Legal
Privacy Policy
What Devign Agency Suite collects, why we collect it, where it is stored, who else sees it, how long we keep it, and how to have your account and data deleted.
The short version
1.1 Devign Agency Suite is a business tool for TikTok LIVE talent agencies. Most of the information in it is an agency’s business record about its own roster, not a consumer profile.
1.2 We collect your name, your email address, an account identifier, what you do in the app, and content you create in the app. If you are agency staff — an owner or an agent — we also ask you, once, to tell us your role, your agency’s name, your country, and optionally your agency’s TikTok handle. Everything in that answer is what you told us; we do not check any of it. That step does not ask for a phone number; section 2.5 says where one can still reach us. We also record, automatically, your IP address and your browser or app user-agent string on security-relevant actions, a record of the app version and device model each session was used from, and a daily record that your account was active.
1.3 An agency’s roster carries each creator’s TikTok handle and the monthly performance figures TikTok reports for them.
1.4 If an agency connects its TikTok Backstage business account, the sign-in details for that business account are stored encrypted on our servers and used only to read that agency’s own figures.
1.5 If an agency owner switches on the AI growth coach, roster and performance information — including creators’ TikTok handles and their monthly figures — is sent to a third-party AI provider. Section 8 sets out exactly what.
1.6 Our servers and databases are hosted in Germany.
1.7 We do not sell your personal data and we do not use it for advertising. The app contains no advertising, analytics or tracking software. The only outside parties that see anything are the service providers listed in section 6, and TikTok — we send TikTok a report on how much each agency is using the app. It names each agency and gives counts and setup status. It names no individual and contains no creator’s handle or figures. Sections 4.4a and 6.2a set it out in full.
1.8 You can delete your account at any time, in the app or on this website. Section 12 explains what deletion removes and what it does not.
1.9 We keep our operational and security records, including the IP address and user-agent above, indefinitely, and our audit log cannot be altered or deleted by anyone — including us. Deleting your account removes the personal data in the account; it does not erase the record of actions taken on the service. Sections 11 and 12 say exactly what that means.
1.10 There is no export button. If you want a copy of your data, ask us and a person at Devign will produce it. Section 13.
Contents
This Privacy Policy explains how Devign Agency Suite (the “app”) and this website, operated by Devign LLC (“we”, “us”), handle information about you. Devign LLC is registered in Casper, Wyoming, USA, and our team works from Lebanon. Effective date: 9 September 2026. Document version: 2026-09-09.
The app and this website are both run by Devign LLC.
2. What we collect
The list below is meant to be complete. If we start collecting something that is not on it, we will add it here first.
2.1 Information you give us
| What | Why |
|---|---|
| Name | To identify you within your agency. |
| Email address | To sign you in, and to send password-reset, email-verification and account-deletion codes. |
| Password | Stored only as a secure one-way hash. Nobody, including us, can read it back. |
| A contact email address — separate from the address you sign in with | Where you signed in with Apple or Google there may be no usable address on the account, so we ask for one, or keep the one the provider gave us. We record whether it came from Apple, from Google, or was typed in. It is how we reach you; it is never how we identify your account. |
| What you tell us at the one-time setup step — asked of agency staff (owners and agents), not of creators: your role (owner or agent), your agency’s name, your country, and, optionally, your agency’s TikTok handle | So that an account can be recognised and checked against what the person said about it. All of it is self-declared and none of it is verified. None of it grants any access, seats you anywhere, or links you to any agency. The name and country are required; the handle is optional and may be left blank. |
| The time zone your device is set to at sign-up, and a market | Sign-up no longer asks which market you are in. Your device sends the time zone it is set to and we read a market out of it; a market may also be named outright, and can be changed afterwards. Both are used to show that market’s settings. |
| Your language, and your choice of colour theme | To show the app in the language you chose and the appearance you picked. The language is also part of what the AI growth coach is told, so it answers in it (section 8). |
| Content you create in the app | Messages to the AI growth coach, support and appeal messages, boost, match and referral requests, staff notes about a creator, reward and redemption notes, daily-challenge answers. |
| An agency logo image | Shown as the agency’s branding. The app reads your photo library in one place only — when you pick this image — and takes only the image you choose. |
