Back to Home

Privacy Policy

Last Updated: March 14, 2026

1. Information We Collect

We collect information that you provide directly to us when you use our services, create an account, or integrate third-party platforms. This includes:

  • Personal Identifiers: Email address and name.
  • Payment Information: We use Stripe to process payments. We do not store your credit card numbers on our servers; Stripe provides us with a token and the last 4 digits for verification.
  • Meta/Threads Platform Data: When you connect your Threads account via Meta OAuth, we collect your public profile information (username, profile picture) and authentication tokens. We request the exact permissions necessary (e.g., to read historical performance, read comments for your engagement dashboard, and publish content) to operate the application.
  • Usage Data: Anonymous data about how you interact with our website to improve system performance.

2. How We Use Your Information

We use the information we collect strictly to provide and improve our services:

  • App Functionality: To allow you to manage multiple Threads accounts, schedule posts, and publish content directly to your connected Threads profiles.
  • Account Management: To secure your account, process payments, and send transactional emails.
  • Compliance: We do not sell, rent, or transfer your Threads data to unauthorized third parties or use it for unapproved advertising purposes, in strict compliance with the Meta Platform Terms.
3. Third-Party Subprocessors

We share data with trusted third-party service providers who assist us in operating our services securely:

  • Stripe (USA): Payment processing.
  • Supabase (USA): Database hosting and secure user authentication.
  • Vercel (USA): Website hosting and infrastructure.
  • Resend (USA): Transactional email delivery.
  • AI Providers (USA): We utilize secure API connections with third-party Large Language Models (e.g., OpenAI, Anthropic) to power our text generation and analytics features.

4. Artificial Intelligence & Data Processing

BlckFlow utilizes third-party Artificial Intelligence (AI) models to provide core features, such as drafting posts and summarizing historical analytics.

  • Data Transmission: When you use our AI features, relevant text inputs, historical post data, or comments may be securely transmitted to our AI partners for processing.
  • No Model Training: We use enterprise API agreements with our AI providers. Your personal data, connected Threads data, and generated content are NOT used by these third parties to train their foundational machine learning models.

5. Data Deletion & Your Rights

All users, regardless of geographic location, have the right to access, modify, or permanently delete their personal data and connected platform data from our servers.

How to Request Data Deletion:

If you wish to delete your account and all associated Meta/Threads data from our systems, you can do so by:

  1. Sending an email to support@blck-flow.com with the subject "Data Deletion Request". We will process and confirm the permanent deletion of your data within 7 business days.
  2. To disconnect from Meta: You can also manually revoke our app's access to your Threads account at any time by navigating to your Threads app Settings > Website permissions > Apps and websites and removing our application.

6. Data Retention & Security

We retain your personal information only for as long as your account is active or as needed to provide you services.

  • Meta/Threads Data: Access tokens and cached profile data obtained via Meta APIs are stored securely using industry-standard encryption. If you revoke access or delete your account, all associated Meta API data and authentication tokens are immediately and permanently destroyed from our active databases.
  • Security: We implement SSL encryption and strict database row-level security (RLS) via Supabase to prevent unauthorized access to your connected accounts.

7. Children's Privacy

Our services are not directed to, and we do not knowingly collect personal information from, children under the age of 13 (or the applicable age of digital consent in your jurisdiction). If we become aware that we have collected personal data from a child without parental consent, we will take immediate steps to delete that information. If you believe we might have any information from or about a child, please contact us at support@blck-flow.com.