1. Scope and service operator
This Privacy Policy applies to the website at https://towkn.com, the PostFlow application presented under the Towkn brand, and related support interactions. In this policy, “Towkn,” “PostFlow,” “we,” “us” and “the service” refer to that service.
The service operator is currently identified for publication as [Insert the service operator's legal name before publication]. The owner must replace this placeholder before publishing the policy.
2. Information we handle
Depending on how you use the service, we may handle the following categories of information:
- Account registration data: your name, email address, profile details, authentication records and information needed to maintain your session.
- Workspace and team information: workspace names, memberships, roles, invitations, approval assignments, comments and team activity.
- Connected social accounts: provider account identifiers, Page or channel names, usernames, profile images, account types, connection status and the relationship between linked accounts, such as an Instagram Professional account linked to a Facebook Page.
- OAuth permissions: the permissions granted through Meta, Google/YouTube or another supported provider, together with token type and expiry information where supplied by that provider.
- Content and media: captions, titles, platform settings, drafts, uploaded images and videos, scheduled publishing times, approval state and selected destinations.
- Publishing and operational records: publishing jobs, attempts, provider identifiers, success or failure status, safe error codes, scheduling history and operational analytics derived from PostFlow activity.
- Support and technical information: messages you send to support and limited technical, diagnostic or security information needed to operate and troubleshoot the service.
3. How we use information
We use information to provide and operate the features you request, including to:
- create accounts, workspaces and team memberships;
- connect and refresh selected social media accounts;
- store drafts and media, coordinate approvals, and schedule or publish selected content;
- maintain publishing history and show operational analytics;
- protect workspaces, enforce access controls, investigate failures and prevent misuse;
- respond to support, privacy and deletion requests; and
- maintain and improve the reliability and usability of the service.
We do not use provider access merely because an account exists. Provider requests are made to support account discovery, refresh, publishing or another feature initiated or configured through the service.
4. OAuth permissions and provider credentials
When you connect a social account, the provider presents its own authorization screen. The permissions displayed there control what PostFlow may request through that provider’s API. You should review those permissions before approving them.
Access tokens, refresh tokens and similar provider credentials may be stored in encrypted form so the service can maintain a connection and carry out authorized publishing. Credential decryption and provider API calls are designed to occur in Supabase Edge Functions or other server-side service components. Provider credentials, service-role keys and encryption keys are not intentionally returned to browser-facing account responses.
No security measure is infallible. If you believe a connection or account has been compromised, disconnect it in PostFlow, review the provider’s own security settings and contact support.
5. Infrastructure and third-party platforms
We rely on service providers and social platforms to operate PostFlow:
- Supabase provides application infrastructure used for authentication, database storage, media storage and server-side Edge Functions.
- Meta provides APIs for supported Facebook Pages and Instagram Professional accounts.
- Google and YouTube provide OAuth, channel discovery and YouTube publishing APIs.
- TikTok and other platforms may process information if a related integration becomes available and you choose to connect or publish through it.
These providers process information under their own terms and privacy policies. Content selected for publishing, account identifiers and necessary API request data are sent to the relevant provider. Provider availability and handling are outside our direct control.
6. Storage and retention
Account, workspace, content, media, scheduling and publishing records are generally retained while they are needed to operate the service, preserve workspace history, address security or support issues, and meet legitimate legal or operational needs. Different records may be retained for different periods. We do not state a fixed retention period because one has not yet been formally adopted for every category.
Deleted information may remain temporarily in backups, logs or systems operated by service providers. Content already sent to a social platform is governed by that platform and is not removed from the platform merely because it is deleted from PostFlow.
7. Disconnecting social accounts
Disconnecting a social account removes PostFlow’s stored connection credential and prevents that account from being used for new publishing through the workspace. Existing drafts, media, publishing history and operational records may remain so the workspace retains an accurate record of prior activity.
Disconnecting inside PostFlow may not revoke provider-wide authorization. Where needed, you can also revoke the application through the security or connected-app settings offered by Meta, Google/YouTube or the relevant provider.
8. Deletion, access and correction requests
You may request access to, correction of or deletion of information associated with your account by visiting the Support page and contacting us from the email address associated with your account. We may need to verify your identity and workspace authority before acting on a request.
Some information may need to be retained where deletion would affect another workspace member’s records, compromise security or publishing history, or conflict with an applicable legal obligation. We will explain material limitations that apply to a request rather than promising deletion that the service cannot safely perform.
9. Security practices
PostFlow uses measures intended to reduce unauthorized access, including encrypted provider credentials, private credential storage, server-side service-role access, workspace-based authorization, row-level security policies and restricted provider operations. We also limit browser-facing account data so credentials are not intentionally included.
These practices reduce risk but do not guarantee absolute security, uninterrupted availability or protection against every threat. Users are responsible for protecting their passwords, email accounts and connected provider accounts.
10. Your choices and rights
Depending on your location and applicable law, you may have rights concerning access, correction, deletion, restriction, objection or portability. The availability and scope of those rights vary. You may also disconnect provider accounts, change workspace permissions, remove content you control and revoke OAuth access through the provider.
Contact support to make a request. We will assess it based on the account, workspace context and applicable requirements.
11. Changes to this policy
We may update this policy as the product, providers or handling practices change. The effective date at the top will be updated when a revised version is published. Material changes may also be communicated in the application or through available account contact details where appropriate.
12. Contact
For privacy questions, account deletion requests or concerns about connected social accounts, email support@towkn.com or use the Support page.