YKL
Privacy Terms Data Deletion Authorization Contact & Support

YKL Global Social Media Operations Platform

Privacy Policy

YKL Privacy Policy

Effective Date: August 12, 2026

1. Introduction

This Privacy Policy explains how Hangzhou YunKaiLiang Intelligent Technology Co., Ltd. ("YKL," "we," "us," or "our") collects, uses, stores, discloses, and otherwise processes information in connection with the YKL Global Social Media Operations Platform, YKL websites, applications, business tools, support channels, and related services (collectively, the "Service").

YKL is a brand operated by Hangzhou YunKaiLiang Intelligent Technology Co., Ltd. Our registered address is Room 405-2, Building 2, Lejia International Building, Wuchang Subdistrict, Yuhang District, Hangzhou, Zhejiang Province, China.

YKL provides business-facing tools intended to help organizations and their authorized personnel prepare content, manage authorized third-party platform connections, coordinate human-controlled publishing workflows, review permitted performance information, manage customer inquiries, and initiate image or video generation tasks within a separate Content Factory.

This Privacy Policy applies to:

  • visitors to our public website;
  • customers that create or administer a YKL organization account;
  • personnel and contractors authorized by a customer to use the Service;
  • persons who contact YKL for support, privacy, or review purposes; and
  • other persons whose information is lawfully submitted to the Service by a customer.

This Privacy Policy does not govern the independent privacy practices of third-party platforms or services. Those third parties process information under their own terms and privacy policies.

2. Business Use and Customer Responsibilities

The Service is designed primarily for businesses, individual business operators, and personnel acting under the authority of an organization. A customer that submits information about another person must have an appropriate legal basis and authority to do so.

Where a customer controls the purposes and means of processing information submitted to the Service, the customer is responsible for its instructions, notices, permissions, and compliance obligations. YKL processes that information to provide the Service, follow the customer's lawful instructions, maintain security, and comply with applicable law.

Organization administrators may manage member access, roles, connected accounts, and organization content. Authorized users should contact their organization administrator first for requests relating to an organization-controlled account, unless applicable law permits or requires a request to be made directly to YKL.

3. Information We Collect

The information we collect depends on how the Service is used, which features are enabled, and what permissions the user grants.

3.1 Account and Organization Information

We may collect:

  • name, business email address, and login identifiers;
  • password hashes or other authentication credentials generated by the Service;
  • organization name, business profile, industry, country or region, and website;
  • organization membership, role, permission, and administrator information;
  • account preferences, language, time zone, and notification settings; and
  • records relating to account creation, verification, login, and security.

We do not ask users to provide passwords for third-party social media accounts. Third-party platform authorization must occur through the applicable platform's official authorization process.

3.2 Connected Platform Information

If a user chooses to connect an eligible third-party account, page, channel, board, professional profile, organization page, or other business asset (a "Connected Platform Account"), YKL may process information made available through the platform's official OAuth or API services.

Depending on the platform, the permissions approved by the platform, the user's authorization, the user's account role, and the capabilities enabled by YKL, this information may include:

  • platform account identifiers, usernames, display names, profile images, and account type;
  • pages, channels, boards, professional accounts, organization pages, or other assets the user is permitted to manage;
  • authorization status, granted scopes, token status, connection time, and disconnection status;
  • user-selected posts, videos, images, captions, boards, Pins, publishing metadata, and content status;
  • publishing job records, platform content identifiers, timestamps, status, and permitted error categories;
  • permitted account, content, audience, and engagement metrics;
  • comments or interaction records only where the applicable platform permits access and YKL has enabled an approved user-facing feature; and
  • information needed to comply with platform deletion, revocation, content status, and policy requirements.

YKL may support integrations with third-party platforms such as YouTube, TikTok, Pinterest, Facebook Pages, Instagram professional accounts, LinkedIn, X, Reddit, or other services that YKL separately enables and discloses. The appearance of a platform name in this Privacy Policy does not mean that every integration, feature, permission, or account type is currently available or approved.

