Account data: your name, email address, agency details, role, and the team members you invite.
Connected social accounts: when you connect an account we receive an access token and the profile, page and content data needed to publish and report on your behalf. Tokens are encrypted at rest with AES-256-GCM. Supported platforms are Facebook, Instagram, LinkedIn, Threads, Google Business Profile, YouTube, Bluesky, Mastodon, Slack, Discord and Telegram.
Connected file stores: if you connect Dropbox, Google Drive, OneDrive, SharePoint or Box to import media, we store an OAuth token for YOUR account, encrypted at rest, and use it only to list and download files you choose. These connections are per-person — nobody else at your agency, including an owner or administrator, can browse or import through your connection or see what is in it. We request read-only access and never write back.
Content you create: posts, captions, scheduled times, media you upload or import, approval decisions, support tickets and comments.
AI inputs and outputs — see “AI features” below.
AI usage metering: for each AI request we record who made it, which feature, the model used, the token counts and the computed cost. This is what enforces your plan's AI allowance and populates the usage figures on your settings page.
Short link analytics: links shortened through Flowtus record a total click count and the time of the most recent click. We do not record who clicked, their IP address, or anything about their device.
Billing data: your plan, subscription status and invoices. Card and bank details are handled entirely by our payment processors and never reach our servers.
Technical data: log data, IP address, a device/session fingerprint, and cookies strictly necessary to keep you signed in.