Back

Privacy Policy for AriaFlow.ai

Privacy Policy for AriaFlow

Last Updated: July 16, 2026

1. Introduction

Welcome to AriaFlow (https://ariaflow.ai). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services to create and edit viral faceless videos.

2. Information We Collect

We collect the following personal information:

  • Name
  • Email address
  • Payment information
  • Google account information (when you sign in with Google)
  • Content and files you upload or create using our services
  • Connected social media account information, such as account IDs, usernames, display names, profile images, channel names, permissions granted, token expiration dates, and publishing status when you connect YouTube, TikTok, Instagram/Meta, or X accounts
  • Publishing metadata, such as video titles, captions, descriptions, hashtags, scheduled publishing times, destination platforms, publish result IDs, and error messages needed to operate and troubleshoot publishing workflows

We also collect non-personal data through web cookies and usage analytics.

3. How We Use Your Information

We use the collected information for:

  • Order processing purposes
  • Providing video creation and editing services
  • Account management and authentication
  • Connecting social media accounts that you authorize
  • Publishing user-approved or user-scheduled videos to connected social media accounts
  • Displaying publishing status, account connection status, and publish history in your dashboard
  • Maintaining secure access tokens and refreshing them when necessary to complete publishing tasks you initiate
  • Customer support
  • Service improvement and analytics

4. Social Platform API Data Usage

AriaFlow integrates with third-party platform APIs only after you explicitly authorize the connection through the platform's official authorization flow. We use platform data only to provide account connection, video publishing, scheduling, status tracking, troubleshooting, and related features that you request.

We do not sell platform data, use platform data for advertising profiles, use it to train AI models, or transfer it to unrelated third parties. We do not publish to your connected social accounts unless you create, approve, upload, schedule, or otherwise initiate the publishing workflow in AriaFlow.

Google API and YouTube Data Usage

AriaFlow uses YouTube API Services to enable users to upload videos and manage YouTube content directly from our platform. By using our integration with YouTube, you agree to be bound by the YouTube Terms of Service and the Google Privacy Policy.

When you connect your Google account, we may access:

  • Basic profile information (e.g., name, email)
  • YouTube account and channel metadata
  • Video management permissions (only when explicitly authorized by you)
  • OAuth access tokens, refresh tokens, scopes, and token expiration data needed to complete uploads and refresh authorized access
  • Upload metadata, such as video title, description, tags, privacy status, upload status, and the YouTube video ID returned after publishing

Important: We use this data solely for the purpose of providing video upload, thumbnail setting, metadata editing, account display, scheduling, and publish status functionality. We retain only the metadata and tokens needed to provide these user-requested features and to support queued or scheduled tasks.

You may revoke AriaFlow's access to your YouTube data at any time via your Google Account settings: https://myaccount.google.com/permissions

You can also revoke AriaFlow.ai's access to your YouTube data at any time via the Google security settings page: https://security.google.com/settings/

Data Storage Policy: We store only the platform metadata, OAuth credentials, generated content, and publishing records needed to provide the service, maintain dashboard history, troubleshoot failures, and complete scheduled publishing. Users may request deletion via support@ariaflow.ai.

TikTok Data Usage

When you connect a TikTok account, AriaFlow may access and store TikTok account identifiers and profile metadata, including open ID, union ID when provided, display name, username, avatar URL, OAuth access tokens, refresh tokens, token expiration data, permissions granted, and publish status data. We use this information to show the connected TikTok account in your dashboard, associate the account with your workflows, upload or publish videos you approve, refresh authorized access, and display publish results.

AriaFlow sends video files, captions, privacy settings, disclosure settings, and related publishing metadata to TikTok only when needed to complete a TikTok publishing task you initiate or schedule.

You may revoke AriaFlow's TikTok access from your TikTok account settings or disconnect the account in AriaFlow. After revocation or disconnection, we stop using the token for new publishing tasks and delete stored TikTok credentials on request.

Instagram and Meta Data Usage

When you connect an Instagram professional account through Meta's official authorization flow, AriaFlow may receive and store the Instagram professional account ID, username or display name, profile image when available, account type or professional account metadata when provided, permissions granted, OAuth access token and expiration data, connection status, media container IDs, Instagram media IDs or permalinks, captions, hashtags, scheduled publishing times, publish status, and error messages returned by Meta APIs. AriaFlow does not receive or store your Instagram or Facebook password.

We use Instagram and Meta data only to identify and display your connected account, link it to the workflows you select, create media containers for videos you approve, publish user-approved or scheduled videos to your Instagram professional account, verify publish status, retry eligible failed tasks, maintain publish history, refresh or maintain authorized access where supported, and troubleshoot publishing issues.

Depending on the connection method made available by Meta, AriaFlow requests only the account-identification and content-publishing permissions required for these features, such as instagram_business_basic and instagram_business_content_publish, or their applicable Facebook Login for Business equivalents.

AriaFlow does not use Instagram or Meta data to read unrelated Instagram content, access private messages, manage comments, obtain follower lists for profiling, build advertising audiences, sell user data, profile users for advertising, or train AI models. We request only the permissions needed for account identification and content publishing.

