Privacy Policy

Last updated: June 12, 2026

This Privacy Policy explains how Upflow (the “Service”) collects, uses, stores, and protects information when you connect your social-media accounts to generate and publish content. We collect only what is needed to operate the Service and we never sell your data.

1. Information we collect

When you connect an account through a platform’s official OAuth flow, we receive and store, on our own server:

  • TikTok: your account identifier (open_id), display name, and follower count, plus the OAuth access and refresh tokens needed to publish on your behalf. We request these scopes: user.info.basic, video.upload, and video.publish.
  • Facebook / Instagram: Page / Business account IDs, names, follower counts, and the Page access tokens required to publish.
  • Content you create: the scripts, images, and videos you generate and approve within the Service.

We do not collect your platform password, payment information, or your personal browsing activity. We only access the data covered by the scopes you explicitly authorize.

2. How we use information

  • To publish the videos you create and approve to the accounts you have connected.
  • To display your connected accounts (name, follower count) so you can manage where content is posted.
  • To operate, maintain, and secure the Service.

We use your TikTok data only to provide the content-publishing feature you requested. We do not use it for advertising, profiling, or any purpose unrelated to the Service.

3. How we store and protect data

Access tokens and account data are stored server-side in a private database and are never exposed to the browser or returned in API responses. The Service runs in a private, access-controlled deployment. Tokens are transmitted only to the respective platform’s official API over HTTPS.

4. Data sharing

We do not sell, rent, or share your personal data with third parties. The only external transmission of your data is to the official APIs of the platforms you connect (e.g., TikTok, Facebook), and solely to perform actions you initiate, such as publishing a video.

5. Data retention & deletion

We retain your tokens and account data only while your account remains connected. You can remove your data at any time by:

  • Disconnecting the account inside Upflow, which deletes the stored tokens and account record; or
  • Revoking Upflow’s access from the platform directly — for TikTok: Settings → Security & permissions → Manage app permissions; or
  • Emailing us at warotwinwin@gmail.com to request deletion of all data associated with your account.

Upon disconnection or a deletion request, the associated tokens and account data are deleted from our database.

6. Third-party platforms

Your use of connected platforms is also governed by their own privacy policies, including the TikTok Privacy Policy. We encourage you to review them.

7. Children’s privacy

The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect data from them.

8. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date above reflects the latest version.

9. Contact

For privacy questions or data-deletion requests, contact us at warotwinwin@gmail.com.

See also our Terms of Service.