Privacy Policy

Effective date: July 17, 2026 · Last updated: July 17, 2026

1. Who we are

ContentWorkflow ("we", "us", the "Service"), available at contentworkflow.co, is a content-production management tool that lets its users plan video content, publish it to social platforms they connect (YouTube, TikTok, Instagram), and view performance metrics for their own published content. This policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights and choices you have. For any privacy matter, contact us at support@contentworkflow.co.

2. Information we collect

We collect the following categories of information:

  • Account information. When you sign in, we receive your name, email address, and profile picture from your sign-in provider (e.g. Google) or from the email address you register with.
  • Content you create. The material you add to the Service: video and image files you upload, titles, captions, hashtags, scripts, notes, comments, and scheduling information.
  • Connected social account data. When you connect a social account through its official API (e.g. TikTok Login Kit, Google OAuth, Instagram Login), we receive and store: the account's public profile information (display name, username or handle, avatar, bio, verification status), account-level statistics (follower, likes, and video counts), OAuth access and refresh tokens, and the list of permissions you granted.
  • Content performance data. For content you published through the Service or imported into it, we retrieve performance metrics from the connected platform's API (views, likes, comments, shares, watch time) and store them so we can show you analytics over time.
  • Waitlist email. If you join the waitlist on our landing page, we store the email address you submit, used only to contact you about access to the Service.
  • Technical data. Standard server logs (IP address, browser type, timestamps) generated when you use the Service, retained briefly for security and troubleshooting.

We do not collect precise location data, contact lists, or any data from your connected accounts beyond what is listed above and covered by the permissions you approve on each platform's consent screen.

3. How we use your information

We use the information described above solely to:

  • authenticate you and maintain your session;
  • provide the Service's core features: storing and organizing your content, publishing the videos you choose to publish to the accounts you choose, and displaying analytics for your own content;
  • display your connected accounts inside the Service (name, handle, avatar) so you can tell them apart;
  • notify you about publishing results within the Service;
  • secure, maintain, debug, and improve the Service; and
  • comply with legal obligations.

We do not sell or rent your personal information, use it for advertising, profile you for marketing, use your content or your connected-account data to train machine-learning models, or share it with third parties except as described in Section 5.

4. Legal bases for processing

Where data-protection law (such as the GDPR or Quebec's Act respecting the protection of personal information in the private sector) requires a legal basis, we rely on: performance of a contract (providing the Service you signed up for); consent (which you give when connecting a social account and can withdraw at any time by disconnecting it); and legitimate interests (keeping the Service secure and functional).

5. How we share information

We share personal information only with:

  • Infrastructure providers that host the Service and store its data on our behalf under their own security and privacy commitments: Vercel (application hosting and cookieless site analytics), Supabase (database and authentication), and Cloudflare (file storage). They process data only to provide their services to us.
  • The platforms you connect, when you take an action that requires it — e.g. when you publish a video, we transmit that video and its caption to the platform (TikTok, YouTube, or Instagram) through its official API, under the permissions you granted.
  • Authorities, if required by law, court order, or to protect the rights, safety, or property of users or the Service.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Our use of TikTok data complies with TikTok's Developer Terms of Service; TikTok data is used only to provide the features described in this policy and is never sold or transferred to third parties.

6. Data retention

We keep your information for as long as your account is active. When you disconnect a social account, we stop all API access to it and delete its stored access and refresh tokens. When you delete your account or ask us to, we delete your account data — including uploaded files, connected-account data, and stored metrics — within 30 days, except where a longer retention period is required by law. Server logs are retained for a short period (typically under 90 days) for security purposes.

7. Security

All traffic to the Service is encrypted in transit (TLS/HTTPS). OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and are never exposed to the browser. Access to production data is restricted to the Service operator. No method of transmission or storage is 100% secure, but we take industry-standard measures to protect your information and will notify affected users of any breach as required by applicable law.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, export, restrict the processing of, or delete your personal information, and to withdraw consent at any time. You can exercise these rights directly in the Service or by contacting us:

  • Disconnect a social account at any time from the Service's settings — this immediately stops all API access and deletes the stored tokens. You can also revoke access from the platform's own settings (e.g. TikTok → Settings and privacy → Security & permissions → Apps and websites; Google Account → Security → Third-party access).
  • Delete your data. Email support@contentworkflow.co from your account email and we will delete your account data within 30 days and confirm when it is done.
  • Access or export your data. Email us and we will provide a copy of the personal information we hold about you.

If you are in the EEA/UK you may also lodge a complaint with your supervisory authority; in Quebec, with the Commission d'accès à l'information.

9. Children

The Service is not directed to children and may not be used by anyone under 13 years of age (or the higher minimum age required in your jurisdiction). We do not knowingly collect personal information from children; if we learn that we have, we will delete it.

10. International transfers

Our infrastructure providers may store and process data in the United States and other countries. Where required, transfers are protected by appropriate safeguards such as standard contractual clauses implemented by our providers.

11. Cookies and analytics

We set only strictly-necessary cookies, used to keep you signed in. We measure site usage with Vercel Analytics, which is cookieless and aggregates anonymous page-view data — it does not identify you or track you across sites. We use no advertising or cross-site tracking cookies, so no cookie-consent banner is required.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new "last updated" date, and for material changes we will notify you in the Service or by email before they take effect.

13. Contact

The person responsible for the protection of personal information is the operator of the Service. Privacy questions, access requests, or deletion requests: support@contentworkflow.co. We respond within 30 days.