Privacy Policy
Last updated: 2026-09-15
Postflow is a social media scheduling tool operated by CI Web Group, Inc. (“CI Web Group”, “we”, “us”). It helps
you draft, schedule, and publish content to Facebook Pages, Instagram professional accounts, and LinkedIn
profiles and organization pages. This Privacy Policy explains what data we collect and how we use it.
Data we collect
- Account data: your email address and authentication metadata (via Supabase).
-
Facebook and Instagram data: when you connect Facebook, we store the ID and name of each Page you
grant access to, the linked Instagram professional account ID and username (if any), and the access tokens
needed to publish and read on your behalf.
-
LinkedIn data: when you connect LinkedIn, we store your LinkedIn member ID and display name, the
IDs and names of organization pages you administer, and the access token needed to publish on your behalf.
-
Published post data: the IDs of posts we publish for you, and the engagement and insights data
(such as reactions, comments, shares, impressions, and reach) that you view in the app.
- Content data: captions, media, links, and schedule details you enter in the app.
How we use data
- To authenticate you and keep you signed in.
- To publish, edit, and delete posts on your connected accounts when you ask us to.
- To show you the posts already published on your connected accounts.
- To fetch reporting and insights data from Facebook, Instagram, and LinkedIn that you view in the app.
We use platform data only to provide the Service to you. We do not sell it, use it for advertising, or share it
with third parties except the platforms themselves and the service providers listed below.
Where data is stored
- Authentication is handled by Supabase.
-
Connection tokens and connected account details are stored server-side in our database (Supabase) and a server
cache (Upstash Redis), scoped to your account. Tokens are never exposed to other users.
- Media you upload for scheduled posts is stored on our hosting provider (Vercel) until published.
- Some scheduling history may be stored in your browser (localStorage).
Data retention
We keep connection tokens for as long as an account stays connected. When you disconnect an account, its token is
deleted. Cached post and insights data expires automatically and is refreshed from the platform when you view it.
Your choices
- You can disconnect Facebook, Instagram, or LinkedIn at any time from Settings inside Postflow.
-
You can also revoke Postflow's access from the platform side: in Facebook under Settings → Business Integrations,
or in LinkedIn under Settings → Data privacy → Permitted services.
- You can request deletion of your data. See Data Deletion Instructions.
Contact
Questions about this policy can be sent to CI Web Group, Inc. at
support@ciwebgroup.com.
See also our Terms of Service.