Overview
FLOPOST, LLC ("FloPost", "we", "us", or "our") operates flopost.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. If you do not agree with the terms of this policy, please do not access the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address, name, authentication credentials, and your FloPost handle when you create a FloPost account
- Content: Posts, images, videos, captions, hashtags, and scheduling preferences you create within FloPost, and the usernames of people you tag or invite as collaborators in a post
- Payment Information: Billing details processed securely through Stripe (we do not store your full credit card number)
- Automation Rules: Keyword triggers and response templates you configure for automated engagement
- Support Communications: Messages you send to our support team
1.2 Information from Connected Social Media Platforms
When you connect your social media accounts via OAuth authorization, we access and store the following data only with your explicit permission:
Meta Platforms (Facebook & Instagram):
- Profile Information: Username, profile picture URL, account type (Business/Creator), page name and ID
- Access Tokens: OAuth access tokens for posting and reading content on your behalf (stored encrypted server-side)
- Post Data: Your published posts' metadata including captions, timestamps, media URLs, and permalink
- Insights & Analytics: Follower counts, engagement metrics (likes, comments, shares, saves), reach, impressions, profile views, website clicks, and follower demographics (age, gender, city, country)
- Messages: Instagram Direct Messages sent to your Business account (used for inbox and auto-reply features)
- Comments: Comments on your posts (used for inbox display and automated engagement)
- Page Information: Facebook Pages you manage and their linked Instagram Business accounts
TikTok:
- Profile Information: Username, display name, avatar, and profile link (
user.info.basic,user.info.profile) - Account Statistics: Follower count, following count, likes count, and video count (
user.info.stats) - Your Video Metadata: Titles, cover images, durations, permalinks, and per-video view/like/comment/share counts for videos on your own account (
video.list) - Publishing: Permission to publish the videos you compose in FloPost (
video.publish) - Comments on your own TikTok videos (only if you connect TikTok for comment replies, using TikTok API for Business permissions Get Business Comment and Manage Account Comment): the comment ID, video ID, comment text and the commenter's TikTok identifier. We use them only to list them for you in your FloPost account, to check whether a comment matches a keyword rule you created and switched on, and to post the one public reply that rule specifies, from your account. FloPost does not send TikTok direct messages. This data is deleted automatically 30 days after we receive it, and sooner when you disconnect TikTok in FloPost, delete your FloPost account, or ask us to delete it. If someone who commented asks us to stop, FloPost deletes their stored comments and does not store their comments or reply to them again. FloPost also keeps your own TikTok identifier, so that it never replies to your own comments; it is deleted when you disconnect TikTok in FloPost or delete your FloPost account.
- Access Tokens: OAuth access and refresh tokens (stored encrypted server-side)
YouTube (Google):
- Channel Profile: Channel name, channel ID, and channel thumbnail
- Channel Statistics: Subscriber count, total view count, and video count
- Your Video Metadata & Statistics: Titles, descriptions, thumbnails, publish times, privacy status, and per-video views, likes, and comment counts for videos on your own channel
- Channel Analytics: Aggregate YouTube Analytics reports for your own channel (views, watch time, subscriber changes, engagement, and audience age-group and gender mix as percentages), shown to you and not stored
- Comments on Your Own Videos: Comment text, author display name, and author channel ID, used for the unified inbox and the auto-reply rules you configure
- Publishing: Permission to upload and publish the videos you compose in FloPost
- Access Tokens: OAuth access and refresh tokens (stored encrypted server-side)
YouTube data is covered in full detail — per scope, with retention and revocation — in Section 4 below.