You may remove the connected account in AriaFlow or revoke AriaFlow's access through your Meta or Instagram settings. Removing or revoking access prevents AriaFlow from using that authorization for new publishing tasks. You may request deletion of the associated stored Instagram credentials and platform metadata as described in Section 6. Content already published to Instagram remains on Instagram until you delete it there. Meta and Instagram process information on their services under their own terms and policies, including the Meta Privacy Policy, the Instagram Terms of Use, and the Meta Platform Terms.

X Data Usage

When you connect an X account through X's official OAuth authorization flow, AriaFlow may receive and store your X user ID, display name, username, profile image when available, granted scopes, OAuth access token, refresh token, token expiration data, and connection status. We also process the videos, Post text, hashtags, selected account, scheduled publishing time, media IDs, Post IDs or URLs, publish status, and API error messages needed to complete and troubleshoot publishing tasks. AriaFlow does not receive or store your X password.

We use X data and OAuth credentials only to display and manage the account you connected, link it to workflows you select, upload media, publish the content you approve or schedule, refresh authorized access, show publish results and history, prevent duplicate publishing, retry eligible failed tasks, and provide support. The offline.access permission allows AriaFlow to refresh authorization so that scheduled publishing can continue without asking you to sign in again for every task.

AriaFlow requests only the X OAuth scopes needed for these features: tweet.read, users.read, tweet.write, media.write, and offline.access.

AriaFlow does not use the X integration to read or store your Direct Messages, manage follows or likes, read unrelated timelines, infer sensitive characteristics, build advertising profiles, sell X data, or train AI models. We do not use your authorization to publish content other than content you have approved or scheduled through AriaFlow.

You may remove the connected X account in AriaFlow or revoke AriaFlow's access in the Apps and sessions section of X. Removing or revoking access prevents new publishing through that authorization. You may request deletion of the associated stored X credentials and platform metadata as described in Section 6. Posts already published to X remain on X until you delete them there. X processes information on its service under the X Privacy Policy and X Terms of Service.

5. Data Protection and Security

Security Measures

  • All communication uses SSL/TLS encryption
  • Encrypted database storage with strict access control
  • Multi-factor authentication for admin accounts
  • Periodic security audits and reviews

Social Platform API Data Protection

  • API keys and OAuth tokens are securely stored and access is restricted
  • We request only the minimum necessary scopes
  • All API traffic is encrypted over HTTPS
  • Social platform data is stored only where needed to provide account connection, publishing, scheduling, and support functionality
  • Access to social platform credentials is limited to systems and personnel that need it to operate or support the service

Data Breach Response

In the unlikely event of a data breach:

  • We notify users within 72 hours
  • We follow all applicable legal and regulatory procedures

6. Data Retention and Deletion

  • Connected platform data is retained only as long as necessary to provide account connection, publishing, scheduling, support, security, legal compliance, and dashboard history.
  • OAuth tokens are retained while the account remains connected or while a queued task requires authorized access.
  • Generated videos are retained according to our storage policy and may be deleted after the retention period stated in our Terms of Service.
  • Cached platform metadata is cleared automatically within 30 days when no longer needed.
  • Users can revoke Google access via Google's security settings, revoke TikTok access in TikTok account settings, revoke Instagram/Meta access in Meta or Instagram settings, or revoke X access in X Apps and sessions.

Deletion Requests

Users may request deletion of their entire account or specific types of data by:

  • Removing a connected social account from the Social Accounts page to delete its stored connection from AriaFlow
  • Contacting us at: support@ariaflow.ai

Verified deletion requests are processed within 30 days. Google, YouTube, TikTok, Instagram/Meta, and X API data is deleted upon request, when no longer needed, or when required by the relevant platform's developer policies.

Disconnecting a social account prevents new publishing tasks from using that platform account. If a deletion request is submitted, we delete stored OAuth credentials, account identifiers, and platform metadata unless we must retain limited records for security, fraud prevention, legal compliance, accounting, or dispute resolution.

7. Data Sharing

We do not sell or rent personal data, Google/YouTube data, TikTok data, Instagram/Meta data, or X data. We share or transmit data only in the following limited circumstances:

  • With the destination platform you selected, such as YouTube, TikTok, Instagram/Meta, or X, to complete user-requested account connection or publishing actions
  • When required by law
  • With your explicit consent
  • With infrastructure partners under confidentiality and security agreements

Infrastructure partners may process data only to host, secure, monitor, store, deliver, or support AriaFlow. They are not permitted to use social platform data for their own advertising, resale, or independent profiling.

8. Cookies

Essential cookies support authentication, security, and core product functions. Optional analytics are disabled by default and are loaded only after you consent.

If allowed, Google Analytics, Plausible, and Microsoft Clarity may measure activity on public marketing pages. AriaFlow does not send email addresses, scripts, video titles, OAuth parameters, or Dashboard content in analytics events. You can reject analytics or withdraw consent at any time through Cookie settings on a public marketing page.

9. Children's Privacy

We do not knowingly collect data from individuals under 13 years of age.

10. International Data Transfers

Data may be transferred outside your country and handled under strict compliance safeguards.

11. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access, correct, or delete your data
  • Restrict or object to certain processing
  • Port your data to another provider

12. Updates to This Privacy Policy

We will notify you by email of any material changes to this Privacy Policy and update the effective date above.

13. Contact Us

If you have any questions or requests regarding this policy or your data rights, please contact:

Thank you for trusting AriaFlow with your personal information.