Privacy Policy
Last updated: September 19, 2026
BrendFlow (“BrendFlow”, “we”, “us”) is a social media management tool that lets a business connect its own social media accounts, draft and schedule posts, and see how those posts perform. This policy explains what data we collect to do that, why, and how it is handled. BrendFlow is operated as an independent product without a registered corporate entity at this time; the contact below reaches the person responsible for it.
Information we collect
When you create an account and use BrendFlow, we collect:
- Account information — your name, email address, and a securely hashed password. We never store your password in plain text.
- Workspace information — your company or workspace name, team members you invite, and their roles.
- Connected social accounts — when you connect a Facebook Page or Instagram account, we receive and store an access token for that account, its name, and its profile picture. Access tokens are encrypted at rest (AES-256-GCM) and are only ever decrypted in memory to make an API call on your behalf.
- Content you create — post captions, uploaded images and videos, campaigns, and schedules. Uploaded media is stored with Cloudflare R2.
- Performance data about your own accounts — when you view analytics, BrendFlow requests engagement figures (likes, comments, shares) and follower counts and demographics for the accounts you connected, directly from the Meta Graph API. We do not collect this data for accounts you have not connected, and we do not collect data about other people’s accounts.
- Cookies — a session cookie that keeps you signed in, and a preference cookie that remembers your chosen language. Neither is used for advertising or cross-site tracking.
How we use your information
We use the data above only to operate the product:
- To publish, schedule, and manage posts on the social accounts you connect.
- To show you analytics about your own connected accounts.
- To let you and your invited teammates sign in and collaborate on a shared workspace.
- To enforce the limits of the plan your workspace is subscribed to.
AI features
If you use the AI caption or image assistant, the caption text you are drafting, or the image attached to your post, is sent to Anthropic’s API to generate suggested text, and a text prompt is sent to OpenAI’s API to generate an image if you ask for one. These providers process that request under their own privacy terms; we do not send them your account credentials, access tokens, or other workspace data beyond what is needed for that single request.
Sharing your information
We do not sell your data. We share it only with the service providers that make BrendFlow work — Meta (to publish and read your connected accounts’ data), Cloudflare (to store your media), Anthropic and OpenAI (for the optional AI features above), and our hosting provider — and only to the extent each needs to perform its function.
Data retention and deletion
We keep your data for as long as your workspace is active. If you disconnect a social account, its access token is deleted immediately. See our Data Deletion page for how to request removal of your account and its data entirely.
Your rights
You can review, correct, or delete your account information at any time from within the app, or by contacting us. You can disconnect any social account whenever you choose from the Platforms page.
Contact
Questions about this policy, or a request concerning your data, can be sent to info@brendflow.com.