Each integration is subject to:

  • the user's express choice to connect the account;
  • the user's authority over the account or business asset;
  • the platform's current API availability and policies;
  • the permissions approved for YKL's application;
  • the scopes granted by the user; and
  • YKL's current technical capabilities.

3.3 Content and Files

We may process content that a user uploads, enters, imports, creates, edits, or asks YKL to generate, including:

  • draft text, captions, prompts, keywords, campaign notes, and content calendars;
  • images, videos, audio, translations, subtitles, and other media;
  • product, brand, and business information;
  • landing-page materials, form configurations, and campaign assets;
  • email templates and user-prepared follow-up content; and
  • comments, revisions, approvals, and collaboration records.

Users are responsible for ensuring that they have the rights and authority required to submit and use this content.

3.4 Publishing and Workflow Information

We may collect:

  • drafts, approval states, and publishing instructions;
  • the identity or role of the user who created, approved, or initiated an action;
  • selected platform accounts and user-selected privacy or publishing settings;
  • API request status, normalized error category, retry status, and completion status;
  • records showing that a user previewed or confirmed an action; and
  • audit records needed to investigate disputes, security incidents, or policy compliance.

YKL does not guarantee that a platform will accept, publish, distribute, or maintain any content. Platform availability, moderation, rate limits, permissions, and account restrictions are controlled by the applicable platform.

3.5 Analytics and Performance Information

Where permitted, we may process:

  • account or content performance metrics returned by a Connected Platform;
  • impressions, views, engagement, followers, comments, or similar platform-provided metrics;
  • YKL-owned operational information, such as publishing completion, workflow status, campaign labels, or inquiry attribution; and
  • aggregated or de-identified service usage information.

YKL seeks to distinguish metrics obtained from a Connected Platform from YKL-generated operational records or calculations. We do not represent YKL-generated metrics as official platform metrics.

3.6 Inquiry, Form, and Customer Relationship Information

Customers may use the Service to collect or manage business inquiries and form submissions. Depending on the form configured by the customer, this information may include:

  • name, business contact information, organization, country or region;
  • message, product interest, request details, and source information;
  • inquiry status, assignment, follow-up notes, and communication history; and
  • consent records or preferences supplied through the applicable form.

Customers are responsible for configuring appropriate notices and collecting only information reasonably necessary for their business purposes.

YKL does not use Connected Platform data to create undisclosed cross-platform identity profiles, to enrich third-party sales databases, or to identify sales leads in a manner prohibited by the applicable platform.

3.7 Content Factory and AI Generation Information

AI processing is limited to user-initiated image and video generation within the Content Factory. When a user intentionally starts such a task, YKL may process:

  • the prompt and task instructions entered by the user;
  • product information, reference materials, images, video clips, or other source media that the user intentionally selects for the task;
  • generation settings such as format, dimensions, duration, language, style, or output preferences;
  • generated images, videos, intermediate task outputs, and task status; and
  • safety, moderation, troubleshooting, and error information related to the generation task.

YKL directly obtains and integrates OpenAI API services through an OpenAI account controlled by Hangzhou YunKaiLiang Intelligent Technology Co., Ltd. YKL does not route Content Factory requests intended for OpenAI through third-party API resellers, aggregation gateways, or unofficial intermediaries. OpenAI may process user-selected Content Factory inputs for preprocessing and image-generation functions.

YKL uses Volcano Engine's Seedance service for user-initiated video generation. Seedance may receive the prompt, generation settings, and source or intermediate media necessary to complete the video task.

Connected Platform Data is excluded from external AI processing. YKL does not send social-platform account data, OAuth credentials, posts, comments, private messages, inquiries, customer emails, audience information, platform metrics, or analytics data to OpenAI, Volcano Engine, or any other AI service provider. YKL does not use Connected Platform Data to train, fine-tune, or improve a generalized AI or machine-learning model.

The publishing center does not use AI to generate or optimize titles, captions, post text, comments, replies, private messages, lead scores, intent classifications, or publishing decisions. A user may manually select a Content Factory output as publishing material, edit the accompanying content, select any required AI-generated-content disclosure, and separately confirm the publishing action.

