AIFlow is an AI social-media assistant that helps you create, schedule and publish content to the social accounts and Pages you choose to connect. We only ever access third-party account data with your explicit authorization, and we use it solely to provide the features you ask for. We never sell your data.
1. Information we collect
Account & profile
- Details you give us at sign-up: name, email, mobile, company.
- Billing records for paid plans (plan, cycle, transaction reference, GST details).
- Content you create or upload: post captions, generated/uploaded images, brand guidelines, and product/service information for your assistant.
Usage & technical
- IP address, browser type, pages viewed and similar log data, used to secure and improve the service.
- Cookies strictly for sign-in sessions and your interface preferences (e.g. light/dark theme).
2. LinkedIn data — how we access, use, store and delete it
AIFlow uses the LinkedIn Community Management API under LinkedIn's API Terms of Use. LinkedIn data is accessed only after you click “Connect with LinkedIn” and grant consent through LinkedIn's official OAuth 2.0 screen. You stay in control and can disconnect at any time.
What we access (only with your permission)
- The Company Pages you administer — so you can choose which Page to publish to. We request the scopes
rw_organization_admin,w_organization_socialandr_organization_social. - Permission to publish posts to the specific Page you select, and to read that Page's own posts/engagement for status.
We do not access your personal connections, private messages/inbox, your personal news feed, or any data unrelated to managing the Page you connect.
What we store
- An OAuth access token (and a refresh token, if LinkedIn issues one) and its expiry date.
- The selected Page's display name and its LinkedIn organization identifier.
Tokens are stored on our secured servers with restricted access and are used only to carry out actions you initiate or schedule in AIFlow.
How we use it
- To publish or schedule the posts you create, to the Page you chose.
- To display your connection status and the connected Page name.
We never post on your behalf without an action or schedule you set up. We never use LinkedIn data for advertising, profiling or model training, and we never sell, rent or share it with third parties.
Retention, revocation & deletion
- Disconnect anytime from Dashboard → Integrations → Disconnect. This immediately deletes the stored LinkedIn tokens from our systems.
- You can also revoke AIFlow's access directly at LinkedIn → Settings & Privacy → Data privacy → Permitted services.
- When you disconnect, close your account, or your account is deleted, we delete the associated LinkedIn tokens and connection details.
Our handling of LinkedIn data complies with the LinkedIn API Terms of Use and LinkedIn's Platform Guidelines. If those terms conflict with this policy for LinkedIn data, the LinkedIn terms govern that data.
3. Gmail data — how we access, use, store and delete it
AIFlow integrates with the Gmail API (via Google OAuth 2.0) to let you send email newsletters, track outreach replies, and organise your inbox — all from within AIFlow. Gmail access is entirely optional and requires your explicit consent through Google's official OAuth screen.
AIFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access (only with your permission)
We request the minimum scopes needed to operate the features you activate:
gmail.send— to send scheduled email newsletters, post digests, and outreach emails on your behalf, from your own Gmail address.gmail.readonly— to read inbox threads so we can track replies to outreach emails you sent through AIFlow and surface reply analytics in your dashboard.gmail.modify— to label, archive, or mark as read the threads AIFlow has sent or is tracking, keeping your inbox organised.userinfo.email— to identify which Gmail address is connected so you can manage multiple accounts within AIFlow.
We do not access your full inbox for any purpose other than tracking threads we sent. We do not read emails unrelated to AIFlow actions.
What we store
- An OAuth access token (short-lived) and refresh token (long-lived), both encrypted at rest using AES-256.
- The connected Gmail address (for display in your AIFlow dashboard).
- Token expiry timestamps.
We never store the content of your emails.
How we use it
- To send emails you schedule or trigger inside AIFlow.
- To retrieve reply status on outreach threads and show you response analytics.
- To apply labels or archive threads as you configure in your AIFlow automation rules.
We never use Gmail data to serve advertisements, build user profiles, or train AI or machine-learning models. We never sell, rent or transfer Gmail data to third parties. This complies with Google's Limited Use Policy.
Retention, revocation & deletion
- Disconnect anytime from Dashboard → Integrations → Disconnect Gmail. This immediately deletes the stored Gmail tokens from our systems.
- You can also revoke AIFlow's access directly at myaccount.google.com/permissions.
- On account deletion, all Gmail tokens and associated metadata are purged within 30 days.
Our handling of Gmail data complies with the Google API Services User Data Policy. If those terms conflict with this policy for Gmail data, the Google terms govern that data.
4. Instagram data — how we access, use, store and delete it
AIFlow connects to the Instagram Graph API (via Meta's OAuth 2.0) to enable scheduling and publishing of content to your Instagram Business or Creator account. Connection requires linking your Instagram account to a Facebook Page. Instagram access is entirely optional and requires your explicit consent.
What we access (only with your permission)
instagram_basic— to read your account's basic profile information and identify the connected Instagram Business account within AIFlow.instagram_content_publish— to publish photos, videos, carousels, Reels, and Stories to your account on the schedule you set.instagram_manage_insights— to retrieve post-level and account-level engagement analytics for display in your AIFlow performance dashboard.
We do not access your Instagram DMs, follower lists, following lists, personal messages, or story replies. We do not read content from your personal feed.
