (to publish a finished video to that
account via TikTok's Content Posting API, using the PULL_FROM_URL source type). We do
not request or use any other TikTok scope or product.
We do not access, store, or process the creator's TikTok followers, direct messages, comments, analytics beyond basic post-publish status, browsing activity, or any content other than the videos our own Service publishes. We do not use TikTok data for advertising, profiling, or any purpose other than publishing the creator's own auto-generated content to their own account.
The same minimum-necessary principle applies to YouTube and Instagram: for each connected
account we store only the OAuth token issued by that platform (via Google's OAuth 2.0 flow for
YouTube, and Meta's Graph API OAuth flow for Instagram) and the account identifier needed to
publish. YouTube tokens are scoped to video upload/management only
(youtube.force-ssl) plus read-only analytics
(yt-analytics.readonly) used to report performance back to the account owner.
Instagram publishing uses Meta's Content Publishing API under the connected account's own
authorization.
Because TikTok's and Instagram's publishing APIs fetch video by URL rather than accepting a direct upload from our server, a finished video is briefly placed at a private, time-limited URL (hosted on Backblaze B2 for Instagram, and on a pre-verified static site for TikTok) solely so that platform's servers can retrieve it during publishing. These URLs are not indexed, not linked from any public page, and are removed or expire shortly after the post is confirmed published. No creator's personal data is contained in the video file hosting step — only the finished video content itself.
We do not sell, rent, or share any creator's data with third parties. Access tokens are used exclusively to publish content to the same account that issued them, and are never used to read, modify, or act on any other account. We do not share data with advertisers, data brokers, or analytics companies. The only "third parties" involved in operating the Service are the infrastructure providers strictly necessary to run it (cloud hosting and object storage), each of which processes data only as instructed by us and does not use it for their own purposes.
Tokens are retained only for as long as an account remains connected to the Service. A creator can revoke access at any time in two ways: (a) disconnecting the app directly from that platform's own connected-apps/authorized-apps settings, which immediately invalidates the token on the platform's side, or (b) requesting removal directly from the developer via the contact details below. Either method stops all future publishing to that account immediately and results in the stored token and account record being deleted from our systems within 7 days. Video files themselves are removed from temporary hosting automatically, typically within 24 hours of a successful publish.
The Service is not directed at children, does not knowingly collect data from anyone under 13, and account connection requires completing that platform's own adult developer/creator authorization flow. All published videos are marked as not made for kids on every platform that supports that designation.
You may request access to, correction of, or deletion of any data we hold about your connected account at any time. Because this is a small, individually operated service, requests are handled directly by the developer. Contact the developer using the email address on file with the relevant platform's developer portal (TikTok, Google, or Meta), or via the contact channel listed for this app in that portal. We aim to respond to any data request within 7 days.
This policy may be updated as the Service changes. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued connection of an account after a change constitutes acceptance of the updated policy; a creator who disagrees with a change can disconnect at any time as described in Section 7.