Enterprise Compliance • Privacy Policy Version 3.0
CreatorFlow Privacy Policy
Comprehensive disclosure of data collection, processing, storage, security, retention, deletion, and strict adherence to Google OAuth, YouTube API Services, Meta / Instagram Graph API, X (Twitter) Developer Policy, and LinkedIn Developer Terms.
Operating Entity & Official Contacts
Legal Operator: CreatorFlow Inc.
Brand Name: CreatorFlow
Platform URL: https://creatorflow.cfd
Registered Address: 548 Market Street, Suite 94000, San Francisco, CA 94104, United States
Google API Services User Data Policy & Limited Use Commitment
CreatorFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements:
- No Sale of Google User Data: CreatorFlow never sells, rents, leases, or monetizes Google user data with data brokers, advertisers, or third parties.
- No Advertising Use: Google user data is never used for personalized, retargeted, behavioral, or interest-based advertising.
- No AI Model Training: Google user data is strictly separated and is NEVER used to train, retrain, fine-tune, or improve generalized, foundational, frontier, or public artificial intelligence (AI) or machine learning (ML) models.
- Permitted Transfers Only: Transfers of Google user data occur solely to provide or improve requested user-facing features, maintain security, or comply with applicable law.
- Restricted Human Review: Unauthorized human review of Google user data is strictly prohibited. Human access is permitted only with user consent, for critical security or bug investigations, or lawful compliance.
YouTube API Services Notice
CreatorFlow uses the YouTube API Services to allow creators to schedule, publish, manage, and analyze YouTube video content. By connecting your YouTube account or using YouTube features in CreatorFlow, you agree to be bound by:
You can revoke CreatorFlow's access to your YouTube data at any time via the Google Security Settings Page. See Section 6 below for complete YouTube API data handling, storage, and deletion procedures.
Meta Platform (Instagram & Facebook) Data Compliance
CreatorFlow integrates with the Meta Graph API and Instagram Graph API in full compliance with the Meta Platform Terms and Developer Policies. CreatorFlow never uses Meta user data for surveillance, never transfers Meta user data to data brokers, and provides an immediate automated and manual mechanism to request complete deletion of stored Meta user data.
For explicit step-by-step instructions on removing CreatorFlow and deleting all associated Instagram data, see Section 15 (User Data Deletion Instructions).
1. Scope of This Privacy Policy
This Privacy Policy applies to all services, features, websites, applications, and developer interfaces provided by CreatorFlow Inc. ("CreatorFlow," "we," "us," or "our"), including:
- The CreatorFlow web application and public platform at https://creatorflow.cfd;
- Creator authentication, user accounts, role-based workspaces, and session management;
- AI-assisted content ideation, prompt engineering, multi-model scripting, and video planning;
- Visual Directed Acyclic Graph (DAG) workflow automation and canvas execution engines;
- Social media scheduling, publishing, and channel analytics integrations across connected third-party platforms (including YouTube, Instagram, Facebook, X/Twitter, LinkedIn, and TikTok);
- Enterprise and developer APIs, webhooks, and administrative control planes; and
- Customer support, billing management, infrastructure monitoring, and security telemetry.
2. Information We Collect
We collect information in three categories: information you provide directly, information collected automatically through your use of the platform, and information authorized via third-party platform connections.
2.1 Account and Identity Information
When you register or sign in to CreatorFlow, we collect:
- Your full name and primary email address;
- Unique account identifiers and workspace membership associations;
- Authentication provider records (e.g., Google Sign-In, Email/Password, WebAuthn Passkeys);
- Profile avatar URL supplied by your identity provider;
- Email verification status and multi-factor authentication (TOTP/MFA) enrollment timestamps;
- Organization, agency, and workspace role assignments (Owner, Admin, Creator, Viewer).
2.2 Creator Content and Project Inputs
We process the materials you upload, generate, or schedule through the platform:
- Creative prompts, research notes, script drafts, and video storyboards;
- Brand guidelines, custom vocabulary, tone-of-voice parameters, and logos;
- AI-generated text, subtitles, voiceover scripts, image prompts, and generated media assets;
- Visual automation graph structures, event triggers, node configurations, and execution histories;
- Publishing schedules, captions, hashtags, destination channel selections, and post metadata.