Under OpenAI's standard API data controls, API data is not used to train OpenAI models by default unless the customer affirmatively opts in to data sharing, and limited abuse-monitoring data may be retained for up to 30 days. YKL does not represent that zero data retention applies unless YKL has confirmed and enabled the applicable control.

AI-generated output may be incomplete, inaccurate, unsuitable, or similar to other output. The user must review the output, confirm the necessary rights, and make any disclosure required by law or an applicable platform before use. AI processing never authorizes or triggers an external social-platform action.

3.8 Subscription, Order, and Usage Information

Where applicable, we may process:

  • selected service plan, entitlements, usage, quotas, or credit balance;
  • order, invoice, tax, payment status, and transaction reference information;
  • service activation, renewal, cancellation, and support history; and
  • records needed for accounting, fraud prevention, dispute handling, and legal compliance.

Payment functionality may not be available in all versions of the Service. Unless explicitly shown in an applicable offer, the existence of a plan, quota, or credit record does not mean that a payment transaction has been completed.

3.9 Device, Log, Cookie, and Security Information

We may automatically collect:

  • IP address, device and browser type, operating system, language, and time zone;
  • date and time of access, requested pages, referring page, and session activity;
  • authentication, security, access-control, and anti-abuse events;
  • application performance, API status, and normalized error information; and
  • necessary cookie, session, and preference identifiers.

We do not intend to expose third-party tokens, client secrets, OAuth codes, raw webhook secrets, or unredacted third-party error payloads in user-facing logs.

4. How We Use Information

We may use information to:

  • create, authenticate, administer, and secure accounts;
  • provide organization membership and role controls;
  • connect, display, and manage user-authorized third-party integrations;
  • prepare, review, and perform user-initiated publishing workflows;
  • display permitted platform status and performance information;
  • provide user-initiated Content Factory image and video generation;
  • manage customer-configured forms, inquiries, and follow-up workflows;
  • provide support, respond to privacy requests, and communicate service notices;
  • maintain, troubleshoot, analyze, and improve the reliability and security of the Service;
  • enforce our Terms of Service and prevent fraud, abuse, or policy violations;
  • comply with law, lawful requests, and applicable platform requirements;
  • maintain accounting, tax, audit, and dispute records; and
  • complete a corporate transaction subject to appropriate confidentiality and legal safeguards.

We do not:

  • sell Connected Platform data;
  • use Connected Platform data for unrelated advertising;
  • provide platform data to data brokers;
  • use platform data to determine creditworthiness, employment, housing, insurance, or similar eligibility;
  • use the Service to conduct unlawful surveillance or infer sensitive characteristics; or
  • guarantee audience growth, customer acquisition, sales, or platform distribution.

5. Legal Grounds Where Applicable

Depending on the applicable law and context, we process information:

  • to perform a contract or take steps requested before entering a contract;
  • with the user's consent, including OAuth authorization where required;
  • for legitimate interests such as securing, supporting, and improving a business service, where those interests are not overridden by applicable rights;
  • to comply with legal obligations; or
  • to establish, exercise, or defend legal claims.

Where processing is performed on behalf of a customer, the customer determines the appropriate legal basis for its own collection and use of information.

6. How We Disclose Information

We may disclose information only as reasonably necessary in the following circumstances.

6.1 Service Providers

We may use service providers to support:

  • cloud infrastructure, hosting, storage, backup, and content delivery;
  • email, customer support, and business communications;
  • user-initiated Content Factory image and video generation;
  • security, monitoring, troubleshooting, and abuse prevention;
  • payment processing, accounting, or invoicing where enabled; and
  • professional legal, audit, insurance, and compliance services.