| Your 18+ and document acceptance | That you accepted, which documents, the version number of each that was current at that
moment, and the date and time. The date you confirmed you are 18 is stamped separately on
your account. Nothing is recorded at sign-up — the box on the
registration screen unlocks the button on your device and is not sent to us; the record is
written by the separate acceptance step afterwards. Accounts that existed before that step
was built carry a row marked grandfathered instead, which records
our position that the account was in use and not any act by its holder, and carries no age
confirmation. |
2.2 Information your agency records about you
| What | Why |
|---|---|
| TikTok handle | The name TikTok settles by, and how a month of figures is matched to a creator. |
| Roster status and dates | Whether a creator is a prospect, invited, active, paused or gone, and the dates they joined and left. |
| Role and permissions | Which seat you hold in the agency and what it lets you do. |
| Staff notes | Free text an agency’s own staff write about a creator, visible only inside that agency. |
| Rewards records | DPoints entries, redemptions, level and tier history, incentive applications, and the monthly Coins figure the agency records for a creator. DPoints entries exist only at an agency that has switched the programme on. |
2.3 Information read from TikTok
| What | Why |
|---|---|
| Monthly performance figures — diamonds, diamonds from PK and matches, valid LIVE days, PK battle count, LIVE hours, level and tier, and the bonus contribution TikTok estimates for the agency | Read through the agency’s own TikTok Backstage business connection. These are the agency’s own business data about its own creators, shown in the app so the agency can manage its roster. |
| The agency’s Backstage sign-in details | Stored encrypted, used only to sign in to that same agency’s Backstage. Section 7. |
2.4 Information collected automatically
| What | Why |
|---|---|
| IP address | Recorded on every security-relevant action, together with the account it belongs to, in our append-only security log. Used to investigate abuse, account takeover and support questions. |
| User-agent string (the device, browser or app version your request identifies itself as) | Same log, same purpose. |
| Daily activity record | One row per person per agency per day recording that the account was used that day, how many times it was opened, and when it was first and last seen. Used to know whether the service is working, and — collapsed into counts — to build the report we send TikTok about how much each agency is using the app. The rows themselves stay with us. What goes to TikTok is counts of distinct people per agency, naming no individual. Section 4.4a. |
| Session presence records | While you are signed in, we record which five-minute periods of the day your account was active in a workspace, and how many requests fell in each. Used to answer how long the tool was in use, which is the other half of the question above. |
| The app and device your session identifies itself as — app version and build number, operating system, device model, and the identifier of the over-the-air update you are running | Recorded against those session records so we can tell which versions of the app are in use, reproduce a fault on the build that has it, and know when an update has reached everybody. |
| In-app interactions | The actions you take and the screens you use, needed to operate the app’s features. |
| Push notification token and device platform (iOS or Android) | Only if you turn notifications on. Section 9. |
| Server log files | Ordinary web-server and application logs, which can contain an IP address and a request path. |
| Screens opened and controls pressed (the name of the screen, the name of the button, and how long the screen was open) | Recorded against your account so we can see where the app is confusing or slow, and which parts of it are used at all. Names only: we never record what you type, and no creator handle, email address or amount appears in these records. Kept 30 days. |
| Crash and error reports (the error, where in the code it happened, the screen you were on, and the app version and device) | Sent when the app fails, so the fault can be found and fixed. A crash on a screen reached before you sign in is reported too, with no account attached, so that problems on the sign-in screen are not invisible to us. |
2.5 What we do not collect
We do not collect payment card, bank account or wallet details; health information; your contacts; your microphone or camera; or advertising identifiers. The app moves no money and holds no balance for anyone. There are no advertising, analytics or tracking software libraries in the app.
About a phone number, precisely. Nothing in the app asks you for one. The setup step in 2.1 asked for a phone number when it was first built and does not any more, and the field it used is cleared. One route is left: an agency owner registering an agency may supply a WhatsApp number so that a verification code can be sent to it, and where that channel is switched on the number is stored against the agency and marked verified when the code comes back. That channel is switched off, so today no phone number is asked for, sent to or stored by this service. We are naming the route rather than writing a flat “we never hold a phone number” that a configuration change would quietly falsify.
