Overview
FloPost ("we", "us", or "our") operates flopost.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. If you do not agree with the terms of this policy, please do not access the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address, name, and authentication credentials when you create a FloPost account
- Content: Posts, images, videos, captions, hashtags, and scheduling preferences you create within FloPost
- Payment Information: Billing details processed securely through Stripe (we do not store your full credit card number)
- Automation Rules: Keyword triggers and response templates you configure for automated engagement
- Support Communications: Messages you send to our support team
1.2 Information from Connected Social Media Platforms
When you connect your social media accounts via OAuth authorization, we access and store the following data only with your explicit permission:
Meta Platforms (Facebook & Instagram):
- Profile Information: Username, profile picture URL, account type (Business/Creator), page name and ID
- Access Tokens: OAuth access tokens for posting and reading content on your behalf (stored encrypted server-side)
- Post Data:Your published posts' metadata including captions, timestamps, media URLs, and permalink
- Insights & Analytics: Follower counts, engagement metrics (likes, comments, shares, saves), reach, impressions, profile views, website clicks, and follower demographics (age, gender, city, country)
- Messages: Instagram Direct Messages sent to your Business account (used for inbox and auto-reply features)
- Comments: Comments on your posts (used for inbox display and automated engagement)
- Page Information: Facebook Pages you manage and their linked Instagram Business accounts
TikTok:
- Profile Information: Username, display name, avatar, and profile link (
user.info.basic,user.info.profile) - Account Statistics: Follower count, following count, likes count, and video count (
user.info.stats) - Your Video Metadata: Titles, cover images, durations, permalinks, and per-video view/like/comment/share counts for videos on your own account (
video.list) - Publishing: Permission to upload and publish the videos you compose in FloPost (
video.upload,video.publish) - Access Tokens: OAuth access and refresh tokens (stored encrypted server-side)
YouTube (Google):
- Channel Profile: Channel name, channel ID, and channel thumbnail
- Channel Statistics: Subscriber count, total view count, and video count
- Your Video Metadata & Statistics: Titles, descriptions, thumbnails, publish times, privacy status, and per-video views, likes, and comment counts for videos on your own channel
- Comments on Your Own Videos: Comment text and author display name, used for the unified inbox and the auto-reply rules you configure
- Publishing: Permission to upload and publish the videos you compose in FloPost
- Access Tokens: OAuth access and refresh tokens (stored encrypted server-side)
YouTube data is covered in full detail — per scope, with retention and revocation — in Section 4 below.
Threads (Meta):
- Profile information (username, biography, profile picture)
- Post content and publishing permissions
- Post insights (views, likes, replies, reposts, quotes)
- Replies to your own Threads posts (for inbox display and managed replies)
LinkedIn:
- Profile Information: Your name, profile picture, and LinkedIn member ID, plus the email address on your LinkedIn account (
openid,profile,email) - Publishing: Permission to post text and media to your LinkedIn feed on your behalf (
w_member_social) - Access Tokens: OAuth access tokens (stored encrypted server-side)
X (formerly Twitter):
- Profile Information: Username, display name, and user ID (
users.read) - Post Data: Your own posts and their metadata (
tweet.read) - Publishing: Permission to publish posts, and — only where your X plan grants it — to upload attached media (
tweet.write,media.write) - Access Tokens: OAuth 2.0 access and refresh tokens, so connections survive without re-authorising (
offline.access; stored encrypted server-side)
1.3 Automatically Collected Information
- Usage data (features used, pages visited, actions taken within FloPost)
- Device information (browser type, IP address, operating system)
- Cookies and similar technologies for session management and preferences
2. How We Use Your Information
We use your data solely to provide and improve our Service:
- Content Publishing: Schedule and publish posts to your connected social media accounts at times you specify
- Inbox & Messaging: Display your Instagram DMs and comments in a unified inbox; send replies on your behalf when you choose to respond
- Automated Engagement: Execute auto-reply rules and auto-like settings that you configure and control
- Analytics & Insights: Fetch and display performance metrics for your content so you can make data-driven decisions
- Account Management: Store your connection status, tokens, and preferences to maintain your linked accounts
- Token Maintenance: Automatically refresh expiring access tokens so your connections remain active
- Service Improvement: Analyze anonymized usage patterns to improve features and user experience
- Customer Support: Respond to your inquiries and provide technical assistance
- Security: Verify webhook signatures, detect fraud, and prevent unauthorized access
- Legal Compliance: Comply with applicable laws and enforce our Terms of Service
We do NOT:
- Sell your personal information or social media data to any third party
- Share your data with advertisers or data brokers
- Use your content for purposes other than providing our Service to you
- Access your social media accounts for any purpose you have not authorized
- Send unsolicited messages from your accounts — automation only responds to incoming conversations
- Train AI models on your private data or content
4. YouTube API Services
FloPost uses YouTube API Services to publish to, and read data from, the YouTube channel you choose to connect. This section applies whenever a YouTube channel is connected to your FloPost account, and is in addition to the rest of this policy.