Threads (Meta):
- Profile information (username, biography, profile picture)
- Post content and publishing permissions
- Post insights (views, likes, replies, reposts, quotes)
- Replies to your own Threads posts (for inbox display and managed replies)
- Posts that mention you
- Deleting a Threads post when you ask FloPost to
LinkedIn:
- Profile Information: Your name, profile picture, and LinkedIn member ID, plus the email address on your LinkedIn account (
openid,profile,email) - Publishing: Permission to post text and media to your LinkedIn feed on your behalf (
w_member_social) - Company Pages (Brand plan): If you connect a LinkedIn Page with the separate "Connect LinkedIn Page" button, FloPost reads the Pages where your LinkedIn role lets you post, and each Page's name and ID. It publishes the posts you write (text, or text with one image) as the Page, now or at the time you schedule. It reads the comments on the Page's posts when you open a post, and posts your replies, and any first comment you add, as the Page. It shows the totals LinkedIn reports for the Page's posts (impressions, likes, comments, shares and engagement) and does not store them (
r_organization_social,w_organization_social,rw_organization_admin,r_organization_social_feed,w_organization_social_feed) - People who comment on your Page's posts: FloPost shows a comment's text and time. It shows the commenter's name only when LinkedIn includes the name in the comments it sends; otherwise it shows "LinkedIn member". FloPost saves none of this. It gets the comments from LinkedIn again each time you open the post. It never adds commenters to contacts, never uses them in automations, never messages them and never exports them
- What FloPost keeps for a Page: the Page's name and ID, the IDs of the posts FloPost published to it, and the Page's access token (stored encrypted server-side). If you manage more than one Page, the list of Pages and the token wait, encrypted, for up to 10 minutes while you choose which ones to connect. FloPost also counts how many LinkedIn Page requests your account makes each day, so it can stay under LinkedIn's daily limit, and it deletes those counts after 2 days
- Access Tokens: OAuth access tokens (stored encrypted server-side)
X (formerly Twitter):
- Profile Information: Username, display name, and user ID (
users.read) - Post Data: Your own posts and their metadata (
tweet.read) - Publishing: Permission to publish posts, and — only where your X plan grants it — to upload attached media (
tweet.write,media.write) - Access Tokens: OAuth 2.0 access and refresh tokens, so connections survive without re-authorising (
offline.access; stored encrypted server-side)
1.3 Automatically Collected Information
- Usage data (features used, pages visited, actions taken within FloPost)
- Device information (browser type, IP address, operating system)
- Cookies and similar technologies for session management and preferences
1.4 People Who Interact with Our Customers
Using FloPost also means we hold some information about other people: people who comment on your posts, message you or receive a message from you, follow your accounts, or tap a link you share through FloPost. We hold it on your behalf, to provide the Service to you:
- Comments and messages: the platform's ID for the person, their username, display name and profile picture, the text of their comment or message, and whether they follow your account when a rule of yours depends on it
- Followers: the platform's ID, username, display name and profile picture of the people who follow your accounts, and of those who stop following them, kept in the follower history behind your growth charts
- Link taps: when someone taps a lead-magnet link you share through FloPost, their IP address, country, network (ASN, the number that identifies their internet provider), browser type, device type and language; when someone taps a link on your FloPost link-in-bio page, the site they came from, their device type and browser type
- Tags and collaborators: the usernames of people you tag or invite as collaborators in an Instagram post
If you are one of these people and want FloPost to delete this information, visit flopost.ai/data-deletion or email support@flopost.ai.
2. How We Use Your Information
We use your data solely to provide and improve our Service:
- Content Publishing: Schedule and publish posts to your connected social media accounts at times you specify
- Inbox & Messaging: Display your Instagram DMs and comments in a unified inbox; send replies on your behalf when you choose to respond
- Automated Engagement: Execute auto-reply rules and auto-like settings that you configure and control
- Analytics & Insights: Fetch and display performance metrics for your content so you can make data-driven decisions
- Account Management: Store your connection status, tokens, and preferences to maintain your linked accounts
- Token Maintenance: Automatically refresh expiring access tokens so your connections remain active
- Service Improvement: Analyze usage patterns to improve features and user experience
- Customer Support: Respond to your inquiries and provide technical assistance
- Security: Verify webhook signatures, detect fraud, and prevent unauthorized access
- Legal Compliance: Comply with applicable laws and enforce our Terms of Service
We do NOT:
- Sell your personal information or social media data to any third party
- Share your data with advertisers or data brokers
- Use your content for purposes other than providing our Service to you
- Access your social media accounts for any purpose you have not authorized
- Send unsolicited messages from your accounts — automation only responds to incoming conversations
- Train AI models on your private data or content
4. YouTube API Services
FloPost uses YouTube API Services to publish to, and read data from, the YouTube channel you choose to connect. This section applies whenever a YouTube channel is connected to your FloPost account, and is in addition to the rest of this policy.
4.1 Governing Documents
By connecting a YouTube channel to FloPost you are also agreeing to the documents below. We encourage you to read them:
4.2 What YouTube Data We Access, and Why
We request the minimum set of Google OAuth scopes needed for the features you use. When you connect a YouTube channel, FloPost requests exactly these four Google OAuth scopes, and no others:
https://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.force-sslhttps://www.googleapis.com/auth/youtube.readonlyhttps://www.googleapis.com/auth/yt-analytics.readonly
Separately, if you use Sign in with Google to log in to FloPost, we ask Google only for your basic profile and email address (the profile and email scopes): your name, email address, profile picture, and Google account ID. We use them only to create and identify your FloPost account. Signing in with Google gives FloPost no access to your YouTube channel; that requires the separate connection above.
