Last updated:
ContentFlow ("ContentFlow", "we", "us") is an AI platform that helps people create, schedule and publish content to social networks, available at https://contentflow.fyi. This Privacy Policy explains what data we collect, why we collect it, how we process and store it, who we share it with, and how you can have it deleted. It is our own policy and applies to the ContentFlow web app, its API, and the ContentFlow MCP server.
We are the controller of the data described here. For any privacy question, including deletion requests, contact us at aitkalirassul@gmail.com.
By creating an account or connecting a social network to ContentFlow, you agree to the processing described in this policy.
Connecting a social network is always optional and always initiated by you. When you connect an account, we receive and store only what is needed to run the features you asked for:
We request the narrowest set of permissions needed for these features. We do not use Meta platform data for advertising, we do not sell it, and we do not transfer it to data brokers or to anyone building independent profiles of you. Our use of data from Meta platforms complies with the Meta Platform Terms and Developer Policies.
We do not use advertising cookies and we do not run third-party ad or social tracking pixels on our site.
We process your data only for the purposes below. Where the GDPR applies, our legal basis is noted in brackets.
We do not use your content or your connected-platform data to make automated decisions with legal or similarly significant effects about you.
To generate content, ContentFlow sends your input, your brand settings, relevant knowledge base excerpts and relevant trend data to our AI provider alem.plus, which performs text generation, speech-to-text transcription, embeddings and reranking. Voice recordings are sent for transcription and are not stored by us after the transcript is produced. Prompts and responses are traced in Langfuse so we can monitor and improve output quality. Style and knowledge embeddings are stored as vectors in our Milvus instance and are linked to your account.
Your content is processed by these providers only to fulfil the requests you make in ContentFlow. We do not sell your content and we do not publish it anywhere other than to the accounts you explicitly instruct us to publish to.
After you request deletion, backups containing your data are overwritten in the normal backup rotation.
No system can be completely secure, but we work to protect your data and will notify you and the competent authority if a breach affecting your personal data occurs, as required by law.
You can have your data deleted at any time, in any of the following ways.
a) Delete specific items yourself. Sign in and delete individual posts, knowledge base entries or uploaded media from the app. Deleted items are removed from our database.
b) Disconnect a platform. In Settings, click "Disconnect" next to Instagram, Threads or Telegram. The stored access token, platform user ID and username for that integration are deleted from our database immediately, and we stop requesting any data from that platform.
c) Remove ContentFlow from Instagram or Facebook. Open Instagram → Settings → Website permissions → Apps and websites (or Facebook → Settings & privacy → Settings → Apps and websites), and remove ContentFlow. Meta notifies our deauthorization endpoint and we delete the Instagram or Threads data we hold for you.
d) Delete your entire account and all associated data. Send an email to aitkalirassul@gmail.com from the address registered with your account, with the subject "Data deletion request". We will verify the request, delete your account, generated content, knowledge base, uploaded media, style vectors and all stored platform tokens, and confirm by email. We complete deletion within 30 days of receiving the request.
e) Meta-initiated data deletion requests. If you submit a data deletion request through Instagram or Facebook, Meta sends a signed request to our data deletion callback — https://contentflow.fyi/api/auth/instagram/data-deletion for Instagram and https://contentflow.fyi/api/auth/threads/data-deletion for Threads. We delete the Meta data associated with your account and return a confirmation code together with a status URL of the form https://contentflow.fyi/api/auth/instagram/data-deletion/status?code=CONFIRMATION_CODE, which you can open at any time to check the status of that request.
Deletion is permanent: once your data is deleted, we cannot restore it.
Depending on where you live, you have the following rights over your personal data:
To exercise any of these rights, email aitkalirassul@gmail.com. We respond within 30 days.
ContentFlow is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
ContentFlow is operated from Kazakhstan and hosted in Europe. Some of the providers listed in section 7 process data in other countries. When we transfer personal data across borders, we rely on appropriate safeguards, such as the standard contractual clauses offered by those providers.
We may update this policy as the service changes. The "last updated" date at the top always reflects the current version, and this page remains publicly accessible at https://contentflow.fyi/privacy. If we make a material change, we will notify you in the app or by email before it takes effect.
For any question about this policy, about the data we hold, or to request deletion, email aitkalirassul@gmail.com. We aim to reply within 5 business days and in any case within 30 days.