Privacy & Data Security

Privacy Policy

At SethuFlow, we treat your content, social channel credentials, and audience analytics with the highest standard of confidentiality and zero-knowledge token encryption.

Effective Date: October 3, 2026 • Version 3.4

Zero Password Storage

All social logins run through official OAuth 2.0 PKCE. We never see or store your social passwords.

No AI Model Training

Your draft posts, brand voice configurations, and ideas are never used to train external LLMs.

1-Click Full Erasure

Full compliance with GDPR and CCPA. Delete your account and purge all staged posts instantly.

1. Information We Collect

When you register for SethuFlow and use our social orchestration tools, we collect only the necessary data to facilitate publishing, performance analytics, and AI content formatting:

  • Account Information: Name, work email address, and authentication provider identifiers (Google OAuth, GitHub, or email-based magic links).
  • Connected Social Profiles: Public account names, handles, profile avatars, and platform-issued OAuth tokens required to publish posts on your behalf.
  • Content Drafts & Assets: Post text, media URLs, tags, scheduling calendars, and AI adaptation prompts created within the Post Studio.
  • Analytics & Engagement Telemetry: Impressions, click-through rates, likes, and comment volume retrieved from public channel APIs for your dashboard insights.

2. OAuth 2.0 Token Vault & Cryptographic Storage

SethuFlow adheres to strict least-privilege API scopes for all 10 supported platforms (X, LinkedIn, Instagram, TikTok, YouTube, Pinterest, Facebook, Threads, Bluesky, Mastodon).

• Encryption Standard: AES-256-GCM hardware-level vault
• Token Rotation: Automated refresh token renegotiation
• Revocation: Immediate client-side and server-side disconnect

3. Artificial Intelligence & BYOK Protocol

SethuFlow integrates state-of-the-art language and vision models to tailor posts per network. We maintain a strict zero-retention agreement with our upstream API providers:

  • Your inputs, drafts, and brand voice guidelines are sent via secure TLS 1.3 endpoints.
  • No data processed by SethuFlow is ever utilized by OpenAI, Anthropic, or Google DeepMind for foundation model training or reinforcement fine-tuning.
  • If you configure Bring-Your-Own-Key (BYOK), all requests are signed directly with your client key and bypass our platform billing pipeline.

4. GDPR & CCPA Global Privacy Rights

Regardless of your geographic location, SethuFlow provides every user with standard European GDPR and California CCPA rights:

Right to Portability: Export all posts and analytics in JSON/CSV at any time.
Right to Erasure: Purge account and database records with one click in Settings.
Right to Restrict: Revoke social media channel access individually without deleting your account.
Zero Sale of Personal Data: We never monetize, sell, or rent user data to data brokers.

5. Meta & Social Platform Data Deletion

In accordance with Meta Platform Terms (Facebook Login, Instagram Graph API) and GDPR/CCPA regulations, users may request the deletion of all data and tokens acquired via connected social accounts at any time.

User Data Deletion Instructions & Status
Step-by-step instructions to revoke permissions and purge records
View Deletion Instructions

6. Contact Our Data Protection Officer

For privacy inquiries, audit questions, or data protection agreements (DPAs), reach our security and privacy team directly:

SethuFlow Data Protection Officer
Email: dev@sethuflow.com • Response SLA: within 24 business hours
Contact DPO

Ready to create with complete privacy?

Start your 7-day free trial. No credit card required. Full enterprise security.

Start 7-Day Free Trial