Skip to content

Privacy Policy

What IGFlow collects, why, where it is stored and how it is deleted.

Last updated: 2026-08-24

1. Scope

This policy covers the IGFlow web panel and the backend services behind it. By using the service you agree to the processing described here.

IGFlow is not affiliated with, endorsed by or sponsored by Instagram.

2. What we collect

Account details: your name, email address and an irreversible hash of your password. The password itself is not stored.

Connected Instagram accounts: username, public profile details (name, avatar, follower/following/post counts) and the session data required to keep the account connected.

Your Instagram password is NOT stored. It is used only to sign in; afterwards only session data is kept.

Usage records: the tasks and flows you create, their outcomes and error messages.

Optional proxy settings. The proxy password is stored in Postgres encrypted with AES-256-GCM.

When the realtime connection runs through a SOCKS5 proxy, the password is decrypted and written to the account record so the connecting service can use it. This means the password is recoverable inside the system; we are not hiding that from you.

The panel interface never DISPLAYS the password back to you; it only reports whether one is set.

3. Google account and Google Drive data

Connecting Google Drive is OPTIONAL. It is set up only when you choose to export collected data to your Drive.

The permission requested is the `drive.file` scope. That scope grants access only to files IGFlow itself CREATES; we cannot see, list or read any other file in your Drive.

When connected we store: your Google account email, the access and refresh tokens (encrypted), the token expiry, the granted scope and the id of the root folder IGFlow created.

We use information received from Google solely to perform the export you asked for. We do not use it for advertising, do not sell it to third parties and do not read it with human eyes.

IGFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect at any time from the panel; disconnecting deletes the tokens permanently. You may also revoke access from your Google Account settings.

4. Why we process it

To run the automations you request.

To protect your account: applying rate limits, working hours and block detection.

To enforce your plan's scope and account allowance.

To diagnose errors and operate the service.

5. Sharing

We do not sell your data and do not share it for marketing.

Data only goes where the service needs it: Instagram (for the actions you take through it) and Google Drive if you connected it.

If legally compelled, only the minimum required information is shared.

6. Retention and deletion

Your data is kept while your account is open.

Removing an Instagram account from the panel deletes that account's session data and settings.

Disconnecting Google Drive deletes the tokens; files already created in your Drive are NOT deleted — they are yours.

You can request full deletion of your account through the contact channels.

7. Security

Access is limited to authenticated users and every request is scoped to the owner of the account.

Google tokens and proxy passwords are encrypted with AES-256-GCM in the database. A secret has to be decrypted to be used; for that reason the proxy password is written in decrypted form to the record the connecting service can read (see 'What we collect').

No system is perfectly secure and we cannot guarantee absolute security.

8. Age

The service is not directed at anyone under 18 and we do not knowingly collect their data.

9. Changes

This policy may be updated. Material changes are announced in the panel and the date above changes.

Contact

For questions about this policy, reach us through the channels on the contact page.

Home