LEGAL
TikTok API Terms
Last updated 2 October 2026
ZKO Creative Ltd uses the TikTok API for one thing: publishing the video content we make to TikTok accounts we own and operate. This page sets out exactly how and why.
1. Who operates the integration
ZKO Creative Ltd (trading as ZKO Creative), company number 14285845. We are a creative and advertising agency based in Marlow, England, working with clients in the UK and internationally. Contact: hello@zko.world.
2. What we use
We connect to the TikTok Content Posting API, with TikTok Login Kit used only to authorise our own accounts, through a developer application registered with TikTok for Developers. We do not use any other TikTok API product, including the Research API, Display API, Commercial Content API or Marketing API.
3. Why we use it
To publish video content produced by ZKO Creative directly to TikTok accounts owned and operated by ZKO Creative, from our own internal production workflow. The purpose is operational: it lets our team schedule and post our studio's work without manual uploads.
4. Internal and first-party only
- The integration is used by ZKO Creative Ltd alone, for its own accounts. It is an internal tool, not a product or service.
- It is not resold, licensed, sublicensed, white-labelled or otherwise offered to any third party, and no third party has access to it or to anything obtained through it.
- We do not post to, authorise or manage accounts belonging to clients or anyone else through it.
- We do not operate it as, or inside, any software that others can use.
5. The data involved
The integration handles only what it needs to publish:
- Authorisation tokens (access and refresh tokens) issued by TikTok for our own accounts, and the account identifiers they relate to.
- Publishing metadata: the video file we upload, its caption and settings, and the status TikTok returns so we can confirm it posted.
We do not collect, access, store or process data from TikTok users or the public. No viewer data, follower or following lists, comments, messages, profile information, search data or engagement data is requested, received or retained through the API. We do not scrape TikTok, and we do not combine anything from TikTok with data about individuals from any other source.
6. Storage, security and deletion
- Tokens are stored encrypted, in systems controlled by ZKO Creative Ltd, in the UK or EEA, or with providers under UK GDPR transfer safeguards.
- Access is limited to the members of our team who run our publishing.
- Tokens are refreshed only to keep publishing working and are deleted when revoked, when an account is disconnected, or when we stop using the integration.
- We will delete any TikTok data on TikTok's request, or if TikTok terminates our access.
7. Compliance with TikTok's terms
We use the API in accordance with:
- the TikTok Developer Terms of Service and TikTok Developer Policy;
- the TikTok Terms of Service and Community Guidelines for every piece of content we publish;
- TikTok's brand and usage guidelines for how we refer to TikTok;
- published rate limits and the scopes we have been granted, which we do not exceed or attempt to circumvent;
- UK GDPR and the Data Protection Act 2018, as set out in our Privacy Policy.
If TikTok changes its terms, we will update this integration and this page to match. If we cannot, we will stop using the API.
8. Revoking access
Because the only authorised accounts are our own, revocation is in our hands: we can disconnect the application from any account at any time in TikTok's settings, and TikTok can revoke the application's access. Either way, stored tokens for that account are deleted.
9. Contact
Questions about this integration, from TikTok or anyone else: hello@zko.world.