SakaFlow Privacy Policy
Last updated: 10 October 2026 · Applies to https://sakaflow.tech, the SakaFlow dashboard and its connected integrations.
SakaFlow ("SakaFlow", "we", "us") is a social media management app that agencies use to prepare, review, schedule and publish posts for the social accounts of their clients. This policy explains what data SakaFlow handles, why, where it is kept, who it is shared with, and the choices you have.
1. Who we are
SakaFlow is operated by SakaFlow. You can contact us at [email protected].
2. Who this applies to
- Agency users who sign in to the SakaFlow dashboard.
- Account owners (for example an agency's clients) who authorize SakaFlow to access a social account such as a YouTube channel or a TikTok account.
3. Data we collect
| Category | What it includes | Source |
|---|---|---|
| Agency user account | Email address, name or display name, role and the clients the user may manage, sign-in session data. | The user, when the account is created |
| Connected account details | For YouTube: channel ID, channel title, channel handle, the permissions (scopes) granted, connection status and the time of connection. For TikTok: the account's open ID, display name or username, granted scopes and status. | Google / TikTok, after the account owner authorizes access |
| Authorization tokens | OAuth access tokens and refresh tokens for the connected accounts. | Google / TikTok |
| Content and post data | Media files (videos, images), titles, captions, hashtags, scheduling times, approval decisions and publishing results (such as post IDs and error messages). | Agency users, and the agency's file storage (Google Drive folders the agency shares with SakaFlow) |
| Performance figures | Publicly available metrics for posts published through SakaFlow (for example views and likes), kept as periodic snapshots. | YouTube / TikTok APIs |
| Brand profile | Tone-of-voice and brand notes entered by the agency to help write post text. | Agency users |
| Activity and security logs | Who did what and when (sign-ins, connections, approvals, settings changes), request metadata such as IP address and browser type, and error records. | Generated by the app |
We do not collect your Google password, and we do not receive any other Google account data beyond what is listed above.
4. Google and YouTube user data
SakaFlow connects to a YouTube channel only after the channel's owner approves access on Google's consent screen. SakaFlow requests these two Google API scopes:
https://www.googleapis.com/auth/youtube.upload– to upload videos to the channel that the account owner and agency have approved for publishing.https://www.googleapis.com/auth/youtube.readonly– to identify which channel was connected (channel ID, title and handle) and to read public performance figures for the channel's videos.
We use this data only to provide and improve these user-facing features of SakaFlow: connecting the correct channel, publishing approved videos, and showing the results. Specifically:
- We do not use it for advertising, and we do not sell it.
- We do not transfer it to others except as needed to provide the service (see section 6), to comply with the law, or as part of a merger or sale of the service with notice to affected users.
- We do not use it to determine credit-worthiness or for lending purposes.
- Humans do not read this data unless the account owner asks us to, it is needed for security or to investigate abuse, or the law requires it.
- We do not use Google user data to develop, improve or train generalized artificial-intelligence or machine-learning models. The AI writing assistant receives only text that the agency provides or that is part of a post being prepared (for example a draft caption, a file name, the target platform and the client's brand notes). YouTube access tokens and channel details are not sent to it, and metrics are not sent to it automatically. If an agency user pastes performance figures into the assistant, that pasted text is sent to the configured AI provider to produce the summary.
SakaFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we use data
- To authenticate agency users and control which clients each user may see.
- To connect, refresh and, when requested, disconnect social accounts.
- To store, review, schedule and publish content, and to record the result.
- To show performance figures and reports to the agency.
- To help write post text when an agency user asks for it.
- To keep the service secure, prevent abuse and diagnose problems.
6. Sharing and service providers
We do not sell personal data. We share data only with the service providers needed to run SakaFlow, and only for that purpose:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication for user accounts, connection records and encrypted tokens. |
| Hostinger | Server hosting for the SakaFlow application and its automation engine. |
| Cloudflare | DNS, network proxy and access control in front of the application. |
| Google (YouTube and Drive APIs) | Publishing videos, reading channel details and metrics, and reading media files from folders the agency shares. |
| TikTok | Publishing and reading account details when a TikTok account is connected. |
| AI text providers (configured per deployment, for example Google Gemini, Anthropic or OpenAI) | Generating draft post text from text the agency provides. |
| Messaging providers (Telegram, WhatsApp), if the agency enables them | Sending approval notifications or replies. |
Posts are published to the platforms the account owner connected, which is the purpose of the service. We may also disclose data when the law requires it.
7. Storage and security
- All connections to the dashboard use HTTPS, and access to the dashboard is restricted to authorized users.
- Authorization tokens are encrypted at rest in the database using AES-256-GCM and are used only on the server; they are never shown in the browser.
- Access to each client's data is limited by role and by client, enforced in the application and by database row-level security.
- The publishing engine requests short-lived access tokens from the application and does not store long-lived Google credentials for connected channels.
No system is perfectly secure, and we do not claim any third-party security certification.
8. Retention and deletion
- Disconnecting a YouTube or TikTok account in SakaFlow revokes the authorization with the provider where possible and deletes the stored tokens.
- Content, post history and activity logs are kept while the agency's account is active so the agency can review its work. No fixed automatic deletion period has been set for them yet; you can ask us to delete them (see section 9).
- Automation run logs are removed automatically after a short period (7 days by default).
9. Your choices and rights
- Revoke access: you can remove SakaFlow's access to your Google account at any time at myaccount.google.com/permissions, or by disconnecting the account in SakaFlow.
- Access, correction and deletion: you can ask us what data we hold about you, to correct it, or to delete it by contacting us at the address in section 1. Where the data belongs to an agency's client, we may need the agency to confirm the request.
- Depending on where you live, you may have additional rights under local law, and we will honor them as required.
10. Children
SakaFlow is a business tool and is not directed to children. It is not intended for people under 16.
11. Changes to this policy
We may update this policy. The date at the top shows when it last changed, and we will make material changes visible on this page.