2.3 Technical, Device, and Operational Telemetry
To ensure platform security, verify API integrity, and prevent denial-of-service abuse, we automatically collect:
- Internet Protocol (IP) address and approximate geographic location (country/city level);
- Browser type, user agent, viewport resolution, and preferred language;
- Operating system, device category, and client session timestamps;
- API endpoint latency, diagnostic error stack traces, and HTTP response codes;
- Security audit events, failed authentication attempts, and token refresh records.
2.4 Subscription and Transaction Metadata
All payment card processing is performed directly by PCI-DSS Level 1 compliant payment gateways (such as Stripe). CreatorFlow does NOT collect, process, or store full credit card numbers, expiration dates, CVVs, or bank credentials. We receive only transaction confirmations, subscription status, billing tier, invoice identifiers, and payment method brand / last 4 digits.
3. Google Sign-In & Authentication Scopes
CreatorFlow provides Sign in with Google for secure, passwordless authentication. When you sign in with Google, our application requests ONLY non-sensitive authentication scopes:
openid: To verify your identity cryptographically;
.../auth/userinfo.email: To access your primary Google account email address;
.../auth/userinfo.profile: To read basic profile details (full name and profile picture URL).
What We DO NOT Access via Google Sign-In: Basic Google Sign-In does NOT grant CreatorFlow access to your Gmail messages, Google Drive documents, Google Contacts, Google Calendar events, Google Photos, or Google account passwords.
4. How We Use Google User Data
Google user data received during authentication is used strictly to deliver essential user-facing features:
- Authenticating your identity and provisioning your CreatorFlow workspace;
- Associating your creator projects, subscription plan, and assets with your verified profile;
- Delivering critical account security notifications, login confirmations, and billing receipts;
- Preventing account takeover, credential stuffing, and unauthorized workspace access; and
- Providing technical support upon your explicit request.
5. Google API Limited Use Compliance
CreatorFlow strictly complies with the Google API Services User Data Policy, including the Limited Use requirements:
- Prominent User-Facing Features: Google user data is only accessed and processed to provide features that are obvious and prominently displayed in the CreatorFlow user interface.
- No Sale: We never sell Google user data to data brokers, advertisers, or any commercial third party.
- No Advertising: We never use or transfer Google user data for serving advertisements, including retargeting, personalized advertising, or cross-context behavioral tracking.
- No Generalized AI Model Training: CreatorFlow NEVER uses Google user data to train, retrain, fine-tune, or develop generalized, public, or foundational AI or machine learning models.
- Human Access Prohibition: No CreatorFlow personnel are permitted to read Google user data unless: (a) you have provided affirmative written consent for technical troubleshooting; (b) it is required for investigating security incidents or system abuse; (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymized for internal system performance reporting.
6. YouTube API Services (Google / YouTube Developer Terms)
CreatorFlow integrates with the YouTube API Services to provide video upload scheduling, thumbnail publishing, title/description optimization, and channel performance analytics.
6.1 Mandatory Agreement to YouTube Terms
In compliance with the YouTube Developer Policies (Section III.A.1 and III.A.2):
- By using YouTube integration features within CreatorFlow, you agree to be bound by the YouTube Terms of Service.
- You acknowledge that CreatorFlow's handling of data accessed via YouTube API Services is also subject to the Google Privacy Policy.
6.2 YouTube Data Accessed and Collected
When you explicitly authorize CreatorFlow to connect your YouTube channel, we access:
- Your YouTube channel name, channel ID, custom URL, and channel avatar;
- Video metadata for videos scheduled or published via CreatorFlow (titles, descriptions, tags, category IDs, privacy status, publishing timestamps);
- Video analytics metrics for videos published through CreatorFlow (view counts, like counts, comment counts, estimated watch time);
- OAuth 2.0 refresh and access tokens necessary to maintain authorized publishing sessions.
