Skip to content
Preliminary draft — not attorney-approved

These pages are first-pass language and are not legal advice. They are written by the team to be honest and easy to read; consult your own counsel before relying on them in a contract. We'll mark the date each section was last revised at the top of the page.

Preliminary draft · Platform authorization

Platform authorization

What platform integrations request, what the data plane covers today, and how to revoke a connection if you change your mind.

Last updated 2026-08-17 — language is a working draft, not legal advice.

The reality

What the data plane covers today

The Tollcast data plane does not auto-connect to X, Threads, Instagram, LinkedIn, TikTok, or YouTube. There is no constant mention poll wired into the code; today, mentions are surfaced via /inbox from manually-pasted or imported sources, and the /draft queue runs on those inputs.

The platform-connection code paths are early scaffolding — the voice profile can record a string platform, but no background listener or poller is wired up. When that scaffolding turns into a real integration, we'll surface the consent screen first and email account holders before flipping it on.

What we will ask

No write authorization today

Tollcast currently has no installed OAuth provider or platform write adapter. All six platforms are manual-only: you paste public source material, Tollcast can classify it and prepare an advisory recommendation, and you remain responsible for any external action. Tollcast does not monitor live channels, read DMs, or send replies.

  • X, Threads, Instagram, LinkedIn, TikTok, and YouTube — manual source material only; no OAuth write scope, no external send, and no DM access.

Revoking

How to revoke a connection

Revoke a saved manual connection two ways: run the in-app disconnect from /settings, or pull the per-platform access from your account settings on the platform itself (X, Threads, etc.). The two paths converge — we drop the OAuth token on our side on the next sync.

Today the simplest path is account deletion from /profile. The cascade clears any saved manual connection because we don't store platform tokens.