Privacy Policy
Effective Date: June 1, 2026 (Policy Version: v1.0-2026-06). At Flowzens, your privacy is not a feature — it's a foundation.
AES-256 Encryption
All OAuth access tokens for connected social accounts are encrypted at rest before storage using AES-256 cryptography.
No Data Sales — Ever
We never sell, rent, or trade your personal information, brand data, content drafts, or analytics to any third party.
Full User Control
Disconnect any social account or request complete account deletion at any time. We execute deletion within 7 business days.
1. Information We Collect
We collect information necessary to deliver, improve, and personalize the Flowzens experience:
- Account Credentials: Name, email address, bcrypt-hashed password, phone number (optional), and profile image.
- Legal Consent: Date, time, IP address, and policy version at the moment you accepted our Terms and Conditions — stored for compliance audit purposes.
- Company Profile Data: Brand name, industry, target demographics, tone of voice settings, and brand guidelines used to generate platform-specific content.
- Connected Social Accounts: Platform usernames, profile picture URLs, and AES-256 encrypted OAuth access/refresh tokens for LinkedIn, Facebook, Instagram, X, and YouTube.
- Content Metadata: Post captions, image generation prompts, scheduled publish dates, approval status, and performance analytics per post.
- Usage Data: Pages visited, feature usage frequency, session duration, and device/browser metadata — used solely for platform improvement.
2. Token Security & Social Integrations
To auto-publish on your behalf, we securely connect to platform APIs using the following safeguards:
- AES-256 Token Encryption: Platform OAuth tokens are encrypted before storage. The encryption key is stored separately from the database, following defense-in-depth principles.
- OAuth 2.0 PKCE: We use official, minimal-scope OAuth flows (LinkedIn Member Social, Meta Graph API, Twitter PKCE, YouTube upload scope). We never request more permissions than necessary.
- Token Revocability: Disconnecting a social account in your Settings permanently deletes all stored tokens from our database. We also revoke the token at the platform level where APIs support it.
3. How We Process Your Data
- AI Content Generation: Your prompts and company tone profiles are processed by LLM APIs (Anthropic Claude and Google Gemini). These APIs are configured to not use your inputs to train public base models.
- Image Generation: Image prompts are sent to Replicate/Stable Diffusion APIs. Generated images are temporarily stored in our CDN and are not used for any model training.
- Payments: All payment data is processed by Cashfree. Flowzens never stores raw card numbers, CVVs, or bank account details.
- Email Notifications: We send system notifications (email verification, post approval alerts, billing receipts) via SMTP. You can manage notification preferences in your account settings.
4. Data Retention
- Active Accounts: Your data is retained for the duration of your account subscription plus 90 days after account closure for audit and dispute resolution purposes.
- Deleted Accounts: Upon account deletion, all personally identifiable data is purged from our primary database within 7 business days. Anonymized, aggregated analytics data may be retained for product improvement.
- Legal Obligations: We may retain certain records (e.g. billing history, consent logs) for up to 7 years as required by Indian tax and financial regulations.
5. Cookies & Tracking
Flowzens uses a minimal set of cookies strictly necessary for platform operation:
- Session Cookies: JWT-based session tokens (HttpOnly, Secure, SameSite=Lax) used to authenticate your session. These are cleared on logout.
- Preference Cookies: Light/dark theme preference stored in localStorage — never transmitted to our servers.
- Analytics: We do not use Google Analytics or Facebook Pixel. Any analytics are first-party only and do not track you across other websites.
6. Your Rights (GDPR / DPDP)
Under the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act (DPDP Act 2023), you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or outdated personal information.
- Right to Erasure: Request deletion of your account and all associated data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Withdraw Consent: Withdraw your consent for data processing at any time by deleting your account.
To exercise any of these rights, email info@flowzens.com with the subject line "Privacy Request — [Your Right]." We will respond within 30 days.
7. Contact Our Privacy Team
For privacy inquiries, data requests, or concerns about how we handle your information:

