Privacy Policy
How SocialFlow collects, uses, shares and deletes information — including data we access from Meta on your behalf.
Last updated Aug 28, 2026
1. Who we are
SocialFlow is a social media management service operated by Md Imran Hossain, 142/1 Prantika Abashik, Khulna, Bangladesh (“we”, “us”). We are the data controller for the information described in this policy.
The service lets you connect your social media accounts, create and schedule content, handle messages and comments in one inbox, keep records of the people who contact you, and measure how your content performed.
2. Information we collect
Information you give us
- Account details — your name, email address, password hash, and the workspace and team members you create.
- Content you create — posts, captions, drafts, schedules, templates, brand voice settings, and any images or video you upload to the media library.
- Customer records — names, contact details, tags and notes you choose to store about the people who contact your business.
- Billing information — handled by our payment processor. We store only the plan, the billing status, and the last four digits and expiry of the card.
Information from connected social accounts
When you connect an account, the platform asks you to approve specific permissions. We only ever receive what you approve, and only for the accounts you choose. From Meta (Facebook and Instagram) we access:
| Permission | Why we need it |
|---|---|
pages_show_list | To list the Pages you can connect. |
pages_read_engagement | To read Page content and engagement for your analytics. |
pages_manage_posts | To publish and schedule the posts you create. |
pages_manage_engagement | To read and reply to comments in your unified inbox. |
pages_manage_metadata | To receive webhooks when new activity arrives. |
pages_messaging | To read and reply to Page messages in your inbox. |
read_insights | To read reach, impressions and follower metrics. |
instagram_basic | To identify the Instagram professional account you connect. |
instagram_content_publish | To publish the posts you schedule to Instagram. |
instagram_manage_comments | To read and reply to Instagram comments. |
instagram_manage_insights | To read Instagram performance metrics. |
instagram_manage_messages | To read and reply to Instagram direct messages. |
In practice this means we receive: your Page and Instagram professional account profiles and follower counts; the posts published through or synced into SocialFlow; the messages, comments and mentions your accounts receive, along with the profile name and identifier of the person who sent them; and aggregate performance metrics such as reach, impressions and engagement.
Information we collect automatically
- Log data — IP address, browser and device type, pages viewed, and timestamps.
- Session cookies that keep you signed in. We do not use advertising or cross-site tracking cookies.
3. How we use information
- To provide the service — publishing what you schedule, delivering your messages, showing your analytics.
- To generate AI assistance when you ask for it — captions, rewrites, hashtag and reply suggestions.
- To keep the service secure, prevent abuse, and debug faults.
- To bill you, and to send service notices about your account.
We do not sell your data. We do not use the content of your messages or your audience’s data for advertising. We do not use Meta Platform Data to build profiles of people who are not your customers.
AI processing
When you use an AI feature, the relevant text — the draft you are writing, or the conversation you asked for a reply to — is sent to our model provider to generate the response. Our provider processes it only to return that response and does not use it to train their models. AI never publishes or sends anything on its own: every generated caption or reply is a suggestion that a person has to accept.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to deliver the service you signed up for.
- Legitimate interests — to secure the service, prevent abuse and improve reliability.
- Consent — for each social account connection, which you can withdraw at any time by disconnecting the account.
- Legal obligation — for tax and accounting records.
5. Who we share it with
We share information only with the service providers needed to run SocialFlow:
- Cloud hosting and database providers, which store your workspace data.
- Our AI model provider, for the generation requests described above.
- Our payment processor, for billing.
- The social platforms themselves, when we publish or reply on your behalf at your instruction.
Each is bound by contract to process data only on our instructions. We also disclose information where the law requires it, or to protect our rights and the safety of our users.
6. How long we keep it
- Workspace content — posts, media, customers and conversations — for as long as your account is open.
- Access tokens — until you disconnect the account or the token expires, whichever comes first. Disconnecting deletes the token immediately.
- After you close your account — deleted within 30 days, except records we must keep for tax or legal reasons.
- Backups — purged on a rolling 35-day cycle.
7. Your rights
You can access, correct, export or delete your data, object to processing, or ask us to restrict it. Most of this you can do yourself in the app; for the rest, write to us at imraniugp@gmail.com and we will respond within 30 days.
To delete data we hold from a Meta connection, see the data deletion instructions. You can also remove SocialFlow from your Facebook settings at any time, which revokes our access immediately.
If you are in the EU or UK, you have the right to complain to your local data protection authority.
8. Security
- All traffic is encrypted in transit with TLS, and data is encrypted at rest.
- Access tokens are stored encrypted and are never exposed to the browser.
- Access to production data is limited to staff who need it and is logged.
- Role-based permissions inside your workspace limit what each team member can see and do.
9. International transfers
Our providers may process data outside your country. Where data leaves the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses.
10. Children
SocialFlow is a business tool and is not directed at anyone under 16. We do not knowingly collect their data; if we learn we have, we delete it.
11. Platform compliance
Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including their restrictions on use and transfer. The same applies to every other platform we integrate with.
12. Changes
We will post any changes on this page and update the date above. If a change materially affects how we handle your data, we will email you before it takes effect.
13. Contact us
Md Imran Hossain
142/1 Prantika Abashik, Khulna, Bangladesh
imraniugp@gmail.com
Policy URL: https://social.geniusflow.net/privacy