For enabled features, YKL uses or plans to use:

  • Amazon Web Services (AWS) infrastructure in the AWS Asia Pacific (Singapore) Region for hosting, application infrastructure, database services, object storage, backup, and operational monitoring;
  • Tencent Enterprise Email for support, privacy, and platform-review communications;
  • Resend for enabled transactional email and user-confirmed outbound email delivery;
  • OpenAI, accessed directly through a YKL-controlled OpenAI account, for the limited Content Factory processing described in Section 3.7; and
  • Volcano Engine's Seedance service for user-initiated video generation within the Content Factory.

Resend may process recipient and sender information, email subject and body content, delivery status, and related technical metadata when an enabled email is sent. OpenAI and Volcano Engine do not receive Connected Platform Data from YKL. Service providers are permitted to process information only for the services they provide to YKL and are expected to protect it under applicable contractual and legal requirements.

6.2 Connected Platforms

When a user connects or uses a third-party integration, YKL exchanges information with the selected platform as needed to:

  • complete OAuth authorization;
  • identify eligible accounts or business assets;
  • perform the user-requested API action;
  • receive status or permitted metrics;
  • maintain security and token validity; and
  • process revocation, deletion, or policy compliance requirements.

The platform processes information independently under its own terms and privacy policy.

6.3 Organization Administrators and Authorized Users

Information may be visible to authorized members of the same customer organization according to their roles and the customer's configuration.

6.4 Legal, Safety, and Rights Protection

We may disclose information where reasonably necessary to:

  • comply with applicable law, court order, or lawful government request;
  • protect the rights, property, safety, and security of YKL, our customers, users, platforms, or others;
  • investigate fraud, abuse, security incidents, or violations; or
  • establish, exercise, or defend legal claims.

6.5 Corporate Transactions

Information may be disclosed in connection with a merger, financing, restructuring, acquisition, sale of assets, or similar transaction, subject to appropriate confidentiality, notice, consent, or other safeguards where required.

7. International Processing and Storage

YKL's primary application infrastructure is hosted on YKL-controlled Amazon Web Services (AWS) resources in the AWS Asia Pacific (Singapore) Region. This does not mean that every item of information is processed only in Singapore.

Information may be processed in other locations when:

  • a user communicates with or authorizes a third-party platform;
  • a user intentionally initiates a Content Factory task processed by OpenAI or Volcano Engine;
  • an enabled email is delivered through Tencent Enterprise Email or Resend;
  • a support, security, or professional service provider processes information;
  • an authorized user accesses the Service from another location; or
  • processing elsewhere is required for security, support, or legal compliance.

Where applicable law requires safeguards for an international transfer, YKL will use legally recognized mechanisms or other appropriate protections.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain security, comply with platform requirements, meet legal and accounting obligations, resolve disputes, and enforce agreements.

Retention depends on the type of information:

  • account and organization information is generally retained while the account is active and for a limited period afterward;
  • OAuth credentials are retained only while needed to maintain an authorized connection and are disabled, revoked, or deleted when the connection is terminated, subject to technical and legal requirements;
  • cached Connected Platform information is retained only for an approved user-facing purpose and is refreshed, updated, or deleted as required by the platform;
  • user content and workflow records are retained according to the customer's account, deletion instructions, and applicable legal requirements;
  • inquiry and communication records are retained according to the customer's instructions and legitimate business needs;
  • accounting, tax, transaction, security, audit, and dispute records may be retained for the period required or permitted by law;
  • security and technical logs are retained for a limited period appropriate to security, troubleshooting, and abuse prevention; and
  • deleted information may remain in isolated backups until overwritten under the applicable backup cycle, unless earlier deletion is technically feasible or legally required.

Following a verified deletion request, YKL generally aims to complete deletion from active systems within 30 days, unless a shorter period is required by a Connected Platform or applicable law, or retention is permitted or required for a legitimate reason.

9. Data Security

YKL uses administrative, technical, and organizational measures designed to protect information, including, as appropriate:

  • role-based access and least-privilege controls;
  • secure authentication and session management;
  • encryption in transit;
  • encryption or equivalent protection for sensitive credentials at rest;
  • server-side storage of client secrets and OAuth tokens;
  • logging, monitoring, vulnerability management, and incident response;
  • data minimization and environment separation; and
  • restrictions on exposing secrets in frontend code, logs, documents, screenshots, or review videos.

