MilaKnight OS
os.mila-knight.com
Privacy Policy
Last Updated: August 2026
1. Introduction
MilaKnight OS ("we", "our", or "us"), operated by MilaKnight Agency, is a social media analytics and management platform, accessible both through our web platform at os.mila-knight.com and through the MilaKnight OS mobile application (the "App"), used by our staff and by clients we have onboarded. This Privacy Policy explains how we collect, use, store, and protect your personal information across both.
By using MilaKnight OS, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you register, we collect your name, email address, and role within your organization. Staff accounts additionally include a phone number and job details (job title, department, hire date) for the internal company directory.
2.2 TikTok Data (via TikTok Login Kit)
When you connect your TikTok account, we collect the following data using TikTok's official API:
- user.info.basic: Open ID, avatar URL, display name — used to identify and display your connected TikTok account.
- user.info.profile: Bio description, profile web link, profile deep link, verified status — used to display your profile information in the dashboard.
- user.info.stats: Follower count, following count, likes count, video count — used to display organic performance metrics.
- video.list: List of your public TikTok videos including titles, view counts, and engagement — used to display content performance analytics.
2.3 Meta (Facebook & Instagram) Data
When you connect your Meta accounts, we collect:
- Page insights: reach, impressions, engagement, follower count
- Ad account performance: spend, CPC, impressions, link clicks
- Instagram account insights: reach, profile views, website clicks
- Basic profile information for account identification
2.4 Salla Store Data (via the Salla Merchant API & Webhooks)
When you install MilaKnight from the Salla App Store, Salla delivers an authorization payload to our webhook endpoint at https://os.mila-knight.com/api/webhooks/salla. With your consent we then receive and store the following data so we can present it back to you in the dashboard:
- Store profile: store id, name, subdomain/domain, plan tier, owner email, and country.
- Orders: order id, status, payment method, totals (subtotal, tax, shipping, discount), currency, items count, customer reference, timestamps. Stored as a local mirror updated by Salla's
order.*webhooks. - Products: product id, name, SKU, price, sale price, stock quantity, status, thumbnail.
- Customers: customer id, name, email, mobile, city/country, lifetime orders count and total spent.
- Abandoned carts: cart id, total, items count, customer reference, recovery status.
- Reviews: rating, content, product reference (when applicable).
- OAuth tokens: access token and refresh token issued by Salla, used solely to read the data above on your behalf. These are encrypted at rest.
We use this data only to render your live analytics dashboard. We do not share, sell, or otherwise transfer Salla store data to third parties. We do not act on your store programmatically (we never place orders, change products, message customers, etc.). The Salla connection is read-only.
2.5 Other Platforms
We may also collect analytics data from Snapchat Ads, LinkedIn, X (Twitter), Google Ads, and YouTube when you choose to connect those accounts. In each case, only the data necessary to display performance metrics is collected.
2.6 Employment and HR Information (mobile app, staff accounts only)
- Attendance records — check-in/check-out times and working hours.
- Leave requests — dates, leave type, and the reason you enter.
- Salary and contract details — visible only to authorized Admin/HR/Owner roles; the server does not send this information to anyone else.
2.7 Content You Create (mobile app)
Messages you send (including group messages), voice notes you record, photos/videos/files you attach, and media you add to action plans. This content is stored on our backend so it can be shown to its intended recipients inside the App.
2.8 Client Business Information (mobile app, client accounts)
Your client profile, campaign and advertising metrics, reports, and account details — shown only to the client they belong to and to the MilaKnight team members assigned to that client.
2.9 Approximate Location (mobile app, optional)
Only on the virtual-office screen, and only if you grant the permission, the App reads your approximate (coarse) location — never precise/GPS-level location; the App does not request that permission — to show local weather and prayer times. If you decline, a default city is used and the feature still works. Your coordinates are sent directly from your device to our weather and prayer-time providers (Open-Meteo and AlAdhan) and never reach MilaKnight's own servers.
2.10 Device and Security Information (mobile app)
To protect accounts and company data, the App checks the device for tampering signals (for example rooting/jailbreak, hooking tools, running on an emulator, or screen capture). When a security event is detected, the App reports the device model, operating-system version, App version, and the detected threat type. If a known-malicious app is detected on the device, its package name is included in the report.