About location, precisely. We do not use GPS and we do not ask your device for its location. The country in your setup answer is a country you typed. But your IP address indicates roughly where you are, and we record it on security-relevant actions (2.4); and we guess a market from your device’s time zone when you sign up. We use neither for anything but the purposes in section 4.
3. Where the information comes from
3.1 From you, when you register, sign in, fill something in, or write something.
3.2 From your agency, when its staff add you to a roster or record something about you.
3.3 From TikTok’s Backstage portal, through the agency’s own connection.
3.4 From your device, automatically, as described in 2.4.
4. Why we use it
4.1 To run the app — managing a roster, showing monthly figures and levels, running the DPoints programme where an agency has switched it on, and powering the AI growth coach where an agency has enabled it. Both of those are off for every agency until its owner turns them on, and neither collects anything while it is off.
4.2 To manage your account — creating and securing it, signing you in, sending verification, reset and deletion codes.
4.3 To keep the service safe — detecting and investigating abuse, attacks, account takeover and attempts to reach another agency’s data. This is what the IP address and user-agent records are for.
4.4 To keep the service working — knowing that the service is up, and knowing which versions of the app are in use so a fault can be reproduced and fixed.
4.4a To report to TikTok on how each agency is using the app. TikTok’s regional teams ask us how much the tool is actually being used, and we answer them. What goes to TikTok, for each agency, is: the agency’s name; how many staff seats and creator accounts it has; how many staff and how many creators opened the app in the period; how many TikTok Backstage connections it has and how many are failing; whether the Backstage connection is working; whether the agency has set up its own payout scheme or is on the default; and how many creator accounts and staff seats are new in the period. Platform-wide totals for the same measures go with it.
No individual is named in it. The counts are counts of distinct people and the report does not say who they were. No creator handle, no diamonds, no earnings, no message, no note and no coach conversation is in it.
It is segmented. A TikTok team is shown only the agencies in its own audience, and the totals it sees are the totals for those agencies. An agency in one region’s report does not appear in another’s.
How often, honestly. The daily activity records described in 2.4 are what it is built from, and they are written every day. The report itself covers a period — usually the previous day — and is produced and sent by a person at Devign. There is no automatic job that generates or delivers it.
How to be left out. An agency that does not want to be in the report can tell us at info@devignlb.com and we will exclude it. Terms of Service section 9A covers the same ground from the agency’s side.
4.5 To recognise an account — what you told us about yourself at the setup step is kept so that an account which looks wrong can be checked against what its holder said. It is a statement and we treat it as one; nothing in the app relies on it being true.
4.6 To meet a legal obligation or answer valid legal process.
4.7 We do not use your information for advertising, for building a marketing profile, or for training anyone’s AI model, and we do not use it for any purpose incompatible with the ones above.
5. Where your information is stored
5.1 Our servers and databases are hosted in Germany, at a commercial hosting provider.
5.2 Our team works from Lebanon and reaches those servers from there.
5.3 Our users are in the United States, in the Gulf and the Levant, and in Turkey. If you are in any of those places, your information is being stored and processed outside your own country. By using the app you understand that.
5.4 Database backups are taken nightly and stored in object storage at the same commercial hosting provider. Backups are covered by section 11.
6. Who else processes it
6.1 We do not sell your personal data. We do not share it for advertising. Two different kinds of outside party see something, and we separate them because they are not the same: the service providers we need to run the app, and TikTok.
6.2 The service providers. We name them by category:
- A cloud hosting provider in Germany, which runs our servers and stores our databases.
- An email delivery provider, which sends your sign-in, verification, password-reset and deletion codes.
- A push notification service, which passes app notifications to Apple’s or Google’s push systems.
- A third-party AI provider, which powers the AI growth coach. Section 8.
- An operational monitoring service, which receives alerts about errors and events on our own systems so we can keep the service running.
What none of them is sent. The contents of anything you type. What reaches the monitoring service is that a screen was opened or a button was pressed, and never what was entered in it.
6.2a TikTok. TikTok’s regional teams receive a report from us on how much each agency is using the app. This is the one place where information leaves us for somebody else’s own purposes, and we would rather name it than let a general sentence about not sharing cover it over. What is in the report, what is not, how it is segmented and how often it goes are set out in full at section 4.4a. It names agencies; it names no individual; it contains no creator’s handle or figures.
