Privacy Policy
Effective Date: October 01, 2026
•
Last Revised: October 01, 2026
•
Service: https://post.amanaflow.com
At PostFlow ("Amana Flow," "we," "us," or "our"), accessible via https://post.amanaflow.com, we are committed to upholding the highest standards of user privacy, digital transparency, and data security. This comprehensive Privacy Policy describes how our self-hosted social media management platform collects, uses, encrypts, and deletes information when you interact with our services, connected social channels, and APIs.
1. Overview & Self-Hosted Architecture
PostFlow is deployed as an enterprise, self-hosted social orchestration service on our private Virtual Private Server (VPS) infrastructure. Unlike multi-tenant third-party SaaS tools that aggregate and monetize user metrics, your authentication credentials, media assets, and scheduling histories are stored in our private, isolated PostgreSQL 17 database and local volumes.
We do not sell, rent, lease, trade, or monetize your personal data or social media tokens with third-party data brokers, ad networks, or external commercial entities under any circumstances.
2. Categories of Information We Collect
Depending on your interaction with the Platform, we collect and process the following categories of information:
- Account Credentials: Name, administrative email address, encrypted password hash, and team role permissions used to authenticate your login sessions.
- OAuth Access & Refresh Tokens: Standard authorization tokens issued by third-party social media networks (e.g., TikTok, Meta, YouTube, LinkedIn) upon your explicit authorization to enable automated scheduling.
- Social Channel Identifiers: Public channel IDs, usernames, profile handles, and channel avatar URLs necessary to display your connected accounts in the visual calendar interface.
- Post Content & Media Files: Post captions, copy text, hashtags, scheduled publish timestamps, images, graphics, and video files uploaded to our private storage to fulfill publishing requests.
- Analytics & Metric Logs: Aggregated post engagement data (impressions, video views, likes, shares, comments) retrieved via official APIs to display performance reports in your dashboard.
- Technical Diagnostic Logs: IP address, user agent, browser type, and Temporal workflow transaction IDs collected to maintain server stability, prevent cyber threats, and verify webhook delivery.
3. Specific Platform API Compliance Disclosures
Our platform interfaces directly with major social media APIs. We strictly comply with the specific developer policies, user data guidelines, and limited use principles set forth by each respective provider:
TikTok Developer API & Login Kit
TikTok Content Posting API Compliance
When you connect a TikTok creator or business account via the TikTok Login Kit, our application requests the following granular permissions:
user.info.basic: Read basic profile information (display name, avatar, open_id) strictly to display the account in your workspace.
video.publish & video.upload: Upload and publish approved video files and captions directly to your TikTok account at your designated schedule.
Data Retention: Staging video files are deleted immediately after successful upload. TikTok access tokens are encrypted and retained only while the account remains actively connected. You may review our explicit TikTok User Data Deletion Instructions or revoke permissions anytime in TikTok Settings → Security & permissions → Apps and services.
Google & YouTube Data API
Google API Services User Data Policy Compliance
Amana Flow Postiz's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request scopes required to publish videos and manage scheduled posts (e.g., YouTube Data API v3 and Google Business Profile).
- We do not transfer or disclose Google user data to third parties unless necessary to provide the service or comply with applicable law.
- We do not use Google user data for serving advertisements, and we do not permit humans to read your private data unless you give explicit consent or for security investigations.
By connecting a YouTube channel, you also agree to be bound by the YouTube Terms of Service and the Google Privacy Policy. You can revoke access at any time via Google Security Permissions.
Meta Developer Platform (Facebook & Instagram)
Meta Platform Terms & Developer Policies
Our integration uses the official Meta Graph API to interact with Facebook Pages and Instagram Business Accounts:
- We access only pages, feeds, reels, and media objects for accounts you have explicitly authorized.
- We process webhook events to update post status in real time and handle automated data deletion callbacks via our secure endpoint.
- You can revoke access and delete associated data at any time via your Facebook Settings → Settings & Privacy → Business Integrations.
LinkedIn Marketing Developer Platform
LinkedIn Member Data Protection
Connections to LinkedIn use OAuth 2.0 to distribute corporate updates and articles to designated company pages and member feeds. Stored tokens are refreshed using encrypted bearer credentials and are strictly limited to authorized publishing tasks.
4. How We Use and Process Information
All collected data is processed strictly for legitimate operational purposes:
- Facilitating scheduled multi-platform social media publishing via official partner APIs.
- Visual calendar rendering and drag-and-drop campaign reorganization.
- Generating engagement analytics and performance reports for your team.
- Enabling AI copilot capabilities (drafting captions, generating suggested hashtags, optimizing hooks) when prompted by you.
- Monitoring server health, preventing rate-limit violations, and ensuring 99.9% uptime.
5. Data Security, Storage & Encryption
We implement enterprise-grade technical and organizational safeguards to protect your information:
- Encryption in Transit: All communications between your browser, our servers, and third-party APIs are encrypted with TLS 1.3 / HTTPS.
- Encryption at Rest: OAuth tokens and sensitive configuration parameters are stored encrypted in our PostgreSQL database.
- Isolated Architecture: Services run inside containerized Docker environments with strict network segregation.
- Access Control: Administrative access is restricted via SSH key authentication and multi-factor security policies.
6. Data Retention and Erasure (Data Subject Rights)
We retain your personal data and social tokens only for the duration necessary to deliver the scheduling service or until you request its deletion:
- Instant Self-Service Disconnection: You can disconnect any social media channel at any time from your dashboard under Settings → Integrations. Disconnecting a channel immediately wipes the associated tokens from our active database.
- Complete Data Erasure: To request complete account termination and permanent purging of all associated media, logs, and user records, visit our User Data Deletion Instructions or submit a written request to privacy@amanaflow.com. All records are purged within 48 hours of confirmation.
7. Global Privacy Regulations (GDPR & CCPA/CPRA)
Regardless of your geographic location, we extend full data subject rights in alignment with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):
- Right to Access: You may request an export of all personal data held about you.
- Right to Rectification: You may update inaccurate personal information directly within your profile.
- Right to Erasure ("Right to be Forgotten"): You may request complete deletion of your account and tokens.
- Right to Restriction & Object: You can disconnect any individual social integration without closing your account.
8. Contact Information & Data Protection Officer