Privacy Policy
Effective: May 23, 2026 · Last updated: May 23, 2026
This policy explains what Pubflow (“we”, “us”) collects, how we use it, who we share it with, and the choices you have. It applies to app.pubflow.in and the Pubflow service.
We try to keep it short, specific, and accurate. If anything below contradicts what we actually do, the practice — not the document — is what we're accountable for. Tell us and we'll fix it.
1. What we collect
- Account data: name, email, password hash, role inside your team, the tenant (workspace) you belong to, your verification + email-preference state.
- Brand & content: posts you write or generate, scheduled times, brand guidelines (logo, colors, voice, target audience), uploaded media assets, approval workflow comments.
- Social-platform connections: OAuth tokens for the platforms you connect (Facebook, Instagram, X, LinkedIn, etc.). Tokens are encrypted at rest with AES-256-GCM and never exposed to the browser or to other tenants.
- Usage: which features you use, AI token budget consumption, request timings, error events. Used to operate, debug, and bill the service.
- Technical: IP address, browser user-agent, device type, time of access. Used for security, abuse prevention, and rate limiting.
- Payments (when active): billing contact, plan history, invoice records. Card data is processed by Stripe / Razorpay — we never see or store full card numbers. Payments are disabled during beta; Pubflow is free.
2. What we do NOT collect
- We don't sell your data.
- We don't use your posts, brand guidelines, or any tenant content to train AI models that serve other tenants.
- We don't share your social-platform tokens with any third party.
- We don't store credit-card numbers — Stripe / Razorpay handle that.
3. How we use it
- To run the service you signed up for.
- To generate the AI content you ask for, using the brand context and prompts you provide.
- To publish, schedule, and track posts on the social platforms you've connected.
- To send you account, security, and product emails. We only send marketing email if you opt in.
- To detect abuse, enforce rate limits, and protect everyone's data.
- To prepare and (eventually) invoice for paid plans.
4. Sub-processors (the third parties we use)
We rely on these vendors to run Pubflow. Each receives only the data needed for their role.
- Render (United States / Singapore) — application hosting, managed Postgres, managed Redis.
- Vercel (United States) — web application hosting (frontend).
- Cloudflare R2 (global) — media-asset storage.
- OpenAI (United States) — AI text and image generation. We send the prompt, brand context, and your request; we don't enable OpenAI's training opt-in on our API key.
- Resend (United States) — transactional and notification email.
- Sentry (United States) — error telemetry. Cookies, Authorization headers, and CSRF tokens are scrubbed before any event leaves our servers.
- Meta, X, LinkedIn, etc. — the social platforms you connect. Posts and engagement data flow via their official APIs under the OAuth scopes you consented to.
- Stripe / Razorpay (when payments are live) — checkout, subscription management, invoicing.
- Firebase Auth (Google, United States) — used for specific federated-login flows.
5. Where we store data
The primary database is hosted in Render's Singapore region. Sub-processors above operate in their stated regions. By using Pubflow you consent to your data being transferred to and processed in these jurisdictions.
6. How long we keep it
- Active account data: as long as your workspace is active.
- Closed accounts: deleted within 30 days of confirmed deletion request, except where law requires longer retention (e.g. tax invoices).
- Audit logs: kept for at least 12 months for SOC2 / security review.
- Backups: point-in-time recovery retained per our hosting provider's defaults (currently 7 days).
7. Your rights
You can ask us to:
- Access the data we have about you.
- Correct inaccurate data — most fields are editable in your account settings.
- Delete your data — email privacy@pubflow.in from your account email address and we will erase your account, your connected social accounts and the access tokens behind them. Standard delete completes within 30 days.
- Export a copy of your data (right to portability) — email privacy@pubflow.in and we'll respond within 30 days.
- Object to specific processing or withdraw consent for marketing email at any time — every marketing email includes an unsubscribe link.
- Lodge a complaint with your local data protection authority if you believe we've mishandled your data.
8. Security
We use industry-standard practices: TLS in transit, AES-256-GCM for sensitive fields (social-platform tokens, encryption keys), HttpOnly + Secure cookies with CSRF protection for the web session, rate limiting on auth and sensitive endpoints, per-tenant isolation enforced at the data layer, audit logging of admin actions. No system is perfectly secure; if you find a vulnerability, please report it to security@pubflow.in.
9. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to protect against CSRF. We do not use third-party advertising or cross-site tracking cookies. See our cookies page for the full list.
10. Children
Pubflow is a B2B product not intended for children under 16. If you believe a child has signed up, contact us and we'll delete the account.
11. Changes to this policy
We'll post material changes here and update the “Last updated” date at the top. If the change materially expands what we collect or how we use your data, we'll email account owners at least 30 days before it takes effect.
12. Contact
Privacy questions: privacy@pubflow.in
Security reports: security@pubflow.in
General support: hello@pubflow.in