6.3 We require our service providers, by the terms we are on with them, to protect the information and to use it only to provide their service to us. We are reviewing each of those agreements, and where one turns out to say less than that we will either change provider or say so here. Section 8.5 covers the AI provider’s retention specifically, which is the one we are least able to state today.
6.4 We may disclose information if we are required to by law or by valid legal process.
6.5 We describe these providers by category rather than by company name. If you need to know which company sits behind a category — because your own agreement with your creators requires it, or because you are assessing us as a supplier — write to info@devignlb.com and ask.
7. The TikTok Backstage connection
7.1 The monthly figures in the app — diamonds, valid days, LIVE hours and the rest — are read through the agency’s own TikTok LIVE business account, which TikTok calls Backstage. This is the agency’s own business data about its own creators. The app reads it and does not post, message or change anything.
7.2 This is never a creator’s personal TikTok account. A creator is never asked for their TikTok password and their personal account is never connected.
7.3 When an agency chooses to connect, the username and password for that business account are stored encrypted at rest on our servers. They are used for one purpose only: to sign in to that same agency’s Backstage and fetch that agency’s own figures for its own creators.
7.4 Those details are never used for anything else and are never shared with another agency or with any third party. They are never shown to a person and never returned by any address the app or the website answers on — not to the agency, not to its staff, not to us; the part of the system that reports on the connection hands back a status and never the password.
What is true rather than what sounds better. They are encrypted with a key we hold, so they have to be decrypted for the app to use them. The only things that decrypt them are the background processes that sign in to Backstage on the agency’s behalf — which happens on a schedule, many times a week — and two maintenance commands we run against our own systems. The plaintext exists in that process’s memory for as long as the sign-in takes; it is not written to a file, a log, a database or a screen. Every decryption is recorded in our audit log, with the reason for it, and that log cannot be altered or deleted. Section 10.3 says the same thing in the list of protections.
7.5 An agency can disconnect its Backstage account at any time, and the stored credentials are deleted when it does. Where an agency’s workspace is closed, the credentials stay inside that workspace’s own database and are deleted with it, under the 30-day process in Terms of Service section 13.4.
8. The AI growth coach
8.1 The app includes an optional AI growth coach that answers questions about growing LIVE performance. It is off for every agency until an owner switches it on, and each person has a weekly allowance of turns.
8.2 It is off until an agency owner switches it on, and the software enforces that. Only a person holding the owner role can enable it, and they do so for the whole agency, not just for themselves. Until an owner has given that consent, the coach refuses to answer anybody in the agency — including the owner. We record which owner enabled it, the versions of the Terms and this policy shown to them, and the date and time. An owner can withdraw the consent at any time, which stops anything further being sent and puts the coach back to refusing everyone in the agency.
8.3 What we send to the AI provider. Every time someone asks the coach a question, we send the question, the recent conversation, and the working context needed to answer it. Depending on who is asking, that context includes:
- the person’s display name, their role in the agency and its permissions, and their language;
- the agency’s name and the market it operates in;
- the asking creator’s own figures — diamonds, diamonds from PK and matches, valid LIVE days, PK battle count, LIVE hours, DPoints balance, level, tier, the distance to the next one, and the agency’s monthly Coins figure for them;
- when an owner or a member of agency staff is asking, up to eight of that agency’s creators, ranked by diamonds for the current month and each named by TikTok handle, with that creator’s diamonds, valid days, LIVE hours and level, plus roster headcounts and roster totals. The eight are picked on figures alone. A creator who has been paused, or who has left the agency, is included if their figures put them in the eight — nothing filters them out. This goes with every question, whether or not the question is about them;
- the agency’s own reward settings — its share curve, payout components and percentages, DPoints earn rates, daily caps and reward catalogue.
8.4 If you are a creator at an agency that has enabled the coach, your TikTok handle and your monthly figures may be sent to the AI provider when your agency’s owner or staff use the coach, even if you never open it yourself, have no account with us, and have never seen this document. Your agency authorises that on your behalf, and it has warranted to us that it is entitled to and that it has already told you. We do not check that and we hold no record of it — the Terms of Service, sections 8.6, 8.7 and 9.4, set out exactly what the agency promises us. There is no way for one creator to be excluded while the agency’s consent stands; a creator who wants out should ask their agency’s owner to switch the coach off, and may also write to us.
