Trust Center

Privacy Policy

Privacy & Safety

How Flozari handles your data.

This page explains what information we collect, why we collect it, how we protect it, and what rights you have when you use Flozari.

Last updated
July 23, 2026

Overview

Flozari ("we", "us", "our") is an Instagram and Facebook automation platform that helps users manage automated replies, comments, direct messages, and lead capture workflows. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Types of Data Collected

We collect the following categories of data:

  • Account Data: Email address, name, and authentication details when you create or use an account.
  • Instagram and Facebook Data: Usernames, account IDs, page IDs, and access tokens when you connect supported accounts.
  • Usage Data: Automation rules, activity logs, message flow events, feature usage, and related service interactions.
  • Device Data: Browser type, operating system, and device identifiers collected automatically for security and performance.

How We Use Your Data

Your information is used to operate and improve Flozari, including to:

  • Provide and maintain our automation services.
  • Execute rules you create, including comment replies, DM automation, and lead workflows.
  • Authenticate your identity and secure your account.
  • Communicate important updates, product notices, and support responses.
  • Monitor product quality, reliability, and performance.

Instagram & Facebook Permissions

When you connect your Instagram account or Facebook Page, Flozari requests only the permissions required to deliver supported automation features through the Meta platform.

  • instagram_basic: To read basic Instagram account profile information.
  • instagram_manage_comments: To read and respond to comments on your behalf.
  • instagram_manage_messages: To send and receive direct messages through configured workflows.
  • pages_manage_metadata: To subscribe to webhooks for real-time event delivery.
  • pages_show_list: To display Pages that you manage.

We publish content only when you create or schedule it through Flozari. We do not modify your profile, publish without your instruction, or access data beyond what is necessary to provide the features you choose to use.

Data Storage & Security

Your data is stored using industry-standard security controls. Access tokens are encrypted at rest, access is restricted, and row-level data protections are used where supported so users can access only their own records. We do not sell, trade, or rent your personal information.

Legal Basis for Processing (GDPR / UK GDPR)

If you are located in the EEA or United Kingdom, we rely on the following legal bases:

  • Contract — to deliver the Flozari service you signed up for (account, automations, message delivery).
  • Legitimate interest — to keep the service secure, prevent abuse, and improve features (logged activity, rate limits).
  • Consent — for optional integrations (Google, Meta, Kit, Mailchimp, Shopify) that you explicitly connect. You can withdraw consent at any time by disconnecting in Settings.
  • Legal obligation — to comply with tax, accounting, and lawful requests from authorities.

International Data Transfers

Flozari is operated globally. Personal data may be transferred to and processed in the United States and other countries where our third-party service providers operate. We rely on Standard Contractual Clauses (SCCs) and equivalent transfer mechanisms put in place by our third-party service providers to protect your data. A current list of third-party services is published at /legal/third-party-services.

Data Retention

We keep different categories of data for different periods:

  • Account & profile data — for the life of your account.
  • Automations, flows, scheduled posts — for the life of your account.
  • Inbox conversations & messages — for the life of your account, subject to Meta's own retention windows.
  • Activity logs — automatically purged after 90 days.
  • OAuth tokens — until you disconnect the integration, then deleted within 7 days.
  • Support tickets & billing records — up to 7 years where required for legal or tax purposes.

When you delete your account, associated data is removed within 30 days except where retention is required by law.

Meta Platform Data (Instagram & Facebook)

When you connect an Instagram or Facebook account, Flozari receives the following data from Meta under your authorization:

  • Your Instagram username, user id, profile picture, biography, and follower count.
  • Your Facebook Page id and Page access token (used to send messages and replies on your behalf).
  • Direct messages and comments sent to your connected accounts (sender id, content, timestamps).
  • Media metadata for posts and stories referenced by your automations (post id, caption, permalink).

This data is used exclusively to operate the automations and inbox features you configure. It is never sold, shared with advertisers, or used to train third-party models.

Revoking access: you can disconnect any account from Settings → Connected Accounts, or revoke Flozari entirely from Meta Settings → Business Integrations. When Meta notifies us of a removal, we clear stored tokens and mark the connection as deauthorized within seconds. For full data deletion, Meta forwards your request to our Data Deletion endpoint and you can track the status at /legal/meta-deletion-status. See also our Meta Data Usage page for a plain-language summary.

Your Rights (GDPR, UK GDPR, DPDP Act, CCPA)

Depending on where you live, you may have the right to:

  • Access and portability — download a copy of your data from Settings → Security → Download my data.
  • Correction — update inaccurate information directly in your profile.
  • Erasure — delete your account and associated data from Settings → Security → Delete account.
  • Withdraw consent — disconnect linked Instagram, Facebook, Google, or other integrations at any time.
  • Object or restrict — contact us to object to processing based on legitimate interest.
  • Non-discrimination (CCPA) — we will not deny service or charge a different price for exercising your privacy rights.
  • Lodge a complaint — with your local supervisory authority (e.g. ICO in the UK, your state DPA in the EU, DPB in India).

For requests you cannot complete in the app, email support@flozari.com and we will respond within 30 days.

Third-Party Services

Flozari integrates with third-party providers including:

  • Meta / Facebook APIs: For account connection, permissions, and webhook delivery.
  • Authentication providers: For secure sign-up and login.

Each third-party service operates under its own policies, and we encourage you to review them directly.

Cookies & Local Storage

Flozari uses essential cookies and local storage for authentication, session continuity, and basic product functionality. We do not use third-party advertising cookies within the app experience.

You can review or change your cookie choices at any time.

Children's Privacy

Flozari is not directed at children. We do not knowingly collect personal data from anyone under 13 years old (or under 16 in the European Economic Area, where local law requires a higher age). If you believe a child has provided us with personal data, contact support@flozari.com and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page along with a revised last updated date. Continued use of Flozari after changes are published constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at support@flozari.com.