No system is completely secure. YKL cannot guarantee that unauthorized access, loss, misuse, or disruption will never occur.

10. Cookies and Similar Technologies

YKL may use cookies and similar technologies that are necessary to:

  • maintain login sessions;
  • protect accounts and prevent abuse;
  • remember language, time zone, or interface preferences;
  • route traffic and maintain service reliability; and
  • understand aggregate service operation through server logs.

As of the Effective Date, the public website does not use third-party advertising pixels or cross-site behavioral advertising trackers. If YKL later introduces optional analytics or advertising technologies, we will update this Privacy Policy and provide notice or consent controls where required.

Users can control cookies through browser settings, but blocking necessary cookies may prevent the Service from functioning.

11. User Choices and Rights

Depending on applicable law and the context, a person may have the right to:

  • request access to certain personal information;
  • request correction of inaccurate information;
  • request deletion;
  • request restriction of or object to certain processing;
  • withdraw consent, where processing relies on consent;
  • request a portable copy where required;
  • complain to an appropriate authority; or
  • exercise other rights provided by applicable law.

These rights are not absolute and may be subject to identity verification, organizational authority, legal exceptions, platform-specific requirements, and the rights of others.

Users may:

  • manage account and organization information in the Service;
  • export available account data through the applicable account and data-control interface or by contacting privacy@ykltop.com;
  • disconnect a Connected Platform Account through the applicable social account or authorization-control interface;
  • manage third-party authorization through the platform's own account settings; and
  • request deletion through the Service or the instructions at https://www.ykltop.com/data-deletion.

Authorization revocation instructions are available at https://www.ykltop.com/authorization-revocation.

Privacy requests may be sent to privacy@ykltop.com. We may ask for information reasonably necessary to verify identity, authority, account ownership, and the scope of the request. We will not ask a requester to send a third-party password, client secret, access token, refresh token, OAuth code, or webhook secret.

12. Connected Platform Disconnection and Deletion

When a user disconnects a Connected Platform Account:

  • YKL will stop making new API requests on behalf of that connection, except as needed to complete revocation, security, deletion, or legal obligations;
  • pending jobs for that connection should be cancelled or disabled where technically possible;
  • the connection and token status will be updated;
  • credentials will be revoked, invalidated, or deleted as supported by the platform and YKL's implementation; and
  • Connected Platform data retained by YKL will be deleted or de-identified according to the user's request, platform rules, and applicable retention requirements.

Disconnecting YKL does not necessarily delete content already published on a third-party platform. Users may need to manage content and authorization directly in the platform's settings.

13. Children

The Service is not directed to children. Users must be at least 18 years old and have legal capacity to enter into a binding agreement. We do not knowingly offer organization accounts to children.

If we learn that information was submitted in violation of this section, we may restrict the account and delete the information as required by law.

14. Third-Party Services and Links

The Service may link to or integrate with third-party platforms, websites, applications, and services. YKL does not control their availability, security, terms, content, or privacy practices. Users should review the applicable third-party terms and privacy policies before authorizing an integration.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Service, data practices, providers, platform requirements, or law. The updated version will be posted at this URL with a revised "Last Updated" or Effective Date.

If a change materially affects how we use information, we will provide additional notice or obtain consent where required. A user should review the current version before authorizing a new integration or using a materially changed feature.

16. Contact Us

For general support:

support@ykltop.com

For privacy, data access, export, deletion, or authorization questions:

privacy@ykltop.com

For platform review communications:

review@ykltop.com

Display name: YKL Team

Company: Hangzhou YunKaiLiang Intelligent Technology Co., Ltd.

Registered address: Room 405-2, Building 2, Lejia International Building, Wuchang Subdistrict, Yuhang District, Hangzhou, Zhejiang Province, China

Contact YKL Back to homepage
YKL
© 2026 YKL. All rights reserved.
Privacy Policy Terms of Service Data Deletion Authorization Revocation Contact & Support