PostFlow · Effective October 2, 2026
Privacy Policy
This policy describes how PostFlow handles information when you request access or use a PostFlow workspace. It reflects the features currently present in the app and may be updated when new services are added.
1. Information stored
- Account information: name, username, email, password hash, access status, contract dates, session identifiers, and login timestamps.
- Workspace content: post titles, descriptions, hashtags, selected platforms, campaign and schedule details, review history, and files you upload to the content library.
- Integration information: provider app IDs and secrets you submit, authorization tokens after consent, connected account identifiers, token expiry, and granted permissions.
- Team and security records: role assignments, hashed invitation tokens, audit events, and actions needed to protect the workspace.
- Analytics: provider metrics associated with a published post, such as impressions, reach, views, likes, comments, shares, saves, and clicks, when a provider supplies them.
2. How information is used
Information is used to operate authentication and access approval, administer one-year contracts, secure workspaces, store content and schedules, enforce team roles and approvals, complete provider authorization, display provider metrics, and provide support. PostFlow does not currently use third-party advertising or analytics trackers.
3. Provider sharing
When you choose to connect a provider, the app sends authorization requests to that provider and may exchange authorization codes for tokens. If publishing or metrics APIs are enabled, the relevant content or API requests are sent to the provider you selected. Each provider handles information under its own policies and terms. PostFlow does not send content to every provider merely because you create a draft.
4. Storage and security
Application records and uploaded files are stored on the deployment's persistent data volume. Provider app credentials and OAuth tokens are encrypted at rest using the server-side ENCRYPTION_KEY. Passwords are stored as hashes, not as readable passwords. Session cookies are HTTP-only and use secure transport in production.
No internet service can promise absolute security. Protect your password, do not share invitation links, and contact the administrator if you suspect that credentials or a connected account have been exposed.
5. Retention and deletion
Workspace records are retained while needed to operate the account, maintain security and review history, and meet administrative obligations. Expiring a contract blocks access but does not automatically erase workspace records. Archiving an asset hides it from the active library; it does not currently delete the underlying file. To request deletion or revoke a provider connection, contact the platform administrator and revoke access with the provider where appropriate.
6. Cookies and sessions
PostFlow uses an HTTP-only session cookie to maintain sign-in. A new sign-in may invalidate the previous session for that account. The app does not currently use advertising cookies.
7. Payments and minors
PostFlow does not currently collect payment-card details or automatically charge subscription fees. Renewal is coordinated with the administrator. The service is not designed for children.
8. Your choices and contact
You can review your profile and connected integrations within the app. For access, correction, export, deletion, contract, or privacy requests, contact the platform administrator using the contact channel through which your access was issued. You may also revoke authorization directly with a social platform.
9. Changes to this policy
This policy may change when the service or its providers change. The latest version is available at postflow/privacy. Continued use after an updated policy takes effect is subject to the revised policy.