Wireflow is now a Claude connector.

Set it up→

Privacy Policy

Last updated: October 8, 2026

1. Information We Collect

When you use Wireflow, we collect information you provide directly:

  • Account information: Name, email address, and profile picture when you sign in via Google, Discord, or email.
  • Content: Prompts, images, videos, workflows, and other content you create or upload.
  • Payment information: Billing details processed securely through Stripe. We do not store your full card number.
  • Usage data: How you interact with our platform, including features used, workflows created, and models accessed.
  • Connected social accounts: When you connect Instagram, Threads, or another supported platform, we store account identifiers, your username, display name, profile picture URL, granted permissions, and connection status. We store access tokens in encrypted form. For publishing, we also store captions, media URLs, post settings, scheduled times, publishing results, and links to published posts.
  • Facebook Pages: When you connect Facebook, you choose on Facebook's screen which Pages Wireflow may use. For each of those Pages that you can post to, we store the Page name, the Page ID, a Page access token, and the permissions you gave us. The Page token is encrypted. We also store the ID Facebook gives your account for our app, so we know which login a Page came from. We do not store your Facebook user access token. We use it only while you connect, to check which permissions you gave, to get the ID Facebook gives your account for our app, and to get the list of your Pages. Then we drop it. We use each Page token only to post the videos you choose to the Pages you picked, and to check that each video went live. We do not read your Page's other posts, comments, messages, or insights. We ask for four permissions: pages_show_list, pages_read_engagement, and pages_manage_posts, which Facebook requires to post Reels to a Page, and business_management, so Pages owned by a business account show up in your list.
  • Threads: When you connect Threads, we store your Threads user ID, username, name, and profile picture link, plus an encrypted access token. We use the token to post what you choose to your Threads profile.
  • Threads comment auto-reply: If you turn on auto-reply for a post, you pick a keyword and the reply to send, such as a link. Every 10 minutes we read the replies on that post. We only read replies on posts Wireflow published for you that have auto-reply turned on. When a reply has your keyword, we answer it once with the reply you wrote. When Threads tells us who wrote a reply, we answer each person only once per post. When it does not, we answer each matching reply once. We skip replies that are hidden or that you already answered yourself. We do not store the text of the replies we read. So we never answer twice, we keep the reply's ID, our answer's ID, and the person's Threads username when Threads shares it. For this we ask for threads_read_replies, to read the replies, and threads_manage_replies, which lets us post the reply and see how many replies Threads allows.
  • Instagram post insights: When you grant access to insights, we retrieve and store performance snapshots for Instagram posts published through Wireflow. These include available counts for views, reach, likes, comments, shares, saves, and total interactions, plus video watch-time metrics, media type, and publication and snapshot times.

2. How We Use Your Information

  • Provide, maintain, and improve our AI creative tools
  • Process your transactions and manage your account
  • Send you service-related communications
  • Monitor usage to prevent abuse and enforce our terms
  • Analyze trends to improve the platform experience
  • Connect the social accounts you authorize, publish or schedule content you submit, and show publishing status and history
  • Answer keyword replies on your Threads posts, once each, when you turn on auto-reply for a post
  • Show you how your Instagram posts perform over time using the insights you authorize us to retrieve

3. Your Content

You retain ownership of all content you create using Wireflow. We do not use your prompts, images, or generated content to train AI models. Your workflows and outputs are private unless you explicitly choose to share them.

4. Third-Party Services

Wireflow uses third-party services to operate the platform and process your requests, including:

  • FAL.ai, Replicate, and RunPod for AI model inference
  • OpenAI, Anthropic, and Google for language models
  • Amazon Web Services (AWS) for database hosting, storage, and infrastructure, including storage of connected-account data, encrypted access tokens, publishing records, and post insights
  • Vercel for website and API hosting, including processing social account connections and publishing requests
  • Cloudflare R2 for media storage and delivery, including media prepared for Instagram publishing
  • Trigger.dev for background publishing and token refresh jobs. It also retrieves Instagram post insights. These jobs process the account data, access tokens, and post data needed to run them.
  • Stripe for payment processing
  • PostHog for privacy-friendly analytics
  • Meta for Instagram, Threads, and Facebook Page connection and content publishing when you authorize the integration. We send the media, captions, and post settings you choose to the connected platform to publish on your behalf. For Instagram, we also retrieve performance metrics for those posts when you grant access to insights. For Threads posts with auto-reply turned on, we read their replies and post the reply you wrote.
  • Meta (the Meta Pixel and Conversions API) for advertising measurement (see section 7)

Each provider processes data according to their own privacy policies. We only share the minimum data necessary to fulfill your requests.

5. Data Storage and Security

We use the hosting and storage services listed above. Connected social account access tokens are stored encrypted in our database and decrypted server-side when needed to maintain the connection, publish content, or retrieve Instagram post insights. We use encryption in transit (TLS) and at rest. Access to production systems is restricted to authorized personnel only.

6. Data Retention

We retain your account data for as long as your account is active. Generated media is stored until you delete it or close your account. You can request deletion of your account and associated data at any time by contacting us. When your Wireflow account is deleted, after a 30-day recovery window we also delete every connected social account, including its encrypted tokens, its publishing history and post insights, and any Threads auto-reply records.

You can revoke Wireflow's access through the connected-app settings on Instagram, Threads, or Facebook. Revoking access does not itself delete the connection details, publishing history, Threads auto-reply records, or stored Instagram post insights held by Wireflow. To request deletion of that data or your Wireflow account, follow our data deletion instructions. Deleting connection data does not remove your Wireflow workflows, execution records, media files, or posts already published to Instagram, Threads, or Facebook.

7. Cookies and Advertising

We use essential cookies for authentication and session management. We use PostHog for analytics, which uses cookies to understand how visitors use our platform. We also record how people use the app, through PostHog session recording, to find and fix problems. Recordings show what appears on screen, which can include text you entered once it is displayed, such as prompts on your board. Form fields are masked, API keys and invite links are hidden, and we do not record a browser that sends a Global Privacy Control or Do Not Track signal.

We use the Meta Pixel and the Meta Conversions API to measure how well our ads work and to help Meta decide who sees them. The Pixel sets Meta cookies and tells Meta which of our pages you visit and when you submit one of our lead forms. When you submit a lead form, our server can also send that event to Meta with your email address in hashed form, your IP address, your browser's user agent and Meta's click and browser IDs. We do not sell your data to advertisers or data brokers. Our Cookie Policy has the details and your choices.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt out of non-essential communications

9. Children's Privacy

Wireflow is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this privacy policy or your data, contact us at [email protected].