6.3 Storage, Caching, and Retention of YouTube Data
In accordance with YouTube Developer Policy requirements on API data storage:
- Token Storage: YouTube OAuth tokens are encrypted at rest using AES-256 in secure server vaults.
- Cache Refresh: Stored YouTube API data (such as video statistics and channel metadata) is refreshed periodically and is NOT cached for longer than thirty (30) calendar days without re-verification against YouTube API Services.
- Immediate Purge on Disconnect: When you disconnect your YouTube channel in CreatorFlow Workspace Settings, all associated access and refresh tokens are immediately revoked and permanently purged from active databases.
6.4 Revocation of YouTube API Permissions
You may revoke CreatorFlow's access to your YouTube data at any time through:
To request permanent deletion of all historical YouTube analytics or metadata cached by CreatorFlow, email creatorflowuserprivacy@gmail.com.
7. Meta Platforms (Instagram & Facebook Graph API)
CreatorFlow integrates with the Meta Graph API and Instagram Graph API for creator publishing, carousel scheduling, Reels dispatch, and account metrics monitoring.
7.1 Instagram Data Accessed
When you connect an Instagram Professional / Creator account, CreatorFlow accesses:
- Instagram Account ID, username, profile picture, account biography, and follower counts;
- Media posting permissions (ability to publish images, carousels, and Reels to your Instagram feed);
- Media insights for published posts (impressions, reach, engagement, saves, shares);
- Meta OAuth access tokens and page-linking tokens.
7.2 Meta Platform Terms Compliance
- No Sale or Data Brokering: CreatorFlow will never sell, license, rent, or transfer Meta user data to data brokers, advertising networks, or third parties.
- No Surveillance: CreatorFlow does not use Meta user data to conduct surveillance, track users across third-party websites, or build unauthorized profiling databases.
- No AI Model Training: Meta user data and Instagram content are never used to train public or foundational artificial intelligence models.
- Security: All Meta API tokens are encrypted with AES-256 and stored with restricted role-based permissions.
8. X (formerly Twitter) Developer Policy Compliance
CreatorFlow integrates with the X API v2 to allow creators to schedule posts, threads, media attachments, and track engagement metrics.
- Data Accessed: X account user ID, username, display name, profile image, post creation permissions, and public engagement metrics (likes, reposts, replies).
- Honoring Deletions and Takedowns: In accordance with X Developer Policy, CreatorFlow immediately honors all post deletions, account terminations, and user modifications received via X API webhooks or platform sync within twenty-four (24) hours.
- No Surveillance or Profiling: We strictly prohibit the use of X data for surveillance, monitoring sensitive demographics, or building profiling databases.
- Revocation: You can disconnect CreatorFlow from your X account at any time in X Settings → Security and Account Access → Apps and Sessions.
9. LinkedIn Developer Agreement & API Terms
CreatorFlow integrates with the LinkedIn Developer Platform to support publishing professional articles, updates, video content, and viewing post performance.
- Data Accessed: LinkedIn member ID, vanity name, profile headline, organization page administrator roles, post text, media, and engagement metrics.
- Data Minimization & Model Training Prohibition: LinkedIn member data is stored only as long as necessary to confirm publication and display analytics. LinkedIn data is NEVER commingled with other platform datasets or used to train AI models.
- Token Revocation: LinkedIn OAuth tokens are stored encrypted and invalidated immediately upon workspace unlinking.
10. TikTok For Developers Compliance
CreatorFlow connects with TikTok APIs (Login Kit and Content Posting API) for video scheduling and creator publishing.
- Data Accessed: TikTok OpenID, display name, avatar, video upload status, and post metrics.
- Policy Adherence: Data obtained via TikTok APIs is processed in strict accordance with TikTok Developer Terms. User data is never sold or used for off-platform profiling.
11. Artificial Intelligence Services & Model Safeguards
CreatorFlow provides creators with cutting-edge AI ideation, script drafting, and workflow automation. We maintain strict enterprise safety boundaries with all underlying AI model providers (including Google Gemini, Anthropic Claude, and OpenAI):
- Zero Data Retention (ZDR) Enterprise Contracts: CreatorFlow executes enterprise API agreements with AI vendors ensuring that your prompts, scripts, and inputs are processed ephemerally and are NEVER used to train, retrain, or improve foundational or public AI models.