8.5 The AI provider processes what we send in order to return a reply. We require our providers, by the terms we are on with them, to use what we send only to provide their service to us. We are confirming the specific retention term we are on with the AI provider, and until that is settled we make no statement here about how long it keeps what we send. We do not use coach conversations for advertising or to build a marketing profile, and we do not use them to train anyone’s model.
8.6 We do not keep your coach conversation on our servers. The only thing our systems store about coach use is a count of how many coach turns each person has spent in the current week, which is what enforces the weekly allowance. The conversation itself lives on your device.
8.7 Please do not put sensitive personal data into a coach message — government identifiers, bank or card details, or health information. The coach does not need them.
9. Push notifications
9.1 If you turn notifications on, your device’s operating system issues a notification token that identifies your device to Apple’s or Google’s push service. We store that token with your device platform (iOS or Android), against your account.
9.2 We use it for one purpose only: to deliver the notifications you have enabled to your own device. Delivery is handled by a push notification service that passes each notification to Apple or Google on our behalf and is bound to use it only for that.
9.3 You can turn notifications off in your device settings at any time, and choose which kinds reach you in the app’s own notification settings.
9.4 A token from a device that has uninstalled the app is deleted as soon as the push service tells us that device is gone.
10. How your information is protected
10.1 Traffic between your device and our servers is encrypted in transit.
10.2 Passwords are stored only as a secure one-way hash and cannot be read by anyone, including us.
10.3 TikTok Backstage credentials are encrypted at rest, are never shown to a person, and are never returned by any address the app or the website answers on. They are decrypted only inside the background processes that sign in to Backstage and two maintenance commands, and every decryption is recorded. Section 7.4 explains it fully, including the fact that we hold the key.
10.4 Each agency’s roster data lives in its own separate database, so one agency cannot reach another’s.
10.5 Agency staff see only what their role permits.
10.6 Security-relevant actions are written to an audit log that is append-only: the database itself refuses to let anyone alter or delete a row in it.
10.7 Who at Devign can reach your agency’s workspace, and what we are not going to pretend about it. A list of protections that leaves out the largest way in is not a list of protections. So: there is one platform administrator account at Devign that can enter any agency’s workspace and see what is in it. It signs in with a password and a challenge test, and it has no second factor. Entering a workspace that way is recorded in the append-only log, but it is not time-limited, is not tied to a stated reason, and does not expire on its own. A separate mechanism exists that would require an agency to grant access for a limited period; because the administrator account does not need it, it has never been used. We are telling you this because an agency asking “is Devign’s access to my workspace time-boxed and reason-logged?” is entitled to a true answer, and today the true answer is that it is logged and it is not time-boxed.
10.8 We have no security certification and we do not claim one. We have not had a penetration test. No system is perfectly secure.
11. How long we keep things
Read this first. We do not run a general deletion timetable. Our position is deliberate and we would rather state it plainly than imply otherwise:
- Operational and audit records are kept indefinitely. That includes the security and audit log, which records what was done, by which account, from which IP address and with which browser or app user-agent, and when. We keep them for security, for accountability, and so that a dispute between an agency and a creator, or between an agency and us, can be settled by looking at what actually happened rather than at what anybody remembers.
- The audit log is append-only. It cannot be altered or deleted. The database itself refuses any attempt to change or remove a row, by design, so that nobody — including us — can quietly rewrite the record of who did what. It stays that way when an account is deleted.
- What that means for a deletion request. The personal data held in your account is removed (section 12.2). The record of the actions taken on the service — including the IP addresses and user-agents attached to them, and the account identifier they were recorded against — remains, as does the record that you accepted these documents and confirmed you were 18. In short: we delete your account, not the history of what was done with it.
- A closed agency is the one thing we intend to delete on a clock, and you should know how new that is. Where we close an agency, its workspace — its own database, and the records of who belonged to it — is deleted 30 days after the closure if nobody has asked for a copy in that time (Terms of Service section 13.4). There is no automatic job. No part of the software closes a live agency and no part of it deletes a workspace: a person at Devign does both by hand, against a written procedure, and records that they did. The procedure has never been carried out — not once, on any agency — and we intend to rehearse it on a workspace created for the purpose before using it on a real one. And for agencies closed before the procedure existed we hold no recorded closure date, so there is no day from which to count the 30; those workspaces are being left alone rather than deleted on a guessed date. The audit record of any deletion we do perform, like every other, is permanent.
