Privacy Policy

Derive Growth Lab · In force from 6 September 2026 · Version 1.0

This policy explains exactly what Derive Growth Lab collects, why, who else ever sees it, how long we keep it, and how you get rid of it.

This policy covers Derive Growth Lab only — the social publishing tool at studio.derivenotes.com/growth-lab. It is a separate product from the Derive study app, which has its own policy at derivenotes.com/privacy. The two products do not share accounts and do not share data.

1. Who we are

Derive Growth Lab is operated by Derive Notes Pty Ltd (ACN 696 859 597), an Australian company registered in Queensland.

EntityDerive Notes Pty Ltd (ACN 696 859 597)
Postal address2/290 Boundary Street, Spring Hill QLD 4000, Australia
Privacy contactmatt@derivenotes.com

We are the data controller for everything described below. We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth).

2. What Growth Lab is

Growth Lab is a tool for one person to publish their own short-form video to their own social accounts. You upload a video, write a caption, tick which of your connected accounts should receive it, choose the settings each platform requires, and press Post. There is no feed, no other users' content, no messaging between users, and nothing is published without you pressing Post.

3. What we collect, and why

DataWhy we have itWhere it comes from
Your Growth Lab login — an account identifier, a display label, a role, and the access token we issue you To let you in and to scope you to your own connected accounts Created by us when we set your account up
Platform access credentials — for each account you connect: an access token, a refresh token, and the platform's own identifier for you (for TikTok, your open_id) So we can publish on your instruction without asking you to log in again every time Returned by the platform's OAuth flow after you authorise us
The video and caption you upload, plus the publishing settings you chose (audience, comment/duet/stitch, commercial-content disclosure) It is the thing being published You
Publishing records — which video went to which account, when, the platform's post ID, and the resulting URL So you can see what you have posted, and so a failed post can be diagnosed Generated by us, plus the platform's response
Public performance figures for posts made through Growth Lab (views, likes, comment counts) To show you how your own posts performed The platform's own analytics API, for accounts you connected
Server logs — timestamps, request paths, error messages Security and debugging Automatic

We do not ask you for a password, a date of birth, a phone number, a payment method or a physical address to use Growth Lab, and we do not collect them.

4. TikTok data specifically

When you connect a TikTok account, we use TikTok's Login Kit and the Content Posting API. Here is every piece of TikTok data that touches our system.

Stored on our server

Fetched live and never stored

Every time you open the composer, we call TikTok's creator_info endpoint and show you what it returns — your nickname, your profile picture, the audience options your account allows, which of comment / duet / stitch your account permits, and your maximum video length. None of it is written to disk. It exists only in the memory of that one request and in your browser, so that the screen you approve is showing you TikTok's current truth rather than a stale copy of it.

What we never do with TikTok data

Disconnecting

You can revoke our access at any time from inside TikTok — Settings and privacy → Security and permissions → Manage app permissions — or by disconnecting the account in Growth Lab. Either way we delete the stored tokens and the open ID. Revoking in TikTok takes effect immediately and does not depend on us. Posts already published stay on TikTok and are managed from TikTok, as they belong to your account, not to us.

Our use of TikTok data is additionally governed by the TikTok Developer Terms of Service. Where this policy would allow something those terms forbid, those terms win.

5. Instagram and YouTube

The same model applies to any Instagram or YouTube account you connect: we hold the OAuth tokens and the platform's identifier for you, we publish only what you tell us to publish, and we read back only the public performance figures for posts made through Growth Lab. Disconnect an account and the tokens are deleted.

6. Who else sees your data

We do not sell, rent or trade personal information, and we run no advertising. Your data is disclosed only to:

That is the complete list. There are no analytics trackers, advertising pixels, session recorders or third-party scripts on Growth Lab.

7. Where your data lives, and how it is protected

No system is perfectly secure. If a breach ever occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

8. How long we keep things

DataKept
Platform access and refresh tokensUntil you disconnect the account or revoke access at the platform — then deleted
Uploaded videosUntil you delete them, or 90 days after publishing, whichever comes first
Publishing records and performance figuresWhile your account is open, so your posting history stays intact — deleted on request or on account closure
TikTok creator_infoNever stored
Server logs30 days

When you close your Growth Lab account we delete everything above within 30 days, except where we are legally required to keep a record.

9. Your rights

You can ask us at any time to:

Email matt@derivenotes.com and we will answer within 30 days. There is no charge. If you are unhappy with our answer you can complain to the Office of the Australian Information Commissioner. If you are in the EU or UK, you also hold the rights the GDPR gives you, including the right to complain to your local supervisory authority; our lawful basis for the processing above is performing the contract you entered into with us, and our legitimate interest in keeping the service secure.

10. Children

Growth Lab is for people running their own social accounts and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, email us and we will delete it.

11. International transfers

Your data is stored in Australia. Publishing your video necessarily sends it to the platform you chose, whose servers are overseas and whose handling is governed by that platform's own privacy policy. Cloudflare R2 may store archived media outside Australia. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles.

12. Changes to this policy

If we change this policy we will update the version and date at the top of this page. If a change materially reduces your privacy we will tell you before it takes effect.

13. Contact us

Privacy questions, access requests, deletion requests and complaints: matt@derivenotes.com, or by post to Derive Notes Pty Ltd, 2/290 Boundary Street, Spring Hill QLD 4000, Australia.