- Complete Separation of Identity Data: Authentication records (Google identity, Meta identity, email addresses) are strictly separated from AI generation pipelines and are NEVER transmitted to AI models.
- Creator Ownership: All creative prompts, scripts, drafts, and AI outputs belong 100% to you. CreatorFlow claims no intellectual property rights in your generated content.
12. Data Sharing and Third-Party Disclosures
CreatorFlow NEVER sells personal information or social platform user data. We share data only under the following strictly governed circumstances:
- Authorized Infrastructure Sub-Processors: Vetted cloud infrastructure, database, email, and authentication providers (e.g., AWS, Cloudflare, Supabase, Stripe) bound by strict Data Processing Agreements (DPAs). See our public Subprocessors Directory.
- Connected Publishing Endpoints: Transmitting scheduled posts to third-party platforms (YouTube, Instagram, X, LinkedIn, TikTok) solely upon your direct command.
- Legal and Safety Mandates: Where required by valid court order, subpoena, or applicable law, or to protect the safety of our users, platform integrity, and prevent criminal fraud.
- Corporate Restructuring: In the event of a merger, acquisition, or sale of corporate assets, with mandatory notice and continuation of all privacy protections herein.
13. Data Security Architecture
CreatorFlow implements enterprise defense-in-depth security measures to protect your personal data and connected API credentials:
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public endpoints and internal service communications.
- Encryption at Rest: AES-256 encryption applied to all relational databases, object storage volumes, and system backups.
- Token Vaulting: Platform API keys, Google OAuth secrets, and third-party tokens are managed in isolated, audited key management vaults and are never exposed to browser applications.
- Role-Based Access Control (RBAC): Strict principle-of-least-privilege access enforced across all internal production systems.
- Audit Logging: Continuous automated monitoring, intrusion detection, dependency vulnerability scans, and comprehensive access logs.
14. Data Retention Schedule
CreatorFlow retains personal data only as long as your account remains active or as needed to provide our services:
- Account Profile & Credentials: Retained for the lifetime of your active CreatorFlow account.
- Customer Drafts & Assets: Retained until deleted by the user or until account termination.
- Third-Party Social Tokens & Cached Metrics: Refreshed periodically; cached platform data is held for a maximum of thirty (30) calendar days and deleted immediately upon channel unlinking.
- Security & Authentication Logs: Retained for up to ninety (90) days for forensic auditing and abuse prevention, then permanently purged.
- Billing & Invoicing Records: Retained for seven (7) years to comply with statutory accounting and tax regulations.
15. User Data Deletion Instructions (Meta, Google & Universal)
CreatorFlow provides multiple clear, user-friendly mechanisms to request complete and permanent deletion of your personal data, platform connections, and stored assets:
15.1 Self-Service Account & Data Deletion
- Log in to your CreatorFlow account at https://creatorflow.cfd/login.
- Navigate to Workspace Settings → Security & Account.
- Scroll down to the Danger Zone and click Delete Account & All Data.
- Confirm your identity. Your account, workspace assets, connected platform tokens, and stored profile information will be immediately queued for permanent deletion.
15.2 Meta (Instagram / Facebook) Data Deletion Request
In compliance with Meta Platform Terms (Section 4.b), if you wish to remove CreatorFlow from your Meta account and delete all associated data:
- Go to your Instagram profile → Settings and Privacy → Website Permissions → Apps and Websites.
- Locate CreatorFlow in the active list and click Remove.
- To request immediate deletion of all historical analytics, tokens, and media cached on CreatorFlow servers, visit our dedicated deletion portal or email us at creatorflowuserprivacy@gmail.com with the subject line "Meta / Instagram Data Deletion Request" and your Instagram username.
- We will process your request, permanently delete all associated data within thirty (30) calendar days, and provide you with a unique confirmation tracking code.
