frameflow
FeaturesHow it worksDashboard
Open dashboard
Legal information

Privacy Policy

Last updated: TODO_OWNER_LAST_UPDATED

This policy must be completed with the owner’s legal identity, contact details, service providers and retention periods before Meta or Google review.

Who controls the data

Controller: TODO_OWNER_LEGAL_NAME. Contact: TODO_OWNER_EMAIL. Registered address: TODO_OWNER_ADDRESS.

Data we collect

Depending on the features you use, Frameflow may process your workspace user identifier and email; TikTok, Instagram Professional and YouTube channel identifiers, display names and profile images; OAuth scopes and encrypted access/refresh tokens; uploaded MP4 files and their filename, size and duration; publication captions, titles, descriptions, visibility and processing status; and technical timestamps and non-sensitive error codes.

Why we use it

We use this data to connect the account you authorize, show the exact destination and metadata before publication, store your video library, send a publication only after your explicit action, display the platform’s processing result, prevent duplicate records and secure the service. We do not ask for or store platform passwords.

Platform integrations

TikTok receives the video and settings you approve through its official Login Kit and Content Posting API. Meta receives the Reel through the official Instagram API for Professional accounts. For Instagram, a temporary HTTPS media URL is generated only so Meta can fetch the selected video. Google receives the title, description, visibility, audience declaration and video through the official YouTube Data API.

Each platform is independent. Its terms, privacy notice, review status, rate limits and processing decisions also apply.

Tokens and security

OAuth tokens are processed server-side and encrypted with TOKEN_ENCRYPTION_KEY. They are never rendered into browser responses or normal logs. Use HTTPS in production, keep secrets out of source control and restrict the private admin board to authorized operators.

Retention and deletion

Retention periods: TODO_OWNER_RETENTION_PERIODS. Disconnecting a destination deletes its locally stored credentials and destination publication records. You may request deletion of all Frameflow data through TODO_OWNER_DELETION_PROCESS; the service will not delete content from TikTok, Instagram or YouTube unless an authorized platform action explicitly does so.

For Meta data deletion requests, configure /api/meta/data-deletion in the Meta developer console. For Google users, revoke access at Google security settings and then use the Frameflow deletion process.

Your rights and contact

Requests about access, correction or deletion can be sent to TODO_OWNER_EMAIL. Response times and jurisdiction: TODO_OWNER_RIGHTS_PROCESS.

frameflow

Creator-controlled publishing for generated short video.

Privacy PolicyTerms of ServiceContact
Tokens stay server-side