Security and Privacy
The TRESSO Security Boundary
Your videos stay on your computer until you choose to post them. TRESSO does not store your videos in our cloud.
TRESSO is a desktop app - the work happens on your machine. Here is exactly what stays local, what leaves your computer, and why.
Stays on your computer:
- Your videos and media files - they leave only when you post, and then they go straight to the platform you chose, never to TRESSO.
- Your platform access tokens - stored locally and never written to any log.
- Your posting queue, captions, schedule, history, settings, and lock PIN.
Leaves your computer - and only this:
- License check: your license key and a hashed device identifier (not your name, email, or files) go to our license server to confirm your subscription is active on this device - no media, tokens, or post content.
- Posting: the selected video and caption go directly to the platform you chose - Pinterest today - through its own API. They do not pass through TRESSO.
- Connecting an account: a one-time authorization code passes through our server only to complete the secure token exchange (the platform requires an app secret we never ship inside the app). The resulting tokens are returned to your machine and stored locally - we do not retain your tokens.
- Optional anonymous diagnostics: off by default. App-health stats (scheduler running, post counts, connection health) are sent only if you turn on Share diagnostics. They never include videos, captions, platform tokens, media files, or post content.
- Support report: a sanitized status summary, sent only when you choose to - never tokens, media, or post text (captions are attached only if you explicitly consent).
- Billing: handled by Stripe's secure portal when you open Manage Billing.
On the app itself: Remote Access is off by default - the app listens only on your own machine. The optional phone Companion is view-only, requires pairing plus your PIN, is limited to read-only status pages, and cannot reach upload, account, settings, or sign-in actions even when unlocked.
Built Around Local Control
TRESSO was designed around a desktop-first workflow for content creators who want more control over their content, publishing process, and connected accounts.
Your videos, publishing queues, captions, and workflow content are intended to remain on your own computer unless you intentionally publish content through a connected platform. TRESSO is not a cloud media storage platform.
Local Storage Philosophy
TRESSO is designed to minimize unnecessary centralized storage of your content. Core workflow data is intended to remain local to your device whenever reasonably possible.
You remain responsible for:
- Local backups and device access
- Antivirus protection and operating system maintenance
- Password management and physical device security
Connected Platform Accounts
TRESSO may connect with third-party services including Instagram, YouTube, TikTok, and related publishing APIs. These integrations rely on official third-party platform systems.
TRESSO only uses connected platforms to support functionality you intentionally authorize, such as publishing scheduled content.
The access tokens that let TRESSO publish to your accounts are stored locally on your computer and are never written to any log. For platforms that require it, your one-time sign-in code is exchanged through our server only to complete the secure connection - your tokens are returned to your machine and are not retained on our servers.
No Cloud Video Library
TRESSO does not operate a cloud vault where your local video library is uploaded and stored for normal product operation. Your workflow remains centered around your own machine and storage environment.
Payment Security
Payments may be processed through trusted third-party providers such as Stripe. TRESSO does not directly store complete payment card information on TRESSO-controlled systems. Payment providers maintain their own security, compliance, and operational practices.
Reasonable Security Measures
TRESSO uses reasonable technical, operational, and administrative safeguards intended to help protect systems and operational integrity. However, no software, network, API, device, or transmission method can be guaranteed completely secure. Users should assume all internet-connected systems carry some level of operational risk.
Third-Party Platform Limitations
TRESSO depends on external platform infrastructure and APIs that are not controlled by TRESSO. Third-party platforms may change APIs, restrict functionality, modify authentication systems, experience outages, suspend integrations, or remove publishing capabilities without notice. TRESSO does not guarantee uninterrupted compatibility or availability of third-party integrations.
User Responsibility
Users are responsible for securing their devices, protecting account credentials, maintaining backups, monitoring publishing activity, verifying scheduled content, and following platform rules and policies.
TRESSO is not responsible for compromised devices, local file loss, user-side security failures, weak passwords, malware infections, or third-party platform actions.
No Absolute Security Guarantee
While TRESSO prioritizes privacy and operational control, no software or system can guarantee absolute security, perfect uptime, error-free operation, continuous API compatibility, or complete protection against all threats. Users assume responsibility for operating within their own local environments and security practices.
Reporting Security Concerns
Security issues or suspected vulnerabilities may be reported to:
Email: support@tressohq.com
Subject: Security Report
Please include relevant details, screenshots, logs, reproduction steps, and environment information where possible.
Policy Updates
This Security and Privacy page may be updated periodically. Continued use of TRESSO after updates become effective constitutes acceptance of revised policies.
Contact
Questions regarding security or privacy practices may be sent to support@tressohq.com.