The table below sets out the rest.
| Information | How long |
|---|---|
| Your name, email address, password hash, account identifier | While your account exists. Deleted or blanked immediately when you delete your account. |
| Your contact email address, and what you told us at the setup step — your role, your agency’s name, your agency’s TikTok handle and your country | While your account exists. All of it is cleared when you delete your account, so that nobody at Devign is left able to write to somebody who asked to be forgotten. |
| Your acceptance of the Terms and this policy, and the date you confirmed you are 18 | Kept indefinitely, including after you delete your account. One row per document and version, only ever added to: accepting a new version writes a new row beside the old one rather than replacing it. The rows say that an attestation was made, against which version, and when; they carry no name, address or number. Kept because a record of consent that disappears when the account does is not a record of anything. |
| Sign-in sessions and access tokens | A signed-in session can be renewed for at most 180 days from when you signed in, after which you must sign in again. All tokens are deleted immediately when you delete your account. |
| Email verification, password-reset and deletion codes | 15 minutes, then they expire and stop working. |
| Content you wrote in the app — coach messages held on your device, appeal messages, request details, staff notes about you, daily-challenge answers | Deleted or blanked immediately when you delete your account. |
| Agency logo image | While the agency uses it. |
| Your TikTok handle, and the months you worked at an agency, with their figures | Kept after you delete your account, indefinitely, as the agency’s own business record. The handle is the only thing left that lets an agency match a month of diamonds to a payment it still owes, and TikTok settles by handle. TikTok’s own permanent identifier for you is deleted at the same time as your account, so what remains is a handle and a set of months, not a link back to a TikTok profile. |
| Push notification token | While the device is registered. Deleted when the push service reports the device is gone, and when you delete your account. |
| TikTok Backstage credentials | Until the agency disconnects, or the agency’s workspace is closed. Then deleted. |
| Weekly coach turn count | Kept indefinitely while the agency exists. It is a count of coach turns per person per week, and nothing deletes it on a schedule; it goes when a closed agency’s data is deleted. |
| Security and audit records, including IP address and user-agent | Kept indefinitely, and they cannot be altered or deleted. The database refuses any update or delete against this log, by design, so that nobody — including us — can quietly rewrite the record of who did what. These rows carry the account identifier of the person who acted, so they survive the deletion of that account. We have not set an expiry and do not intend to. |
| Daily activity records, session presence records, and the app version and device model recorded against them | Kept indefinitely while the agency they belong to exists. Nothing deletes them on any schedule, and deleting your own account does not remove them. Where an agency is closed, its rows are deleted with the rest of that agency’s data under Terms of Service section 13.4. |
| Server log files | Application log files are kept for 30 days and then deleted. The service’s own container output is capped by size rather than by age — five files of 20 MB each per service, oldest discarded — so how far back it reaches depends on how busy that service has been. |
| The record of your deletion request | Kept indefinitely, as the record that the request was made and honoured, in the same append-only log. |
| Database backups | Backups are taken nightly, weekly and monthly. The rotation is configured to keep at most 14 nightly copies, 56 weekly and 365 monthly — those are the ceilings the schedule allows, not a statement of how far back the copies actually reach, which depends on how long the arrangement has been running. Data you delete stays in any backup already taken until that backup rotates out. We do not edit or selectively erase individual records inside a backup; a backup is restored whole or not at all. |
12. Deleting your account and your data
12.1 You can delete your Devign Agency Suite account in two ways:
- In the app: Account → Delete your account, and confirm with your current password.
- On the web: visit https://creatorapp.devignlb.com/account/delete, enter the email address on your account, and confirm with the code we email you. No app and no password are needed.
The two routes delete the same things, with one difference worth knowing before you choose. If you are the last owner of an agency, only the in-app route can close that agency for you as part of the same request (12.6). The web route refuses, names the agency that is in the way, and deletes nothing.
