WILDFIRE

Privacy Policy

Last updated 24 July 2026

This Privacy Policy explains what data Wildfire (“we”, “us”), operated by MOWA Digital LLC, collects when you use the Service, how we use it, and the choices you have.

1. Data we collect

  • Account data. Your name and email, handled through our authentication provider when you sign up and sign in. We never store your password.
  • Connected platform data. When you connect a social account (e.g. TikTok, YouTube), we receive the profile information needed to show which account you’re posting to — such as your username, display name, and avatar — and the platform’s posting rules for your account.
  • Access tokens. The OAuth tokens that let us publish on your behalf, stored encrypted at rest and decrypted only in memory at the moment of publishing.
  • Content you provide. The videos, captions, and settings you upload or create in order to schedule and publish posts.
  • Usage data. Basic analytics about how the Service is used, to operate and improve it.

2. How we use data

  • to provide the Service — scheduling and publishing the content you approve to the platforms you connect;
  • to display your connected account and its posting options accurately before you publish;
  • to generate suggested copy you review and approve;
  • to secure, maintain, and improve the Service.

We do not sell your personal data, and we do not use the content of your connected accounts for advertising.

3. TikTok data

Where you connect TikTok, we access only the scopes you approve and use TikTok data solely to provide the posting features you request — displaying your creator information before a post and publishing content you have reviewed and approved. Our use and transfer of information received from TikTok APIs adheres to TikTok’s Developer Guidelines. We do not share TikTok data with third parties except the infrastructure providers below that are necessary to run the Service.

4. Service providers

We rely on a small number of third parties to operate the Service, each processing data only to provide their service to us:

  • Clerk — user authentication and account management;
  • Supabase — database and encrypted file/video storage;
  • Vercel — application hosting and delivery;
  • Stripe — payment processing (we never handle raw card data);
  • Anthropic — AI generation of suggested copy you review.

5. Retention & deletion

We keep your data while your account is active. You can disconnect any connected platform at any time, which purges the stored access tokens for that account. You may request deletion of your account and associated data by contacting us; we will delete or anonymise it except where we must retain it to meet a legal obligation.

6. Security

Access tokens are encrypted at rest and never written to logs, error messages, or responses. Tenant data is isolated at the database layer. No system is perfectly secure, but we take reasonable measures to protect your data.

7. Your rights

Depending on where you live — including under the GDPR (EU/UK) and the CCPA (California) — you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. To exercise any of these rights, contact us at the address below and we will respond as required by applicable law.

8. Changes

We may update this Policy; material changes will be posted here with a new effective date.

9. Contact

Questions or requests: admin@mowa.nyc.

Terms·Privacy·Home