How we handle accounts, tokens and content
LIZI acts on social accounts that belong to other businesses. That only works if the boundaries are explicit โ so here they are.
Access is restricted
LIZI is not a self-serve product. Accounts are created by the operator for named users, every session is authenticated, and the application is served exclusively over encrypted HTTPS.
We never see platform passwords
Social accounts are connected with OAuth. The password is entered on the platform's own domain โ TikTok, Instagram or Facebook โ and never reaches LIZI. What we receive is a scoped access token.
Brands are isolated from each other
Every brand is a separate workspace with its own assets, its own plans and its own connections. A publish action is bound to the brand it was approved under, so content cannot cross into another brand's account.
Nothing publishes without approval
Automation stops at the approval step. A human approves each item, and only then can it be published or scheduled. There is no mode in which unreviewed content reaches a live account.
Disconnect and deletion
Disconnecting an account invalidates and removes its stored token immediately. Access can also be revoked from the platform's own security settings. Deletion requests for stored data are handled on request.
We do not sell data
Information is used to operate the service and nothing else. It is not sold, and it is not shared with third parties beyond the destination platform required to complete a publish you asked for.
The formal documents
This page is a plain-language summary. The binding versions are here: