Security and data handling

Access is authorized. Publishing is reviewed.

Offload uses provider authorization for connected accounts, encrypts data in transit, and places an explicit creator decision in front of supported high-impact publishing actions.

Controls

The practical safeguards.

This page summarizes Offload's product controls. The Privacy Policy contains the complete description of collected data, service providers, retention, and user choices.

SIGN-IN

One-time email codes

Offload sign-in uses a one-time code sent to the user's email address. Users do not create a reusable Offload password.

OAUTH

Provider authorization

Connected accounts use the provider's own authorization flow. OAuth for most tools is managed by Composio; Offload does not receive third-party passwords.

TRANSPORT

Encrypted in transit

Information sent between Offload clients, service providers, and the cloud service is protected with TLS in transit.

APPROVAL

Review before publishing

Supported publishing actions display the account, content, and provider-specific choices before the creator approves the action.

TOKENS

Managed connected credentials

OAuth access tokens for most connected platforms are held and refreshed by Offload's OAuth partner rather than being exposed to other users.

CHOICE

Disconnect and delete controls

Users can disable connected-account access and separately request deletion of imported provider data. Account deletion is also available.

Connected-account flow

What happens when you connect a platform.

Access is scoped to the provider permissions shown during authorization and used only to provide the features the creator invokes.

The creator starts in Stack

The user chooses a provider and Offload opens the provider authorization flow.

The provider shows requested access

The creator signs in with the provider and approves or denies the scopes on that provider's consent screen.

Offload uses granted access for requested features

For example, TikTok profile and video permissions populate the creator's analytics view; publishing scopes are used only when the creator initiates and approves those workflows.

The creator can stop access

Disconnecting disables Offload's local use of the connection and requests provider-token revocation where supported. Separate controls remove imported data.

Report a security or privacy concern

Send the affected feature, approximate time, and a concise description. Do not email passwords, access tokens, or sensitive content.

saadosman450@gmail.com