12.2 What deletion removes. Your email address and any other sign-in identity, your password, your display name, your profile image, your contact email address and everything you told us at the setup step — your role, your agency’s name, your agency’s TikTok handle and your country — every session and token, your memberships and any invitation still outstanding, your notes and free text, appeal message bodies, request details, daily-challenge answers, workspace notifications addressed to you, and TikTok’s own identifier for you on any agency roster. Your account record is left pointing at nobody.
12.3 It is immediate. The deletion runs inside the same request. There is no queue and no waiting period, and there is no recovery afterwards.
12.4 What deletion does not remove.
- The agency’s business record of you — your TikTok handle, the months you worked there, and the figures for those months. This is the agency’s record, kept so it can reconcile what it owes and answer its own legal and tax obligations.
- Our security and audit records, including the IP address and user-agent recorded against actions you took, and the account identifier they were recorded against. These are append-only, cannot be altered or deleted by anyone including us, and are kept indefinitely. Deleting your account removes the personal data in the account; the audit trail of actions taken on the service remains. We think you should know that before you delete, rather than after.
- Your record of accepting the Terms and this policy, with the version of each and the date, and the date you confirmed you are 18. These say that an attestation was made and carry no name, address or number, and they are the only evidence that it was made at all.
- Your daily activity records and session presence records — the rows saying that the account was used on a given day, for how long, and from which app version and device model.
- Anything already written to a backup, until that backup is rotated out on the schedule in section 11.
12.5 If you want a copy first, ask before you delete. Deletion is immediate and there is no export button. If you want a copy of your data, request it under section 13 and wait for it to arrive before you delete the account, because afterwards there is less for us to produce.
12.6 A sole agency owner cannot delete their account first. If you are the last owner of an agency, the app will refuse and tell you which agency is in the way. Nothing is deleted when it refuses. To proceed:
- Make someone else an owner in the app under Team, and wait until they have accepted — an invitation nobody has opened does not count. Then request deletion again.
- Or close the agency along with your account. The app offers this on the deletion screen as a separate, clearly marked choice that names the agency it will close. It is never the default and never happens unless you choose it. Choosing it closes that agency, ends everyone’s access to it including yours, and deletes your account in the same request. Figures already collected are kept, and the workspace is deleted afterwards under the 30-day process in Terms of Service section 13.4.
- The web deletion page cannot do that second thing. It has no agency-closing choice: it refuses, names the agency, and deletes nothing. Use the app, or email info@devignlb.com and a person at Devign will close the agency with you.
12.7 We do not charge for a deletion request and we will not ask you why.
13. Your rights
13.1 We offer the rights below to everyone who uses the app, wherever they live, rather than asking you to work out which law covers you:
- Access — ask what personal information we hold about you, and get a copy of it.
- Correction — ask us to correct something that is wrong. Note that figures read from TikTok can only be corrected by TikTok, and a record your agency wrote can normally only be corrected by that agency.
- Deletion — delete your account and its personal data, subject to section 12.
- A copy in a portable form — ask for your data in machine-readable files. There is no self-service export in the app. A person at Devign gathers the data from our systems by hand and sends it to you. That is a deliberate choice about how the request is handled, not a button we forgot to build.
- Object or restrict — ask us to stop or limit a particular use.
- Withdraw the AI coach authorisation — an agency owner can switch the coach off for the whole agency at any time. There is no per-creator exclusion: the software has no way to keep one creator out while the agency’s consent stands, so a creator who wants out has to ask their agency’s owner to switch it off. You may also write to us, and we will pass it on.
- Complain — to us, and to your local privacy regulator where you have one.
13.2 If you are in the United States. Several US states now give residents privacy rights of this kind, and whether a particular state law applies to a business depends on its size and how much data it handles. We do not claim that any specific state law applies to us or that we comply with it. We answer the request either way. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that basis. If we ever refuse a request, we will tell you why and how to ask us to reconsider.
13.3 If you are in the Gulf, the Levant or Turkey. Your country may give you rights under its own data protection law — for example Turkey’s KVKK, or the personal data protection laws of Saudi Arabia and the UAE. We do not claim that any particular one applies to us or that we comply with it. We answer the request either way.
