Privacy Policy
What IGFlow collects, why, where it is stored and how it is deleted.
Last updated: 2026-08-24
1. Scope
This policy covers the IGFlow web panel and the backend services behind it. By using the service you agree to the processing described here.
IGFlow is not affiliated with, endorsed by or sponsored by Instagram.
2. What we collect
Account details: your name, email address and an irreversible hash of your password. The password itself is not stored.
Connected Instagram accounts: username, public profile details (name, avatar, follower/following/post counts) and the session data required to keep the account connected.
Your Instagram password is NOT stored. It is used only to sign in; afterwards only session data is kept.
Usage records: the tasks and flows you create, their outcomes and error messages.
Optional proxy settings. The proxy password is stored in Postgres encrypted with AES-256-GCM.
When the realtime connection runs through a SOCKS5 proxy, the password is decrypted and written to the account record so the connecting service can use it. This means the password is recoverable inside the system; we are not hiding that from you.
The panel interface never DISPLAYS the password back to you; it only reports whether one is set.
3. Google account and Google Drive data
Connecting Google Drive is OPTIONAL. It is set up only when you choose to export collected data to your Drive.
The permission requested is the `drive.file` scope. That scope grants access only to files IGFlow itself CREATES; we cannot see, list or read any other file in your Drive.
When connected we store: your Google account email, the access and refresh tokens (encrypted), the token expiry, the granted scope and the id of the root folder IGFlow created.
We use information received from Google solely to perform the export you asked for. We do not use it for advertising, do not sell it to third parties and do not read it with human eyes.
IGFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from the panel; disconnecting deletes the tokens permanently. You may also revoke access from your Google Account settings.
4. Why we process it
To run the automations you request.
To protect your account: applying rate limits, working hours and block detection.
To enforce your plan's scope and account allowance.
To diagnose errors and operate the service.
6. Retention and deletion
Your data is kept while your account is open.
Removing an Instagram account from the panel deletes that account's session data and settings.
Disconnecting Google Drive deletes the tokens; files already created in your Drive are NOT deleted — they are yours.
You can request full deletion of your account through the contact channels.
7. Security
Access is limited to authenticated users and every request is scoped to the owner of the account.
Google tokens and proxy passwords are encrypted with AES-256-GCM in the database. A secret has to be decrypted to be used; for that reason the proxy password is written in decrypted form to the record the connecting service can read (see 'What we collect').
No system is perfectly secure and we cannot guarantee absolute security.
8. Age
The service is not directed at anyone under 18 and we do not knowingly collect their data.
9. Changes
This policy may be updated. Material changes are announced in the panel and the date above changes.
Contact
For questions about this policy, reach us through the channels on the contact page.