Each item below names the data, the scope it comes from, and the single purpose it serves:
- Channel profile — channel name, channel ID, and channel thumbnail (
youtube.readonly). Used to show you which channel is connected and to label posts and analytics with the right account. - Channel statistics — subscriber count, total view count, and video count (
youtube.readonly). Used to render your dashboard and analytics pages, and to store follower-history snapshots so you can see growth over time. - Your own video metadata — titles, descriptions, thumbnails, publish times, and privacy status of videos on your channel (
youtube.readonly). Used to display your published content inside FloPost and to match scheduled posts to the videos they produced. - Your own video statistics — views, likes, and comment counts for each video on your channel (
youtube.readonly). Used solely to display performance metrics back to you. - YouTube Analytics reports — aggregate reports about your own channel only: views, watch time, average view duration and percentage viewed, subscribers gained and lost, likes, dislikes, comments, and shares, broken down by day, month, video, country, traffic source, or device type, and your audience's age-group and gender mix as aggregate percentages (
yt-analytics.readonly). Used solely to display performance metrics back to you. These reports are fetched when requested and are not stored by FloPost. - Comments on your own videos — comment text, comment ID, author display name, and author channel ID (
youtube.readonly,youtube.force-ssl). Used to populate the unified inbox and to run the auto-reply rules you configure. - Replying to comments — (
youtube.force-ssl). Used to post replies from your channel — ones you write, or ones sent by an auto-reply rule you created and enabled — and, when you instruct FloPost to, to delete a reply you posted or to hide (reject) a comment someone else left on your video. Replies are posted only from your channel, and only in response to an incoming comment. - Video upload and publishing — (
youtube.upload). Used only to upload and publish the videos you compose and schedule in FloPost, at the time you specify. - OAuth access and refresh tokens — stored encrypted server-side and never exposed to your browser. Refresh tokens are used only to keep your connection active so scheduled posts do not fail.
We do not access videos, comments, or analytics belonging to channels you do not own, and we do not use YouTube data for advertising, for building user profiles, or for training any AI or machine-learning model.
4.3 Storage and Retention of YouTube Data
YouTube data we fetch is stored in Firebase Firestore (Google Cloud, United States) so the dashboard, inbox, and analytics views can render without re-querying YouTube on every page load. We retain it as described here:
- While your channel is connected: channel profile and statistics, metadata and statistics for your own videos, and comments surfaced in your inbox are retained so those views stay populated. Records are refreshed in place as newer data is fetched.
- Most stored YouTube records are deleted at 30 days: a scheduled daily job deletes these stored YouTube records once they are 30 days old: your videos' cached metadata and statistics; the comment threads and comment text in your inbox; the commenter identifiers we need in order to reply (including the commenter's channel ID); the log your auto-reply rules keep of each comment they answered or tried to answer — the comment's ID and text and the reply sent; and the channel profile snapshot saved when you connect an account or refresh your profile — your channel's name, description, subscriber count, and profile and banner images, and the titles, thumbnails, and view, like, and comment counts of up to 25 recent videos. Anything still in use is simply fetched again by the normal sync, so for live content this is a refresh boundary rather than a loss; what ages out is the copy we were holding (a channel profile snapshot is saved again the next time you connect the channel or refresh your profile). Not deleted by this job: your account settings and automation rules, which are not YouTube records; the daily subscriber-count snapshots behind your growth charts; the view, like, and comment counts recorded for each video you publish through FloPost at 1 hour, 24 hours, and 7 days after it goes out; a one-way fingerprint (a hash) of the ID of each comment your auto-reply rules answered, with the date and whether the reply was sent, kept so that FloPost never answers the same comment twice; and a list of one-way hashed commenter identifiers kept so that someone who asked not to be contacted again stays uncontacted. Those are kept on the event-driven basis below. YouTube Analytics reports are never stored, so there is nothing of theirs to keep.
- When you disconnect the channel: the stored OAuth access and refresh tokens for that channel are deleted immediately and we stop fetching any new YouTube data. The rest of the YouTube data we stored for that channel is deleted within 7 days of the disconnect, except the list of one-way hashed commenter identifiers described above, which is kept so that someone who asked not to be contacted stays uncontacted, and the one-way fingerprints of answered comments described above, which are kept so that FloPost never answers the same comment twice.
- When you delete your FloPost account or request deletion: all stored YouTube data is permanently deleted, as described in Section 7.
- OAuth tokens: governed by the events above rather than by age — they are deleted the moment you disconnect the channel, and kept valid by refresh while it is connected.
You can delete stored YouTube data at any time without waiting for account closure — see flopost.ai/data-deletion or email admin@flopost.ai.
