Privacy Policy

Effective: 4 October 2026

This Privacy Policy explains what personal data Flowtus collects, how we use and store it, who we share it with, how long we keep it, and the choices and rights you have — including exactly how to delete it.

Who we are

Flowtus is a white-label social media management platform for agencies, operated by Tusk Digital Limited (NZBN 9429053826398), a company registered in New Zealand (“Flowtus”, “we”, “us”). Tusk Digital Limited is the data controller for the account and usage data described in this policy. For any privacy question or request, contact privacy@flowtus.io.

Flowtus is used by agencies who invite their own team members and manage content for their own clients. Where an agency uses Flowtus to process personal data about its clients, that agency is the controller and we act as its processor.

Data we collect

Account data: your name, email address, agency details, role, and the team members you invite.

Connected social accounts: when you connect an account we receive an access token and the profile, page and content data needed to publish and report on your behalf. Tokens are encrypted at rest with AES-256-GCM. Supported platforms are Facebook, Instagram, LinkedIn, Threads, Google Business Profile, YouTube, Bluesky, Mastodon, Slack, Discord and Telegram.

Connected file stores: if you connect Dropbox, Google Drive, OneDrive, SharePoint or Box to import media, we store an OAuth token for YOUR account, encrypted at rest, and use it only to list and download files you choose. These connections are per-person — nobody else at your agency, including an owner or administrator, can browse or import through your connection or see what is in it. We request read-only access and never write back.

Content you create: posts, captions, scheduled times, media you upload or import, approval decisions, support tickets and comments.

AI inputs and outputs — see “AI features” below.

AI usage metering: for each AI request we record who made it, which feature, the model used, the token counts and the computed cost. This is what enforces your plan's AI allowance and populates the usage figures on your settings page.

Short link analytics: links shortened through Flowtus record a total click count and the time of the most recent click. We do not record who clicked, their IP address, or anything about their device.

Billing data: your plan, subscription status and invoices. Card and bank details are handled entirely by our payment processors and never reach our servers.

Technical data: log data, IP address, a device/session fingerprint, and cookies strictly necessary to keep you signed in.

AI features, and whose account they run on

Flowtus offers AI caption, hashtag and content suggestions. When you use one, the text you supply is sent to Anthropic's API for processing and the generated text is returned to you. Where you started from a curated RSS item, that item's title is part of the text sent.

Unless your agency has supplied its own Anthropic API key, these requests are made on FLOWTUS'S OWN API KEY. We are therefore the party sending your content to Anthropic, under our commercial agreement with them rather than yours. We state that plainly rather than describing AI as something that simply happens.

We send only the text you provide to the feature. We do not send your connected accounts' data, your team's personal details, or your billing information. We do not use your content to train AI models.

AI features are optional. If you never use them, nothing of yours is sent to Anthropic.

How we use your data

To provide the service: scheduling and publishing posts, running approval workflows, importing media, syncing analytics, and sending transactional email.

To secure your account: enforcing one active session per seat, detecting abuse, and keeping an audit record of significant actions.

To operate our business: billing, metering AI usage against your plan, support, and improving the product.

We do not sell your personal data, and we do not use the content of your connected accounts for advertising.

How we store and protect it

Application, database and cache are hosted in the Singapore region; object storage and our front-end are served globally. Every provider is named under “Subprocessors” below.

OAuth access tokens — for both social accounts and file stores — are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit with TLS. Passwords are hashed and are neither stored in the clear nor recoverable.

Every record is scoped to one organization, and that isolation is verified by automated tests against a real database rather than by convention.

Subprocessors

We share data only with the providers below, each under contract and only as needed to run Flowtus:

Fly.io — Application and background-worker hosting (Singapore).

Neon — PostgreSQL database, including point-in-time recovery (Singapore).

Upstash — Redis — sessions, rate limits and job queues (Singapore).

Cloudflare — R2 object storage for media and backups; CDN and WAF (Global).

Vercel — Web app and marketing site hosting (Global).

Anthropic — AI caption, hashtag and content suggestions (United States).

Resend — Transactional email (United States / EU).

Sentry — Error monitoring (United States).

PayHere — Payments in LKR (Sri Lanka).

Paddle — International payments, merchant of record (United Kingdom / EU).

We also share data with the platforms and file stores YOU connect, strictly to carry out the actions you ask for through their APIs.

We may disclose data where required by law.

Google and YouTube

Flowtus uses YouTube API Services to let you connect a YouTube channel and publish videos to it. By connecting a YouTube channel you also agree to the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.

When you connect a channel we ask Google for permission to upload videos to your channel (youtube.upload) and to view your channel and video information (youtube.readonly). We use these only to: list the channels on your Google account so you can choose one; publish the videos, titles and descriptions you schedule in Flowtus; and read the view, like and comment counts of videos published through Flowtus so we can show you performance. Videos published through Flowtus are uploaded as public. We do not read your subscribers, your watch history, the text of comments, or videos you did not publish through Flowtus.

