Your data, explained.
Last updated: October 11, 2026
This policy covers the public website, local video preview and account authorization test module. TikTok connections activate only after configuration, site sign-in and explicit user authorization.
1. Who operates this website
Yihe Global is operated by 佛山一合跨境电子商务有限公司, based in Foshan, China.
2. Information used in this preview
The public website is open to visitors. The account test module uses ChatGPT sign-in and separate TikTok authorization; there are no payments or contact forms. If you select a video or type a caption in the workspace preview, the page uses it in browser memory for local preview only. This version does not send that file or caption to our server and does not store it in a database or browser storage. Refreshing or leaving clears the draft.
3. Hosting and technical requests
The website is hosted through OpenAI Sites infrastructure. Hosting providers may process connection and request information needed to serve, protect and operate the website. This website is publicly accessible without signing in. Fonts use your device’s local fonts. This site does not add advertising trackers or analytics scripts.
4. Account authorization and data
Account management uses the hosting platform's stable signed-in user ID to separate users. When you connect TikTok, official OAuth requests profile, account statistics and public video permissions. We do not collect TikTok passwords or request publishing permissions in this phase.
The server stores your user ID, TikTok open_id, granted scopes, update time and AES-GCM encrypted access and refresh tokens in the hosting platform's Cloudflare D1 database. The encryption key is held in server-side secret configuration. Tokens are retained until you disconnect or request deletion. Expired tokens are not used, but records may remain until disconnected.
Profiles and video statistics are fetched from TikTok on demand and displayed without storing historical statistics. Your browser visits video links you choose to open. Short-lived HttpOnly, Secure authorization cookies and single-use verification records prevent request forgery. Verification records expire after 10 minutes, are deleted on use, and expired records are cleaned on subsequent authorization starts. ChatGPT sign-in also uses hosting-managed session state.
OpenAI, Cloudflare and TikTok process data for their respective services. This deployment does not promise mainland China data residency; processing may take place abroad. Actual storage regions and cross-border processing information must be confirmed before general customer launch.
5. Your choices
You can use the company pages without selecting a video. Use “Clear preview” to clear local selections and captions. For privacy questions or requests to access, correct or delete personal information you have sent us, email privacy@yiheglobal.net. Describe your request without sending passwords or access tokens. Use “Disconnect & delete” in account management to remove the local authorization record and request TikTok revocation. If revocation is not confirmed, remove app access within TikTok as well. Your TikTok videos are not deleted.
6. Email communications
If you email support@yiheglobal.net or privacy@yiheglobal.net, your email address, message and any attachments are processed to respond to your inquiry. Incoming messages are routed through Cloudflare Email Routing to a company-managed NetEase 163 mailbox. Email providers process the messages as part of delivery and storage. These domain addresses are forwarding addresses, not separate mailboxes; replies may come from our company-managed mailbox.
You may request deletion of messages you have sent us by contacting the privacy address. We may need enough information to identify the relevant correspondence. Do not include sensitive information that is unnecessary for your inquiry.
7. Changes
We will revise this notice as the service develops. Changes to features and integrations require a policy matching the actual implemented service.