4.4 Revoking FloPost's Access to Your YouTube Data
You can revoke our access at any time, by either route:
- In FloPost: disconnect the YouTube channel from the Accounts page. This deletes the stored tokens and stops all further YouTube API calls for that channel.
- At Google: visit the Google security settings page at https://security.google.com/settings/security/permissions and remove FloPost's access. This revokes our tokens at Google, so no further YouTube API request from FloPost can succeed.
Revoking access stops future data collection. The YouTube records covered by the 30-day job in Section 4.3 are then deleted by that job once they are 30 days old, because nothing refreshes them. To delete everything we have stored — including your subscriber-count history and per-video counts — without waiting, submit a deletion request as described in Section 7.
4.5 Data We Send to YouTube
We send content to YouTube only when you act: publishing or scheduling a video, or sending a comment reply (manually, or through an auto-reply rule that you created and enabled). Anything we upload on your behalf is content you supplied to FloPost.
4.6 Limited Use of Information Received from Google APIs
FloPost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data is transmitted over TLS/SSL (HTTPS)
- Server-side token storage: OAuth access tokens are stored in Firebase Firestore, never exposed to the client browser
- Webhook verification: Instagram, Facebook and TikTok webhooks are verified using HMAC-SHA256 signatures
- Authentication: All API endpoints that access user data require Firebase Authentication
- Scheduled task verification: Scheduled post execution endpoints use cryptographic QStash signature verification
- CRON job protection: Background jobs are protected by bearer token authentication
- Security headers: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are enforced on all responses
While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Data Rights
You have the following rights regarding your personal data:
- Access: Get a copy of the personal data we hold about you — download it yourself at any time in the app under Settings > Download my data, or ask us
- Correction: Update or correct inaccurate information
- Deletion: Delete your account and its data yourself in the app, or ask us to (see Section 7)
- Portability: Receive your data in a machine-readable format — Download my data gives you one JSON file
- Withdrawal of Consent: Disconnect any social media account at any time from the Accounts page — this immediately revokes our access to that platform. For Google/YouTube you can also revoke access directly at https://security.google.com/settings/security/permissions.
- Objection: Object to processing of your data for specific purposes
- Restriction: Request that we limit how we process your data
To exercise any of these rights, contact us at support@flopost.ai. We will respond within 30 days.
7. Data Deletion
There are two kinds of deletion, and they reach different amounts of data.
7.1 Delete Your FloPost Account: Everything, at Once
In the app, open Settings and choose Delete my account. FloPost then deletes, at once, everything it stores for your account except the few records listed below: your account and sign-in record, your profile and FloPost handle, the connected accounts you own and their access tokens, your posts, drafts and post history, analytics and follower history, inbox messages and comments, contacts, automation rules and settings, and the files you uploaded. Deleted data is gone from our database and file storage, the database's 7-day undo copy included, within 7 days.
A connected account you own is deleted with your FloPost account, even if teammates use it (if it has a second owner, only your own seat is removed). If you are a member of a connected account someone else owns, only your own seat is removed; the account and its data stay with its owner.
Before you delete, you can choose Download my data in the same place. It gives you one file straight away, in JSON (a machine-readable format), with the data stored for your account, including your contacts on every plan. Access tokens and other secrets are masked, and other people's technical details from link taps (IP address, network and browser) are left out.
If you cannot sign in, email support@flopost.ai with "Data Deletion Request" in the subject line. We delete your FloPost account and its data, as described here, within 7 days of receiving your email.
What we keep after your account is deleted, and why:
- A record that the deletion happened: your FloPost user ID and the email address on the account, and the time it was deleted
- For each Instagram account you owned in FloPost, a one-way fingerprint (a hash) of its Instagram account ID, with the date and how many automated DMs had been used that month — kept to prevent abuse of the free plan, for 365 days. It holds no name, handle or content.
- For each person who asked us to stop replying to their TikTok comments, a one-way fingerprint (a hash) of their TikTok ID and the date they asked — kept so that FloPost never replies to them or stores their comments again. It holds no name, handle or content, and it is not linked to any FloPost account.
- Technical records of which platform events (identified by the platform's own IDs, such as a message or comment ID) FloPost has already processed, so that none is handled twice
- Records of deletion requests (the request's code, status and dates, and the platform's ID for the person who asked or a one-way hash of it), so that a request's status can still be checked
- Billing records: the payment and subscription events Stripe, our payment processor, sent us
- A log of changes FloPost staff made to accounts, such as a plan or role change
7.2 Ask Facebook, Instagram or Threads to Delete Your Data
If you remove FloPost in the settings of Facebook, Instagram or Threads and ask that platform to delete your data, Meta sends us the request and our callback endpoint at /api/data-deletion handles it. A request made at Facebook deletes the Facebook data and the Instagram data connected through Facebook Login; a request made at Instagram or at Threads deletes that platform's data only. Your FloPost account and your other platforms' data stay. When data was deleted, Meta gives you a confirmation code, and you can check its status at flopost.ai/data-deletion.