13.4 How to ask, and how long we take. Use the in-app or web deletion flow for a deletion, or write to info@devignlb.com for anything else. We will confirm we received it and answer within 30 days of the day your request reaches us. The clock starts on receipt, not on anything we do afterwards. We do not charge, and we will not ask you why.
This is a promise kept by people, not by software. We record a request and its due date, but nothing in our systems watches that date or reminds anybody it is coming, and one person does this work. No request has yet been made or answered under this policy. We are telling you so that you hold us to the 30 days rather than assume something is counting them for us.
13.5 We will check that the request really comes from you before we act on it — normally by emailing a code to the address on the account, and for an agency’s data by confirming that the person asking is one of its owners. We do this so that nobody else can obtain your data by asking for it. That check happens inside the 30 days and does not extend them. If you cannot complete it, we will tell you what is missing and why we cannot answer without it.
13.5a If you are a creator on an agency’s roster and have no account with us. Your TikTok handle and your monthly figures may be in this app because your agency put them there, without you ever installing it. Our identity check is built around an account, and you have none, so we cannot email a code to an address we do not hold. Write to info@devignlb.com and say which agency and which handle: we will tell you what is held against that handle, and we will do what we reasonably can to satisfy ourselves that you control it before we say anything. We may not be able to verify you, and where we cannot, we will say so rather than guess. Your agency is the party that put the information here and is the faster route for most requests; Terms of Service sections 8.6 and 8.7 set out what your agency has promised us about telling you.
13.6 If a law that applies to your request sets a shorter deadline than 30 days, the shorter one is the one we keep. We do not use the 30 days here to take longer than a law allows.
13.7 If your account or your agency has been closed by us, you have 30 days from the closure to ask for a copy of the data that was in it. Terms of Service section 13.3 sets that out. After that window the personal data is deleted and we cannot produce it.
13.8 What a request produces. For a person: your profile, your memberships, your record of accepting the Terms and this policy, and your activity records. For an agency, on an owner’s request: the roster, the monthly figures, the reward and payout configuration, and the agency’s notifications. Our security and audit records are not part of a routine copy; if you want to know what the audit log holds about you, say so in the request and we will tell you.
13.9 An agency using the app is responsible for its own relationship with its creators. Where a request concerns something the agency recorded, we may need to pass it to the agency.
14. Children
14.1 Devign Agency Suite is for adults. You must be 18 or older to hold an account. We ask you to confirm it by ticking a box reading “I am 18 or older, and I accept the Terms and the Privacy Policy”, and we record who confirmed it, against which versions of these documents, and when. Nothing in the app checks anyone’s age — the confirmation is a statement you make, and it is not asked at sign-up but at the separate acceptance step described in section 2.1. Accounts that existed before that step was built have not made it.
14.2 TikTok LIVE is not open to under-18s.
14.3 We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, contact us and we will close it and delete the personal data on it.
15. Changes to this policy
15.1 We may update this policy. When we do, we will change the effective date and the version at the top and post the new version here. The version at the top of this page is always the version in force, and it is the only version anybody can accept — an acceptance is recorded against the version that was published when it was given, and against no other.
15.2 Publishing a new version asks everybody again. Every acceptance already recorded names the older version, so once a new one is posted the app treats everyone as owing an answer on it and asks them for it. The earlier acceptance is kept as the record of what was agreed and when.
15.3 How you will find out — and you should not rely on us telling you. We do not email, message or send a notification when this policy changes. There is no such mechanism. The only way the app tells you is by asking you, the next time you open it, to accept the new version. If you do not open the app you will not be told. Where a change materially affects how we handle your information we will ask you to acknowledge the new version through that same prompt; today the prompt asks and does not block, so a person who declines can still use the service. If you want to know when this document changes, check this page or write to us. Every version we publish stays readable at its own permanent address once it is superseded, so an acceptance recorded against a version number names a document you can still read; the list at the foot of this page links to each one.
16. Contact us
Questions, requests and complaints about privacy all go to the same place: info@devignlb.com.
Devign LLC, 5830 E 2ND ST, STE 7000 #23016, CASPER, WY 82609, USA
Previous versions
Every version we publish stays readable at its own address, so that an acceptance recorded against a version number names a document you can still read.
- 2026-09-09 — in force since . This document.
- 2026-08-10 — in force to . Superseded.