PMG Amplifier Privacy Policy

Effective date: July 23, 2026Last updated: July 23, 2026

Website: https://pmgamplifier.com · Contact: support@phatmusicgroup.com

Introduction

This Privacy Policy explains how PMG Amplifier (“PMG”, “we”, “us”, or “our”) collects, uses, stores, and shares information when you use our public website at https://pmgamplifier.com and the authenticated application available to approved users (currently served at app.s3lim.com).

This Policy is written to describe the product as it currently operates. It is not a generic template and is not a claim of certification under any privacy framework.

Who operates PMG Amplifier

PMG Amplifier is operated by PHAT MUSIC GROUP INC. (also referred to as Phat Music Group Inc.).

Privacy and data requests: support@phatmusicgroup.com.

Scope of this Privacy Policy

This Policy covers:

  • the public product website and legal pages on pmgamplifier.com;
  • account registration, authentication, and access-controlled use of the application;
  • connected platform integrations, including TikTok Login Kit and related APIs;
  • catalog, content, campaign, Ghost Poster, smart-link, support, and billing features that store or process data in the product.

Third-party platforms (including TikTok) have their own privacy policies. This Policy explains PMG’s practices, not TikTok’s.

Information users provide directly

Depending on how you use PMG, you may provide:

  • name;
  • email address;
  • password (stored only as a one-way password hash; we do not store plaintext passwords);
  • artist, band, or company name;
  • role or intended use case;
  • music, social, or website links you choose to submit;
  • support messages and attachments;
  • campaign plans, captions, hashtags, approval comments, and other workspace text;
  • song metadata, rights/registration information, and contributor details you enter;
  • billing and payment-related details needed if you use paid features (processed with our payment provider).

Source: you. Purpose: create and operate your account, deliver requested features, and provide support. Stored: yes, in our application database while your account remains active and as otherwise described in Retention.

Account and authentication information

PMG uses account credentials and session records to authenticate approved users. Session identifiers are stored server-side and associated with browser cookies such as pmg_user_session. Where an access gate is enabled, an additional access cookie such as pmg_app_access may be used.

We also store account status and role information (for example, whether an account is pending approval or approved) so we can enforce access control.

Information received from TikTok

When you choose to connect TikTok through PMG’s Login Kit flow, TikTok may provide information authorized by the scopes you grant. By default, PMG requests:

  • user.info.basic — basic account identity used to confirm the connected account; and
  • video.upload — permission used for user-initiated draft/inbox video upload through TikTok’s Content Posting API when that capability is enabled for the connected account.

For user.info.basic, PMG currently requests and may store: TikTok open ID, display name, username/handle, and avatar URL. These values are used to display connection status and identify the connected account inside Ghost Poster and related workflows.

PMG also receives and stores OAuth access tokens and, when provided by TikTok, refresh tokens and expiry metadata so the connection can remain functional until you disconnect or authorization ends. Tokens are encrypted at rest using application-managed encryption keys.

PMG does not request TikTok passwords. PMG does not use TikTok Login Kit to browse your private TikTok content beyond what the granted scopes and your in-product actions allow.

Information received from other connected platforms

If you connect other platforms available in the product (for example YouTube, Instagram, or Meta advertising/attribution integrations), PMG may receive account identifiers, profile display information, granted scopes, and encrypted access tokens needed to perform the features you enable. Those connections are optional and user-initiated.

Meta-related features may store configuration such as pixel/dataset identifiers and encrypted tokens when you configure tracking or ads integrations. Attribution and campaign events may record campaign, visitor, and event metadata generated by features you use.

Content, media, files, and metadata

When you upload or generate content in PMG, we process media and metadata needed for your workspace, including video files, audio files, images/artwork, captions, hashtags, titles, descriptions, and related campaign or approval records.

Media files may be stored using our hosting and object-storage providers (including Vercel Blob where configured). Database records about those assets and campaigns are stored in our application database.

Some features may send user-provided text or media to third-party AI or media-generation providers that you choose to use inside PMG (for example caption or video-generation workflows). Those providers process the submitted materials to return the requested output.

Device, browser, usage, diagnostic, and log information

Like most web applications, our infrastructure and application logs may automatically process technical information such as IP address, user agent, request paths, timestamps, and error diagnostics when you use the website or application. We use this information for security, reliability, abuse prevention, and troubleshooting.