Disconnecting an account inside FloPost is not a deletion request; what happens to that account's data then is set out in Section 8.
Note: Deleting data from FloPost does not delete content already published to your social media accounts. To manage content on Facebook, Instagram, Threads, TikTok, YouTube, LinkedIn, or X, use those platforms' native tools. To revoke FloPost's access to your accounts, remove the app from each platform's settings — for Google/YouTube, that is https://security.google.com/settings/security/permissions.
8. Data Retention
We retain your personal data only as long as necessary:
- Active accounts: Data is retained while your account remains active and connected
- Disconnected platforms: When you disconnect a social media account, we delete the associated access token and stop fetching new data. Its historical data (posts, analytics, stored comments and messages) is deleted within 7 days of the disconnect for a YouTube channel, and for any other platform once the account has stayed disconnected for 90 days — or sooner, if you delete your FloPost account or ask us to delete it.
- YouTube data: unlike the other platforms, this is not purely event-driven. Our stored copies of your videos' cached metadata and statistics, inbox comments, and commenter identifiers are deleted once they are 30 days old, whether or not you disconnect anything; anything still in use is fetched again by the normal sync. Also deleted once they are 30 days old: the log your auto-reply rules keep of the comments they answered (including each comment's text) — what stays of each answered comment is a one-way fingerprint (a hash) of its ID, with the date and whether the reply was sent, so that FloPost never answers the same comment twice — and your channel profile snapshot, which is saved again the next time you connect the channel or refresh your profile. YouTube Analytics reports are not stored at all. Your connection ends when you disconnect the channel: its stored access and refresh tokens are deleted immediately and we stop fetching new YouTube data. The rest of the YouTube data we stored for that channel, your subscriber-count history included, is deleted within 7 days of the disconnect, except the one-way hashed do-not-contact list and those one-way fingerprints. Your FloPost settings and rules stay in your FloPost account until you delete your FloPost account or ask us to delete your data. See Section 4.3 for the detail.
- Other platforms: Retention for non-YouTube platform data is event-driven: the access token is deleted the moment you disconnect the account, the account's history is deleted once it has stayed disconnected for 90 days (except one-way fingerprints of the comments your auto-reply rules answered, kept so that FloPost never answers the same comment twice), and the data is deleted when you delete your FloPost account or submit a deletion request. TikTok comment data is the exception: it is deleted automatically 30 days after we receive it, and at once when you disconnect TikTok in FloPost.
- Usage counts: FloPost keeps per-user daily usage counts (no content: no comment or message text, no tokens, no handles) for 90 days, then deletes them, and deletes them at once with the account.
- Deleted accounts: All data is permanently deleted within 30 days of a deletion request, except the few records Section 7 lists as kept
- Access tokens: Automatically refreshed before expiration (within 20 days of expiry) to maintain functionality. Expired tokens that cannot be refreshed are flagged.
- Legal requirements: Some data may be retained longer if required by law (e.g., financial records for tax compliance)
9. Children's Privacy
Our Service is not intended for users under 13 years of age (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at support@flopost.ai and we will promptly delete such data.
10. International Data Transfers
FloPost is hosted on Firebase App Hosting (Google Cloud, United States), and our database, authentication, and file storage are Google Cloud services in the United States. Your information may be transferred to and maintained on servers located outside your country of residence, where data protection laws may differ. By using our Service, you consent to this transfer. We ensure appropriate safeguards are in place, including data processing agreements with our service providers.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
To exercise these rights, contact support@flopost.ai.
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland:
- Legal basis: We process your data based on your consent (connecting social media accounts) and contractual necessity (providing the Service)
- Data Protection Officer: Contact support@flopost.ai
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority
- Data transfers: Transfers outside the EEA are protected by standard contractual clauses or other appropriate safeguards
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, the new version is posted on this page with a new date.
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account.
15. Contact Us
For privacy-related questions, concerns, or data requests:
- Privacy Email: support@flopost.ai
- Data Deletion: flopost.ai/data-deletion
- Website: flopost.ai
Platform-Specific Privacy Policies
Your use of connected social media platforms is also subject to their respective privacy policies:
Last updated: September 28, 2026