4.1 Governing Documents
By connecting a YouTube channel to FloPost you are also agreeing to the documents below. We encourage you to read them:
4.2 What YouTube Data We Access, and Why
We request the minimum set of Google OAuth scopes needed for the features you use. Each item below names the data, the scope it comes from, and the single purpose it serves:
- Channel profile — channel name, channel ID, and channel thumbnail (
youtube.readonly). Used to show you which channel is connected and to label posts and analytics with the right account. - Channel statistics — subscriber count, total view count, and video count (
youtube.readonly). Used to render your dashboard and analytics pages, and to store follower-history snapshots so you can see growth over time. - Your own video metadata — titles, descriptions, thumbnails, publish times, and privacy status of videos on your channel (
youtube.readonly). Used to display your published content inside FloPost and to match scheduled posts to the videos they produced. - Your own video statistics — views, likes, and comment counts, plus aggregate channel performance figures (
yt-analytics.readonly). Used solely to display performance metrics back to you. - Comments on your own videos — comment text, comment ID, and author display name (
youtube.force-ssl). Used to populate the unified inbox and to run the auto-reply rules you configure. Replies are posted only from your channel, and only in response to an incoming comment. - Video upload and publishing — (
youtube.upload,youtube). Used only to upload and publish the videos you compose and schedule in FloPost, at the time you specify. - OAuth access and refresh tokens — stored encrypted server-side and never exposed to your browser. Refresh tokens are used only to keep your connection active so scheduled posts do not fail.
We do not access videos, comments, or analytics belonging to channels you do not own, and we do not use YouTube data for advertising, for building user profiles, or for training any AI or machine-learning model.
4.3 Storage and Retention of YouTube Data
YouTube data we fetch is stored in Firebase Firestore (Google Cloud, United States) so the dashboard, inbox, and analytics views can render without re-querying YouTube on every page load. We retain it as described here:
- While your channel is connected: channel profile and statistics, metadata and statistics for your own videos, and comments surfaced in your inbox are retained so those views stay populated. Records are refreshed in place as newer data is fetched.
- No automatic age-based deletion: we do not run a scheduled job that deletes stored YouTube records once they reach a certain age. Records are refreshed in place as newer data is fetched, and older records are kept so your history and growth charts remain intact. Retention is driven by the events below — disconnecting the channel, deleting your account, or asking us to delete your data — not by a timer.
- When you disconnect the channel: the stored OAuth access and refresh tokens for that channel are deleted immediately and we stop fetching any new YouTube data. Previously fetched data (past posts, historical analytics snapshots, and stored comments) remains in your FloPost account so your history is not silently erased.
- When you delete your FloPost account or request deletion: all stored YouTube data is permanently deleted, as described in Section 7.
- OAuth tokens: governed by the events above rather than by age — they are deleted the moment you disconnect the channel, and kept valid by refresh while it is connected.
You can delete stored YouTube data at any time without waiting for account closure — see flopost.ai/data-deletion or email admin@flopost.ai.
4.4 Revoking FloPost's Access to Your YouTube Data
You can revoke our access at any time, by either route:
- In FloPost: disconnect the YouTube channel from the Accounts page. This deletes the stored tokens and stops all further YouTube API calls for that channel.
- At Google: visit the Google security settings page at https://myaccount.google.com/permissions and remove FloPost's access. This revokes our tokens at Google, so no further YouTube API request from FloPost can succeed.
Revoking access stops future data collection. To also delete YouTube data we have already stored, submit a deletion request as described in Section 7.