We store the OAuth tokens Google issues (encrypted at rest with AES-256-GCM), the channel’s ID, name and thumbnail, and the aggregate performance counts of videos published through Flowtus. Those counts are refreshed every four hours, kept for up to 400 days, and deleted when your organization is deleted. Disconnecting a channel ends our access and stops the refresh, but does not by itself erase counts already recorded for videos you published. YouTube data is never sold, never used for advertising, and never used to train AI models. It is shared only with the subprocessors listed above as needed to run Flowtus, and never with other third parties.

If you connect Google Drive to import media, we request access only to the specific files you pick (drive.file) and your account email so Settings can show which Google account is connected. We never request access to your whole Drive.

You can revoke Flowtus’s access at any time by disconnecting the channel in Flowtus — which asks Google to revoke the grant immediately — or directly in your Google Account permissions.

Flowtus’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep things

Media attached to posts is kept until no active post needs it AND your organization's retention window has passed — 30 days by default. It is not deleted the moment a post publishes: agencies re-use and re-check recent creative, and an asset that vanished at publication would break that. The window is set per organization and can be zero (reclaim as soon as nothing references it) or never.

Media you save to your library is kept for as long as you keep it there, whatever the retention window says. Library storage is bounded by your plan's storage quota rather than by time.

Audit records — who did what, and when — are kept for the life of your organization and for 12 months after it is deleted, so that security and fraud questions arising after the fact can still be answered. They hold the action, the actor and the timestamp. They do not hold your posts, media or messages.

Everything else is deleted with your account or your organization, as described below.

Backups

We keep continuous point-in-time recovery on our database and take an encrypted nightly snapshot into private object storage. Backups are what let us recover from a bad deploy, a hardware failure, or an accidental deletion.

This means deleted data does not vanish from every copy the instant you delete it. It remains in backups until they age out, which happens within 30 days on a rolling schedule. Backups exist only for disaster recovery: they are not searchable in the ordinary course of business, and we do not restore individual records from them to reverse a deletion.

We say this rather than implying that a deletion unwrites history, because it does not — and a provider claiming otherwise either has no backups or is not being straight with you.

Deleting a connected account

In Flowtus, go to Accounts, find the account and choose Disconnect. The connection is marked revoked and Flowtus immediately stops publishing to or reading from that account.

For YouTube, disconnecting also asks Google to revoke Flowtus’s authorisation straight away and erases our stored copy of your tokens. For other platforms, our stored copy of the token is erased when your organization is deleted — or sooner for Facebook and Instagram, if you remove Flowtus from Facebook as described below — and the authorisation may remain listed in that platform’s connected-apps settings until you remove it there: for Google Business Profile at Google Account permissions, for Facebook and Instagram under Settings & privacy → Settings → Apps and Websites.

For a file store, go to Settings → Import sources and choose Disconnect. The token is deleted immediately. Files you already imported stay in Flowtus: they were copied at import time and no longer depend on the original.

For Facebook and Instagram you can also remove Flowtus from Facebook itself, under Settings & privacy → Settings → Apps and Websites. Facebook notifies us and we erase the stored tokens for everything that person authorized. Our data deletion page describes this in full.

Deleting your own account

Any team member other than the owner can delete their own account. We remove your name, email address, avatar, password and two-factor credentials, sign you out everywhere, and free your seat.

Work you did — posts you scheduled, approvals you gave, tickets you opened — stays with the agency, attributed to a deleted user. It is the agency's record of its own operations, and removing it would leave them unable to answer who did what.

An owner cannot delete only their own account, because an organization with no owner has nobody who can manage billing or delete it. Transfer ownership first, or delete the whole organization.

Deleting your whole organization

An owner can delete the organization from Settings. We ask you to type the organization's name and re-enter your password: the first proves you know which organization you are deleting, the second proves it is you.

Deletion is scheduled 7 days out. From the moment it is requested the organization is inaccessible — everyone is signed out and nobody can sign back in — but nothing is erased during those 7 days.

We email the owner a single-use link that cancels it. That link is the only way back, precisely because nobody can sign in to cancel from inside the product.

After 7 days we permanently delete your users and sessions, clients and workspaces, posts and their scheduling, media objects in storage, evergreen library, short links, AI usage records, connected-account tokens, notifications and invitations. Deleting a token removes our copy of it; where a platform still lists Flowtus as an authorised app, remove it there as described above.

What survives, and for how long: audit records for 12 months as described above; the record that a Meta deletion request was made, because Meta requires its confirmation-code status page to keep answering; and copies in backups until they age out within 30 days.

If you would rather we did it, email privacy@flowtus.io and we will.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. The deletion routes above are available to you directly and take effect without asking us.

For anything else — access, correction, export, or a complaint — contact privacy@flowtus.io. We respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority.

If you use Flowtus as a member of an agency's team, some requests can only be acted on by that agency, because they control the data. We will say which and put you in touch.

Children

Flowtus is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy. Material changes are posted here with a new effective date, and we tell account owners by email before they take effect.