Flowtus is a white-label social media management platform for agencies, operated by [Legal entity name], [jurisdiction] (“Flowtus”, “we”, “us”). For any privacy question or request, contact us at privacy@flowtus.io.
Privacy Policy
Last updated: July 19, 2026
This is a template pending final legal review. It describes our intended practices; the finalized version will replace it before general availability.
This Privacy Policy explains what personal data Flowtus collects, how we use and store it, who we share it with, and the choices and rights you have — including how to delete your data.
Who we are
Data we collect
Account data: your name, email, agency/organization details, and team members you invite.
Connected social account data: when you connect a Facebook, Instagram, or LinkedIn account, we receive access tokens and the profile, page, and content data needed to publish and report on your behalf. OAuth access tokens are encrypted at rest using AES-256-GCM.
Content you create: posts, captions, media you upload, approval decisions, and support tickets.
Billing data: subscription plan and payment status. Card and bank details are handled by our payment processors (PayHere and Paddle) and are never stored on our servers.
Usage and technical data: log data, IP address, device/session information, and cookies strictly necessary to keep you signed in.
How we use your data
To provide the service: scheduling and publishing posts, running approval workflows, syncing analytics, and sending transactional email.
To secure your account: enforcing one active session per seat and detecting abuse.
To operate our business: billing, support, and improving the product.
We do not sell your personal data, and we do not use the content of your connected accounts for advertising.
How we store and protect it
Data is stored on managed infrastructure in the Singapore region. OAuth tokens are encrypted at rest (AES-256-GCM); traffic is encrypted in transit (TLS).
Media uploaded for a post is stored only as long as needed to deliver that post and is automatically deleted after delivery.
Access is scoped per organization (tenant isolation) so one agency's data is never visible to another.
Sharing with third parties
We share data only with service providers that help us run Flowtus, under contract: hosting and database, Redis cache, object storage (Cloudflare R2), email (Resend), error monitoring (Sentry), and payments (PayHere, Paddle).
We share data with the social platforms you connect (Meta, LinkedIn) strictly to perform the actions you request via their APIs.
We may disclose data if required by law.
Data retention and deletion
You can disconnect any social account at any time from within the app, which revokes and deletes the stored tokens for that account.
You can request deletion of your account and associated personal data by emailing privacy@flowtus.io or through your account settings. We will delete or anonymize your personal data within 30 days, except where we must retain limited records to meet legal, tax, or audit obligations.
To remove Flowtus's access to your Meta (Facebook/Instagram) data, you can also remove the app from your Facebook settings under Settings & Privacy → Settings → Apps and Websites.
Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact privacy@flowtus.io.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here with an updated effective date.