15.3 Google & YouTube Data Revocation & Deletion
- Visit the Google Security Settings Permissions Page.
- Find CreatorFlow and click Remove Access.
- Email creatorflowuserprivacy@gmail.com with the subject line "Google Data Deletion Request" to permanently purge any cached Google identity details or YouTube statistics from our servers.
15.4 Email-Based Deletion Requests
You may at any time email our dedicated Privacy Officer at creatorflowuserprivacy@gmail.com. We verify all requests against the registered account email and execute permanent erasure across active databases within thirty (30) calendar days, with standard backup cycles purged within thirty (30) additional days.
16. Disconnecting Third-Party Platforms
You can disconnect any social media or identity integration at any time directly through CreatorFlow Workspace Settings → Integrations. Disconnecting an integration immediately revokes stored access tokens and ceases all data synchronization with that platform.
17. Cookies and Local Storage
CreatorFlow uses strictly necessary cookies and secure browser local storage exclusively for:
- Maintaining authenticated user sessions;
- Protecting against Cross-Site Request Forgery (CSRF);
- Storing user interface preferences (such as dark mode theme and workspace layout); and
- Enforcing rate limiting to prevent automated API abuse.
CreatorFlow does NOT use third-party advertising cookies, cross-site tracking beacons, or behavioural advertising pixels.
18. Global Privacy Rights
Regardless of your geographic location, CreatorFlow provides you with robust privacy rights:
- Right to Access / Know: Request a complete copy of all personal information we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure (Right to Be Forgotten): Request permanent deletion of your personal data.
- Right to Data Portability: Obtain your content and drafts in a structured, commonly used machine-readable format (JSON/CSV).
- Right to Restrict or Object: Restrict or object to specific processing operations.
- Right to Withdraw Consent: Revoke consent for optional features at any time without penalty.
18.1 California Privacy Rights (CCPA / CPRA)
Pursuant to the California Consumer Privacy Act as amended by the CPRA, California residents have the right to request disclosure of categories of personal information collected, request deletion, and opt out of any sale or sharing of personal data. CreatorFlow does not sell or share personal information for cross-context behavioral advertising.
18.2 European Economic Area (EEA) & United Kingdom (GDPR)
For users residing in the EEA or UK, we process personal data under the lawful bases of: (a) Contractual necessity; (b) Legitimate business interests (security and fraud prevention); (c) Compliance with statutory legal obligations; or (d) Explicit user consent. You have the right to lodge a complaint with your national Data Protection Authority.
18.3 India Privacy Rights (DPDP Act)
For users in India, CreatorFlow complies with the Digital Personal Data Protection Act (DPDPA). Grievances may be directed to our appointed Grievance Officer at creatorflowuserprivacy@gmail.com.
19. Children's Online Privacy Protection
CreatorFlow is strictly intended for professional creators, agencies, and businesses. The platform is not directed to individuals under the age of 16 (or the legal age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a minor has registered an account, contact us immediately at creatorflowuserprivacy@gmail.com for prompt account deletion.
20. International Data Transfers
CreatorFlow operates cloud infrastructure in the United States and globally. If you access the Services from outside the United States, your information will be transferred to and processed in the United States under standard data protection mechanisms, including European Commission Standard Contractual Clauses (SCCs).
21. Policy Modifications and Notifications
We may update this Privacy Policy from time to time to reflect platform improvements, new platform integrations, or evolving legal and Google/Meta/X/YouTube policy requirements. In the event of material modifications, we will notify registered users via email or in-app notification at least fourteen (14) days prior to the effective date, and update the "Last Updated" timestamp at the top of this document.
22. Official Legal Contacts & Corporate Directory
For privacy inquiries, rights requests, security disclosures, or compliance audits, please contact our dedicated teams:
Document: CreatorFlow Privacy Policy
Version: 3.0
Verification: Google OAuth & YouTube API Compliant
Meta Compliance: Meta / Instagram Graph API Compliant
X Compliance: X API v2 Developer Policy Compliant
LinkedIn Compliance: LinkedIn Developer Terms Compliant
© 2026 CreatorFlow Inc. All rights reserved.