What we store
- An OAuth access token and its expiry date.
- Your Instagram Business account ID and display name.
How we use it
- To publish the content you schedule in AIFlow to your connected Instagram account.
- To display engagement metrics (likes, reach, impressions) in your AIFlow dashboard.
We never publish content without an action or schedule you set up. We never use Instagram data for advertising, profiling or model training, and we never sell or share it with third parties.
Retention, revocation & deletion
- Disconnect anytime from Dashboard → Integrations → Disconnect Instagram.
- You can also revoke access via Instagram → Settings → Apps and Websites.
- On disconnect or account deletion, all Instagram tokens and connection data are deleted immediately.
5. Facebook Pages data — how we access, use, store and delete it
AIFlow connects to the Facebook Graph API (via Meta's OAuth 2.0) to allow scheduling and publishing of content to your Facebook Pages. Facebook Pages access is entirely optional and requires your explicit consent.
What we access (only with your permission)
pages_show_list— to list the Facebook Pages you manage, so you can choose which ones to connect to AIFlow.pages_read_engagement— to read post engagement and Page-level insights for your AIFlow analytics dashboard.pages_manage_posts— to create, schedule, and publish posts to your connected Facebook Pages.
We do not access your personal Facebook profile, personal feed, friends list, Messenger messages, Facebook Groups, or Facebook Ads data.
What we store
- An OAuth Page access token (per connected Page) and its expiry date.
- The connected Page's name and Page ID.
How we use it
- To publish the posts you schedule in AIFlow to your connected Facebook Page(s).
- To display post-level engagement metrics in your AIFlow dashboard.
We never publish without an action or schedule you configure. We never use Facebook data for advertising, profiling or model training, and we never sell or share it with third parties.
Retention, revocation & deletion
- Disconnect anytime from Dashboard → Integrations → Disconnect Facebook.
- You can also revoke access at Facebook → Settings → Security and Login → Apps and Websites.
- On disconnect or account deletion, all Page tokens and related data are deleted immediately.
6. Microsoft 365 (Outlook) data — how we access, use, store and delete it
AIFlow integrates with the Microsoft Graph API (via Microsoft Identity Platform / Azure AD OAuth 2.0) to let you send and manage email through your Microsoft 365 / Outlook account. This is entirely optional and requires your explicit consent through Microsoft's official OAuth screen.
What we access (only with your permission)
Mail.Send— to send scheduled email newsletters, outreach emails, and post digests on your behalf from your Outlook address.Mail.ReadWrite— to read, organise, and track replies to emails sent through AIFlow, and to apply folder rules you configure.offline_access— to obtain a refresh token so AIFlow can send scheduled emails without requiring you to re-authenticate each time.User.Read— to identify the connected Microsoft 365 account (email address and display name) within AIFlow.
We do not access your full Outlook inbox beyond threads related to AIFlow actions. We do not access your Microsoft Teams, SharePoint, OneDrive, Calendar, or any other Microsoft 365 service.
What we store
- An OAuth access token (short-lived) and refresh token (long-lived), both AES-256 encrypted at rest.
- The connected Outlook email address.
- Token expiry timestamps.
We never store the content of your emails.
How we use it
- To send emails you schedule or trigger inside AIFlow.
- To track reply status on outreach threads and display reply analytics.
- To apply folder or label rules you set up in your AIFlow automations.
We never use Microsoft 365 data to serve advertisements, build profiles, or train AI models. We never sell or share this data with third parties.
Retention, revocation & deletion
- Disconnect anytime from Dashboard → Integrations → Disconnect Microsoft 365. This immediately deletes the stored tokens.
- You can also revoke access at myapps.microsoft.com → Edit profile → Revoke permissions.
- On account deletion, all Microsoft 365 tokens are purged within 30 days.
7. AI processing
To generate captions, images and assistant replies, and to read brand or product documents you upload, we send the relevant content to our AI provider (Anthropic, via the Claude API) strictly to produce your requested output. This content is not used to train AI models. Do not upload information you are not authorized to share.
8. How we share information
We share data only with service providers that help us run AIFlow (hosting, email, payments, the AI provider above), and the social platforms you connect — each only to the extent needed to deliver the service. We may disclose information where required by law. We do not sell personal information.
9. Security
We use technical and organizational safeguards — restricted access, encrypted transport (HTTPS), and isolated per-customer data — to protect your information. No method of transmission or storage is 100% secure, but we work to protect your data and to limit access to it.
10. Data retention
We keep your account data while your account is active and as needed to operate our business, meet legal/tax obligations, resolve disputes and prevent fraud. Connection tokens are removed on disconnect or account deletion as described above.
11. Your rights
You may access, correct or delete your personal information, and limit certain uses, subject to applicable law (including Indian and UAE data-protection rules). To make a request, contact us using the details below.
12. International transfers
As permitted by applicable law, we may process and store information outside your country of residence, wherever we or our service providers operate, with appropriate safeguards.
13. Changes to this policy
We may update this policy to reflect changes to our services or the law. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Continued use of AIFlow after an update means you accept the revised policy.
14. Contact us
Questions or requests about this policy or your data:
- Email: customer.relations@merciglobal.com
- Merciglobal Systems Pvt Ltd