Security & Data

How we handle accounts, tokens and content

LIZI acts on social accounts that belong to other businesses. That only works if the boundaries are explicit โ€” so here they are.

๐Ÿ”’

Access is restricted

LIZI is not a self-serve product. Accounts are created by the operator for named users, every session is authenticated, and the application is served exclusively over encrypted HTTPS.

๐Ÿ”‘

We never see platform passwords

Social accounts are connected with OAuth. The password is entered on the platform's own domain โ€” TikTok, Instagram or Facebook โ€” and never reaches LIZI. What we receive is a scoped access token.

๐Ÿงฑ

Brands are isolated from each other

Every brand is a separate workspace with its own assets, its own plans and its own connections. A publish action is bound to the brand it was approved under, so content cannot cross into another brand's account.

โœ‹

Nothing publishes without approval

Automation stops at the approval step. A human approves each item, and only then can it be published or scheduled. There is no mode in which unreviewed content reaches a live account.

๐Ÿ—‘๏ธ

Disconnect and deletion

Disconnecting an account invalidates and removes its stored token immediately. Access can also be revoked from the platform's own security settings. Deletion requests for stored data are handled on request.

๐Ÿšซ

We do not sell data

Information is used to operate the service and nothing else. It is not sold, and it is not shared with third parties beyond the destination platform required to complete a publish you asked for.

The formal documents

This page is a plain-language summary. The binding versions are here: