Privacy
Privacy Policy
How PostemFlow handles the data used to organize content, approvals and integrations.
Last updated: September 22, 2026
1. Who we are and how to contact us
PostemFlow is a content management, editorial calendar and approval tool for Social Media teams. The privacy and data-subject contact channel is suporte@postemflow.com.br.
This document explains objectively how personal data is handled on the website, in the system and in integrations requested by the user.
2. Data we process and sources
Depending on product use, we may process:
- registration and authentication data, such as name, email and identifiers supplied by Supabase or Google;
- workspace data, invitations, roles, clients, posts, briefs, media, approvals, comments and requests entered by the user;
- metadata needed to locate files, prefixes and uploads in private storage;
- technical, security, support and audit records needed to operate and protect the service.
Data may be supplied directly by the data subject, by a workspace administrator, through an invitation or by a connected authentication provider.
3. Purposes and legal bases
- Contract performance: create the account, deliver the workspace and provide requested calendars, approvals, invitations and uploads.
- Consent: authorize optional integrations such as Instagram when the data subject chooses that option.
- Legitimate interest and security: prevent fraud, protect sessions, investigate failures, provide support and improve service stability.
- Legal obligation: comply with applicable laws, regulations and requests from competent authorities.
4. Google and storage
Google sign-in is handled by the configured authentication provider. PostemFlow files are stored in private storage accessed only by the server, without permanent credentials in the browser.
Integration access tokens are encrypted on the server. PostemFlow does not sell Google data, use files for advertising or request more data than needed for the enabled feature. Legacy files that remain with another provider are subject to that provider's rules during migration.
5. Instagram and other social networks
When a social integration is enabled, PostemFlow may process account ID, username, authorized scopes, token expiration, media or publication IDs, processing status, captions and temporary URLs needed for delivery. A person authorized in the workspace starts the connection, which is used only to prepare or publish requested content.
Social network tokens are encrypted on the server and are not sent to the browser as permanent credentials. PostemFlow does not use this data for advertising, sale or profile enrichment. The user must have permission to connect the account and publish the material; the social network's rules continue to apply.
6. Cookies and similar technologies
The site uses technologies that are strictly necessary for sessions, security and OAuth. When enabled, optional analytics load only after affirmative consent and measure visits, campaign sources and aggregated funnel steps. We do not use advertising or remarketing. See the Cookie Policy for purposes and controls.
7. Sharing and transfers
Data may be processed by infrastructure, authentication, database, hosting, storage and integration providers selected by the user, including login providers, hosting, storage, Meta/Instagram and other activated services. Providers receive only what is necessary and may process data outside Brazil under their own policies and applicable safeguards.
We do not share personal data for sale or behavioral advertising. We may share information when required by law, by a competent authority or to protect rights and security.
8. Retention and deletion
We keep data while the account or workspace is active and for as long as needed for the stated purposes. Invitations and temporary states expire according to their purpose. Integration tokens are removed when a connection is disconnected, except where a legitimate record or legal obligation requires retention.
When PostemFlow is removed from Instagram settings or Meta data deletion is requested, we remove the connection, encrypted token and pending schedules linked to that account. Content already published remains subject to the social network's controls.
Privately stored files and publications already sent to a social network remain subject to the retention controls of the relevant service. Legacy files at external providers may require additional deletion there.
9. Data-subject rights
Within applicable law, data subjects may request confirmation of processing, access, correction, anonymization, blocking, deletion, information about sharing, withdrawal of consent and data review. Send requests to the privacy channel with enough information to locate the account. We may request identity verification to protect the data subject.
10. Security
We use technical and administrative controls proportionate to risk, including access control, separation of server-side secrets, token encryption and OAuth state validation. No internet-connected system is completely immune to incidents; where applicable, we will communicate incidents as required by law.
11. Changes to this policy
This policy may be updated to reflect product, provider or legal changes. The date at the top identifies the current version. Material changes will be communicated through available channels.
