WunderKindy

Privacy Policy

Last updated 10 September 2026

The short version. WunderKindy is a private production tool used by one company to make its own videos and post them to its own social media accounts. There is no public sign-up and there are no user accounts. We do not use analytics, advertising, or tracking of any kind, and we do not sell or share personal data for anyone else's purposes.

1. Who we are

WunderKindy is operated by DECIDE99 LTD ("we", "us"), which is the data controller for the purposes of the UK GDPR and the EU GDPR.

For any question about this policy, or to exercise a data right, write to thanushenbalaskandar@gmail.com. We answer data requests within one month, as the GDPR requires.

2. What this policy covers

It covers the WunderKindy console at wunderkindy.com — the internal tool we use to produce video and publish it — and the data that tool obtains from the social media platforms we connect to it, including TikTok.

It does not cover the social platforms themselves. Once a video is published to TikTok, Instagram, YouTube or elsewhere, that platform's own privacy policy governs what happens to it and to anyone who interacts with it there.

3. What we collect

3.1 Credentials for our own social accounts

When we connect one of our social media accounts to the console, the platform gives us an access token. We store:

Tokens are encrypted at rest with AES-256-GCM under a key held only on our own server. They are never sent anywhere except back to the platform that issued them.

3.2 Data obtained through the TikTok API

TikTok requires that this is set out specifically, so it is:

PermissionWhat we obtainWhy
user.info.basic The connected account's open ID, display name, username and avatar URL. To show which account is connected, so we do not publish to the wrong one.
video.upload No data is read. It permits sending a video file to the account's drafts. To place a finished video in the account's drafts for a person to review and publish.
video.publish The account's permitted privacy settings and posting limits, and the identifier and URL of a video we have published. To publish a finished video to our own account, and to record where it went.

The account in question is our own. We do not obtain, request or store data about any other TikTok user. We do not read followers, comments, direct messages, watch history, or any other person's content or profile.

3.3 Content we create

Video, audio and text produced in the console — scripts, generated voice tracks, images and finished videos. This is our own material. Where a recognisable person appears in it, they have agreed to that separately.

3.4 Records of what we published

For each video we publish we keep the destination platform, the caption, the time, whether it succeeded, any error the platform returned, and the resulting post's identifier and URL.

3.5 Access to the console itself

The console is behind a password. We keep a session cookie for whoever is signed in, and short-lived counters against network addresses that fail the password, so it cannot be attacked by guessing. Our server keeps ordinary operational logs.

4. What we do not do

5. Our legal basis

Where we process personal data, we rely on our legitimate interests in running our own production and publishing our own content (Article 6(1)(f)), and on consent where a platform requires it — connecting an account is an explicit, revocable act of consent by whoever holds it.

6. Who else is involved

The console sends data to these services in the course of doing its work. Each is an independent controller or processor under its own terms:

ServiceWhat reaches it
TikTokVideos and captions we publish; requests made with our own token.
Instagram and Facebook (Meta)Videos and captions we publish.
YouTube (Google)Videos, titles and descriptions we publish.
LinkedInVideos and captions we publish.
XVideos and captions we publish.
ElevenLabsScript text, for generating and aligning speech.
Amazon Web Services (Bedrock)Script text, for converting a document into our production format.

These providers operate internationally, so data sent to them may be processed outside the United Kingdom and the European Economic Area under the safeguards in their own terms. Everything else stays on hardware we control.

7. Where it is kept, and how it is protected

8. How long we keep it

9. Disconnecting, and deleting data

Any connected account can be disconnected from the console's Setup screen, which deletes the stored token immediately.

Access can also be revoked from the platform's own side, and that is the route we recommend because it does not depend on us. For TikTok: Profile → Menu → Settings and privacy → Security & permissions → Manage app permissions, then remove WunderKindy. Revoking access there stops all further data access at once.

To ask us to delete anything else we hold, write to the address in section 1.

10. Your rights

Under the UK GDPR and the EU GDPR you have the right to access a copy of your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You may withdraw consent at any time.

You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.

11. Children

The console is not available to the public and is not directed at children. We do not knowingly collect personal data from anyone under 13.

12. Changes

If this policy changes we will update the date at the top. Material changes affecting anyone who has connected an account will be told to them directly.

13. Contact

DECIDE99 LTD — thanushenbalaskandar@gmail.com