Integrations
Which permissions we request, what we store and how to disconnect.
Flow publishes to social accounts that the account holder connects themselves. Connection is made through each network's official login (OAuth) — we never ask for the account password. Whoever connects can disconnect at any time inside Flow, and the authorization can also be revoked directly on the social network.
TikTok
Used to publish videos directly to the profile of the person who authorized it.
| Scope | Why we need it |
|---|---|
user.info.basic | Read the display name and profile picture, so the screen always shows which account will receive the video. |
video.publish | Publish the approved and scheduled video to the profile. |
Before every post we query the creator information and honor the account's limits: the person publishing must manually choose the video privacy level (there is no default value), whether comments, Duet and Stitch are allowed, and disclose whether the content is commercial (own brand or paid partnership). Options the account does not allow are shown disabled. We upload the video with no watermark and no overlays. We only re-encode the file when the frame rate is variable or outside the 23–60 fps range TikTok accepts.
What we store: the public account identifier, the display name and the access tokens required to publish. We do not read private messages, contacts or browsing history.
Instagram and Facebook
Publishing photos, carousels, reels and video to the Instagram Business accounts and Facebook Pages the holder authorizes. Authorization happens once through the Meta account, and then each account is linked to the matching client inside Flow.
What we store: the page/account identifier and name, and the publishing token.
Publishing text, image and video to the profile of whoever authorizes it. LinkedIn does not provide automatic refresh, so the connection has to be renewed periodically.
What we store: the profile identifier, the name and the publishing token.
How to disconnect
- In Flow: Settings → Clients → open the client → remove the connected network. Tokens are deleted from our database immediately.
- On the social network: through the connected apps settings of the platform itself.
To request deletion of any data, write to igmagencia2@gmail.com. See also our Privacy Policy.