How Haiyuntu protects connected accounts
Haiyuntu is designed around official OAuth authorization, least-privilege access, explicit publishing confirmation and traceable operations.
Official OAuth, not shared passwords
Users authorize access on the platform's own screen. Haiyuntu does not collect or store TikTok, Facebook, Instagram, YouTube or LinkedIn passwords.
Encrypted credentials
OAuth access and refresh tokens are transmitted over TLS, encrypted at rest and available only to restricted server processes and authorized administrators. Social publishing and advertising configurations remain separated where required.
Least privilege and asset selection
Haiyuntu requests only permissions needed for demonstrated features. Users select eligible Pages, channels, professional accounts or organizations they own or are authorized to manage.
Explicit control of publishing
Users preview original content, edit text, choose destination-specific settings and confirm before any upload begins. Haiyuntu does not silently copy content from another platform or publish without confirmation.
Auditability and status
Haiyuntu records authorization, user confirmation, destination settings and platform status needed for security and troubleshooting. Platform publish identifiers and available errors are shown to authorized users.
Revocation and incident reports
Users can disconnect an account, revoke Haiyuntu in platform settings or request data deletion. Security concerns can be reported to api_service@golantechcn.com.