Operational logs are not a substitute for your workspace content and are retained according to security and operational needs rather than as a user-facing archive.

Cookies and similar technologies

PMG uses cookies and similar technologies that are necessary to operate the service, including:

  • authentication/session cookies for signed-in users;
  • access-gate cookies where an access password is configured;
  • short-lived OAuth state cookies used during TikTok (and other platform) connection flows, such as state and redirect-URI cookies, to protect against CSRF and complete the callback securely.

Public legal pages on pmgamplifier.com are available without requiring you to sign in. Viewing those pages does not require creating an account.

How information is used

We use information to:

  • provide, secure, and improve PMG Amplifier;
  • authenticate users and enforce access controls;
  • display connected-account status and operate integrations you authorize;
  • host, process, and deliver content and campaign workflows you request;
  • perform user-initiated TikTok draft/inbox uploads when enabled;
  • provide support and respond to requests;
  • process payments and credits where those features are used;
  • prevent fraud, abuse, and security incidents;
  • comply with legal obligations.

PMG does not sell TikTok user data. PMG does not share TikTok user data with advertisers for advertising unrelated products. PMG does not use TikTok-derived identity or token data to train general-purpose AI models.

How information is disclosed

We disclose information in these categories:

  • Service providers — hosting, database, storage, email, payments, and similar vendors that process data to help us run PMG;
  • Connected platforms you authorize — for example, sending video bytes and related parameters to TikTok when you initiate a draft upload;
  • Legal and safety — if required by law, regulation, legal process, or to protect rights, safety, and integrity;
  • Business transfers — if we are involved in a merger, acquisition, or similar transaction, information may be transferred under appropriate confidentiality expectations.

We do not sell personal information. Infrastructure and platform providers process data as part of delivering the service; that is not the same as selling TikTok user data.

Service providers and subprocessors

Depending on which features you use, information may be processed by categories of providers including:

  • application hosting and edge delivery (Vercel);
  • object/media storage (Vercel Blob);
  • application database hosting (Turso);
  • email delivery (Resend);
  • payments (Stripe), when billing features are used;
  • TikTok, for Login Kit and Content Posting API features you authorize;
  • Meta, when you configure Meta tracking or ads-related features;
  • AI/media providers used by optional generation features you run in the product.

These providers process information to deliver their services to PMG. Their own terms and privacy policies also apply to their processing. This Policy does not claim that a specific form of data-processing agreement exists with every vendor.

TikTok-specific data practices

What we receive: basic profile fields under user.info.basic (open ID, display name, username, avatar URL), granted-scope metadata, and OAuth tokens (access token and refresh token when issued).

Why: to confirm the connected TikTok account, show connection status in the product, maintain the authorized connection, and perform user-requested draft/inbox uploads when video.upload is granted and the feature is enabled.

Storage: profile display fields and encrypted tokens are stored in PMG’s Ghost Poster account records while the connection exists. The OAuth callback path used by the application is /api/social/tiktok/callback.

Sharing: TikTok-derived identity and tokens are not sold and are not shared with advertisers for unrelated advertising. Content you choose to upload may be transmitted to TikTok only when you initiate an upload action in the product.

Auto-posting: PMG does not auto-post to TikTok and does not publish to TikTok without a user-initiated action in the product. Draft/inbox upload is distinct from a final public post completed inside TikTok.

User-controlled posting and uploads

Ghost Poster supports manual handoff packages and, when approved and enabled, user-initiated TikTok draft/inbox uploads through the Content Posting API. Uploads require an authenticated user action (for example, starting an upload from Ghost Poster against a selected asset/post and connected account).

Users review captions and content details in the product before initiating supported submission or export steps. PMG does not guarantee TikTok acceptance, ranking, reach, or continued API availability.