2.11 Push-Notification Identifiers (mobile app)
A push registration token (Firebase Cloud Messaging token) is generated on your device so our server can send you notifications; it is sent to us paired only with your device's operating system, and is removed from our server when you sign out. MilaKnight's own servers never receive or store any separate installation identifier. Separately, and outside of MilaKnight's control, Google's Firebase infrastructure uses its own internal installation identifier with Google's own servers as part of issuing this token in the first place — this is a standard part of how Firebase Cloud Messaging operates and does not involve MilaKnight.
2.12 Voice and Video Calls (mobile app)
In virtual-office rooms, your microphone (and your camera, which stays off until you turn it on) carry your live audio/video to the other participants via LiveKit. The App does not record or store calls.
3. How We Use Your Data
- To display real-time analytics and performance metrics in your dashboard
- To generate reports for your social media accounts
- To authenticate and maintain your connected platform accounts
- To run attendance, leave management, and the staff directory
- To deliver messages, files, and action-plan content to the right people
- To show local weather and prayer times (if you allow location)
- To send notifications related to your account or service updates
- To protect accounts and company data from tampering and fraud
- To improve our platform's features and user experience
We do not sell, rent, or share your personal data or platform data with any third parties for advertising or commercial purposes.
4. Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide our services. TikTok data obtained via the API is used in real-time and is not stored beyond the session unless explicitly needed for dashboard display.
Salla data: when you uninstall MilaKnight from your Salla store, Salla sends us an app.uninstalled webhook. We immediately mark the store as uninstalled and stop syncing. Your historical mirror data is preserved for 90 days to allow easy reinstall, after which it is permanently deleted unless you reinstall the app. You may also request immediate deletion by emailing privacy@mila-knight.com; we will delete all Salla store data we hold within 30 days.
Security reports (mobile app device-integrity checks) are retained for 180 days and then deleted automatically.
You may request deletion of any other personal data at any time using the same email.
5. TikTok API Compliance
Our use of TikTok data is subject to the TikTok Terms of Service and TikTok Privacy Policy. We only request data scopes that are strictly necessary for the functionality described above. We do not use TikTok data for any purpose beyond providing analytics within our platform.
6. Data Security
We implement industry-standard security measures to protect your data:
- All data is transmitted over HTTPS/TLS encryption
- Access tokens are stored securely and never exposed publicly — on mobile, sign-in tokens and cached profile data are kept in the device's hardware-backed secure storage (Android Keystore / iOS Keychain)
- Access to your data is restricted to authorized personnel only
- Regular security reviews are conducted on our infrastructure
7. Your Rights
You have the right to:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and all associated data
- Disconnection: Disconnect any social media platform at any time from your Connections page
- Portability: Request your data in a portable format
- Withdraw permissions: Location, microphone, camera, and notification permissions can each be revoked in your device settings at any time without losing access to the rest of the App
Because mobile app accounts (staff and client) are created and managed by MilaKnight rather than self-registered, account deletion for these is not self-service — contact us using the email below.
8. Data Deletion
To disconnect your TikTok or any other social media account, visit your Connections page in the platform. To request complete deletion of all your account data from our servers, contact us at support@mila-knight.com. We will process deletion requests within 30 days.
9. Third-Party Services
Our platform integrates with third-party services, each receiving only what its function requires:
| Service | What it receives | Why |
|---|---|---|
| TikTok, Meta, Snapchat, LinkedIn, X, Google, Salla | Platform-specific data as described in Section 2 | Displaying your connected-platform analytics |
| Open-Meteo | Approximate coordinates only — no name or account identifier | Local weather on the mobile app's office screen |
| AlAdhan | Approximate coordinates only — no name or account identifier | Local prayer times on the mobile app's office screen |
| Talsec | Device model, OS version, App version, detected security-threat data | Mobile app device-integrity and fraud protection |
| LiveKit | Live call audio/video streams and technical connection details | Real-time voice/video in the mobile app's office rooms |
| Google Firebase | Push registration token | Delivering mobile app push notifications |
Each integration is governed by the respective provider's own privacy policy. We are not responsible for the privacy practices of these third-party platforms. The mobile app contains no advertising SDKs, no ad identifiers, no analytics or tracking SDKs, and no crash-reporting services.
10. Children's Privacy
MilaKnight OS is intended for business use only and is not directed at, and must not be used by, individuals under the age of 18. We do not knowingly collect personal information from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last Updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
- Email: support@mila-knight.com
- Website: os.mila-knight.com
- Company: MilaKnight Agency, Kingdom of Saudi Arabia