Privacy Policy
Last updated September 7, 2026
This policy explains what GGO Academy, at https://ggo-academy.borgrise.com (the "Service"), collects when you use it, how that information is used, who it is shared with, and how you can control it.
The short version: we collect only what the features need; TikTok data is read only after you authorize it and stops when you disconnect; we do not sell your data or use it for advertising.
What we collect
- Account information: your email address, display name, and the account type you chose at signup (creator or coach). Passwords are stored hashed by our authentication provider; we never see them in plain text.
- What you create in the Service: workspace names, content plans, ideas, the products you add to a plan or send to research, and the product or video links you paste.
- TikTok data: read only after you authorize it, as described in the next section.
- Coaching relationships: invitations, when they were accepted or ended, and which coach is linked to which creator.
- Technical information: cookies that keep you signed in and remember your language, and server logs containing IP address, browser type and time of access. We do not use third-party analytics or advertising trackers.
Data from TikTok
A workspace can be connected to one TikTok account through two independent grants. Each grant takes effect only after you explicitly approve it on TikTok's own pages.
- TikTok for Developers (Login Kit): your basic profile (open_id, union_id, display name, avatar, username) and your list of videos (video id, title, cover, publish time, duration, and view, like, comment and share counts). Used to list your videos in Video Trace. The scopes requested are user.info.basic, user.info.profile and video.list.
- TikTok Shop Creator: your creator identity, the products in your showcase, affiliate marketplace search results, and the sales performance of your shoppable videos (GMV, orders, items sold, click-through rate and similar). Used for product research in Content Lab and for the sales columns in Video Trace. Reading video sales performance requires the TikTok Shop scope creator.video.write; that is what TikTok requires for the endpoint, and we never use it to post or change a video.
Access tokens: after you authorize, TikTok issues tokens that let us call its APIs on your behalf. They are stored encrypted with AES-256-GCM, used only to call TikTok, and never shown to anyone, including your coach.
We never post, edit or delete videos on your behalf, never change your showcase, and never read your messages or any data not listed above.
How we use it
- To provide the features: workspaces, plans, syncing videos and sales, researching products and videos.
- To sync the TikTok data you authorized in the background, so the numbers on the page stay current.
- To let a coach whose invitation you accepted view your workspaces (read-only).
- To send coaching invitations and the account emails that are necessary, such as signup verification.
- To keep the Service secure, diagnose problems and prevent abuse.
We do not sell your data to anyone, and we do not use it to show advertising to you or to anyone else.
About the research features
Product Breakdown, Video Breakdown and the research inside Content Lab process public TikTok Shop product pages, buyer reviews and public videos: we fetch that public content, download and transcribe the video where needed, and pass it to AI models to produce an analysis.
What is sent for processing is public product and video content. Your access tokens, email address and password are never part of it.
Who can see your data
- You: your workspaces are visible to and editable by you alone.
- Your coach: only after you accept their invitation can they view your workspaces, and only to read. You can disconnect at any time.
- Processors that provide the Service for us: Supabase (authentication, database and file storage), OpenAI (speech transcription and text analysis), TikHub (public TikTok Shop product and video information), Resend (invitation emails), and TikTok itself (through its official APIs). Each may process data only as needed to provide its service to us.
- Legal requirements: we may disclose information when a law, regulation or competent authority requires it.
Your data is stored on cloud infrastructure that may be located outside your country, including in the United States.
Retention and deletion
- TikTok access tokens: deleted immediately when you disconnect. You can also revoke access from TikTok's connected-apps settings.
- Synced TikTok data (video list, sales, showcase): stops updating when you disconnect; contact us to have it cleared.
- Workspaces: archiving only hides a workspace from the sidebar. Nothing is deleted.
- Your account: to delete your account and all of its data, email us and we will handle it within a reasonable time.
- Server logs: kept for a limited period, for security and troubleshooting.
Security
Every connection is encrypted with HTTPS. Access tokens are encrypted at rest, and row-level access control is enabled on every database table, so a coach can only read what they have been granted.
No system is perfectly secure. If a security incident affects your data, we will notify you as soon as we can.
Your rights
You can view and edit your account information and workspace content, disconnect TikTok, end a coaching relationship, or ask us to delete your account and data at any time.
Depending on where you live, you may also have rights to access, correct, delete, restrict the processing of, or export your data, and to withdraw consent. To exercise them, contact us at the address below.
Children
The Service is for people aged 18 and over. We do not knowingly collect personal information from minors; if you believe a minor has given us information, contact us and we will delete it promptly.
Changes to this policy
We may update this policy. We will announce material changes in the Service or by email, and update the date at the top of this page.
Contact
Questions about this policy or your data? Email support@borgrise.com.