4.5 Data We Send to YouTube
We send content to YouTube only when you act: publishing or scheduling a video, or sending a comment reply (manually, or through an auto-reply rule that you created and enabled). Anything we upload on your behalf is content you supplied to FloPost.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data is transmitted over TLS/SSL (HTTPS)
- Server-side token storage: OAuth access tokens are stored in Firebase Firestore, never exposed to the client browser
- Webhook verification: Instagram and Facebook webhooks are verified using HMAC-SHA256 signatures
- Authentication: All API endpoints that access user data require Firebase Authentication
- Scheduled task verification: Scheduled post execution endpoints use cryptographic QStash signature verification
- CRON job protection: Background jobs are protected by bearer token authentication
- Security headers: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are enforced on all responses
While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Data Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request complete deletion of your data (see Section 7)
- Portability: Request transfer of your data in a machine-readable format
- Withdrawal of Consent: Disconnect any social media account at any time from the Accounts page — this immediately revokes our access to that platform. For Google/YouTube you can also revoke access directly at https://myaccount.google.com/permissions.
- Objection: Object to processing of your data for specific purposes
- Restriction: Request that we limit how we process your data
To exercise any of these rights, contact us at admin@flopost.ai. We will respond within 30 days.
7. Data Deletion
You can request deletion of your data through any of these methods:
- Visit our Data Deletion page and follow the instructions
- Email us at admin@flopost.aiwith "Data Deletion Request" in the subject line
- For Facebook/Instagram users: Data deletion is also initiated automatically through Meta's platform when you remove our app from your Facebook settings. Our callback endpoint at
/api/data-deletionprocesses these requests.
Upon receiving a deletion request, the following data will be permanently removed within 30 days:
- Your FloPost account information and authentication data
- All stored OAuth access tokens for connected platforms
- Scheduled posts, drafts, and post history
- Analytics data and follower history snapshots
- Stored messages and comments from the unified inbox
- Automation rules and settings
- Uploaded media files (images, videos)
You can check the status of your deletion request at flopost.ai/data-deletion using the confirmation code provided.
Note: Deleting data from FloPost does not delete content already published to your social media accounts. To manage content on Facebook, Instagram, Threads, TikTok, YouTube, LinkedIn, or X, use those platforms' native tools. To revoke FloPost's access to your accounts, remove the app from each platform's settings — for Google/YouTube, that is https://myaccount.google.com/permissions.
8. Data Retention
We retain your personal data only as long as necessary:
- Active accounts: Data is retained while your account remains active and connected
- Disconnected platforms: When you disconnect a social media account, we delete the associated access token and stop fetching new data. Historical data (posts, analytics, stored comments and messages) is retained until you delete your FloPost account or request deletion.
- YouTube data: retained on the same event-driven basis as every other platform — we do not delete stored YouTube records automatically once they reach a given age. Records are refreshed in place as newer data is fetched, and your history is kept until you disconnect the channel, delete your FloPost account, or ask us to delete your data. See Section 4.3 for the detail.
- Other platforms: Retention for non-YouTube platform data is event-driven: it persists until you disconnect the account (tokens are deleted immediately), or until you delete your FloPost account or submit a deletion request.
- Deleted accounts: All data is permanently deleted within 30 days of a deletion request
- Access tokens: Automatically refreshed before expiration (within 20 days of expiry) to maintain functionality. Expired tokens that cannot be refreshed are flagged.
- Legal requirements: Some data may be retained longer if required by law (e.g., financial records for tax compliance)
9. Children's Privacy
Our Service is not intended for users under 13 years of age (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at admin@flopost.ai and we will promptly delete such data.
10. International Data Transfers
FloPost is hosted on Firebase App Hosting (Google Cloud, United States), and our database, authentication, and file storage are Google Cloud services in the United States. Your information may be transferred to and maintained on servers located outside your country of residence, where data protection laws may differ. By using our Service, you consent to this transfer. We ensure appropriate safeguards are in place, including data processing agreements with our service providers.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
To exercise these rights, contact admin@flopost.ai.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland:
- Legal basis: We process your data based on your consent (connecting social media accounts) and contractual necessity (providing the Service)
- Data Protection Officer: Contact admin@flopost.ai
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority
- Data transfers: Transfers outside the EEA are protected by standard contractual clauses or other appropriate safeguards
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification to your registered email address
- Prominent notice within the FloPost dashboard
- Updating the "Last Updated" date at the top of this policy
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account.
15. Contact Us
For privacy-related questions, concerns, or data requests:
- Privacy Email: admin@flopost.ai
- Data Deletion: flopost.ai/data-deletion
- Website: flopost.ai
Platform-Specific Privacy Policies
Your use of connected social media platforms is also subject to their respective privacy policies:
Last updated: July 21, 2026