Data retention

PMG does not publish a single fixed deletion clock for every record. Retention follows these criteria:

  • Account and workspace data — retained while your account remains active and as needed to provide the service;
  • TikTok connection tokens — retained while the TikTok account remains connected. If you use Ghost Poster → Accounts → Disconnect for an OAuth TikTok account, PMG deletes that connected-account record (including stored encrypted tokens). If TikTok sends a deauthorization/webhook event that PMG processes, PMG clears stored tokens and marks the account as needing re-authorization; residual non-token profile fields may remain until you disconnect/remove the account or request deletion;
  • Media and campaign records — retained while associated with an active workspace unless you delete them in-product or request deletion assistance;
  • Support communications — retained as needed to handle your request and maintain support history;
  • Security, backup, fraud-prevention, accounting, and legal records — retained for a limited additional period as reasonably necessary for those purposes even after a primary record is deleted.

We do not claim that every backup copy or log is erased at the exact moment of a disconnect or deletion request.

Data security

We use administrative, technical, and organizational measures designed to protect information, including encrypted storage of social access tokens, hashed passwords, HTTPS transport in production, and access controls for the authenticated application.

No method of transmission or storage is 100% secure. We do not claim perfect security.

International processing and transfers

PMG is operated by PHAT MUSIC GROUP INC. and uses cloud infrastructure and vendors that may process information in the United States and other countries where those providers operate. If you access PMG from another country, your information may be processed in a country with different data-protection rules than your own.

This Policy does not claim a specific residency for all data or a specific transfer mechanism for every jurisdiction.

User choices and controls

You can:

  • choose whether to create an account or request access;
  • choose whether to connect TikTok or other platforms;
  • disconnect integrations in the product where available;
  • decide whether to initiate draft uploads or use manual handoff;
  • contact us to request access, correction, or deletion assistance.

Disconnecting TikTok and other integrations

To disconnect TikTok inside PMG Amplifier:

  • sign in to the authenticated application;
  • open Ghost Poster;
  • go to Accounts;
  • select the connected TikTok account and choose Disconnect.

You should also revoke PMG’s access in your TikTok account/app permissions settings if you want to end authorization on TikTok’s side.

Disconnecting in PMG deletes the connected Ghost Poster account record for that OAuth connection, including stored encrypted tokens. That action removes PMG-stored credentials; it does not by itself call TikTok’s authorization-revoke API, so you should also revoke access in TikTok’s settings if you want authorization ended on TikTok’s side. Historical post/campaign or analytics records that already reference the account may remain in your workspace unless separately deleted or removed through a deletion request.

Access, correction, export, and deletion requests

To request a copy of your information, a correction, an export of available account data, or deletion of TikTok-derived information or other personal information we hold, email support@phatmusicgroup.com from the email address associated with your account and describe the request.

PMG does not currently provide a fully self-service legal data-export portal for all data categories. We will respond to verified requests as required by applicable law and as reasonably practicable for the systems involved.

Account deletion

To request deletion of your PMG Amplifier account, email support@phatmusicgroup.com. We may need to verify your identity and retain certain records as described in Retention (for example, security, billing, or legal records).

Account deletion is not instantaneous in every system copy. We do not claim immediate erasure of all backups and logs.

Rights for users in applicable jurisdictions

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; to withdraw consent where processing is consent-based; and to lodge a complaint with a regulator.

PMG is not “GDPR certified,” “CCPA certified,” or certified under any other privacy framework by virtue of this Policy. If a law applies to you, contact support@phatmusicgroup.com to exercise available rights.

Children’s privacy

PMG Amplifier is intended for adults and professional/business users who manage music marketing and catalog workflows. It is not directed to children.

We do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information, contact support@phatmusicgroup.com and we will take appropriate steps to delete it.

Third-party services

The service links to and integrates with third-party services (including TikTok, Meta, payment processors, hosting providers, and optional AI/media tools). Those services are governed by their own terms and privacy policies. PMG is not responsible for third-party practices outside PMG’s control.

Changes to the policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Material changes may also be communicated through the product or by email where appropriate.

Canonical URL: https://pmgamplifier.com/privacy.

Contact information

Operator: PHAT MUSIC GROUP INC. (Phat Music Group Inc.)
Product: PMG Amplifier
Website: https://pmgamplifier.com
Privacy contact: support@phatmusicgroup.com
Related: Terms of Service · Contact · Sign In

Terms URL: https://pmgamplifier.com/terms.

Effective date and last-updated date

The effective date and last-updated date appear at the top of this Privacy Policy and apply to the version published at https://pmgamplifier.com/privacy.

PMG Amplifier Privacy Policy