Kraflio

Privacy Policy

Last updated: July 2026

1. What Data We Collect

  • Account information: Email address (required for sign-up)
  • Generated content: Topics you provide and the posts and scripts we generate for you for LinkedIn, X, Instagram, Bluesky, YouTube, and TikTok
  • Voice samples: Posts you paste to train your voice profile
  • Usage metrics: Post count, features used, generation timestamps
  • Connected social account data: For accounts you link (LinkedIn, Instagram, X, Bluesky), an OAuth access token, your account identifiers (such as your Instagram user ID and username), and the performance metrics of your own published posts (for example likes, comment counts, shares, saves, and views)
  • Payment information: Processed by Razorpay - we do not store card numbers

2. What We Do NOT Collect

  • Your social platform account passwords (except encrypted Bluesky app passwords, which you provide to enable publishing and can revoke in your Bluesky account at any time)
  • Browsing history
  • Personal messages or contacts
  • Location data (beyond country-level for payment routing)

3. Where Data Is Stored

Your data is stored on Supabase (hosted on AWS, us-east-1 region). API processing runs on Cloudflare Workers (global edge network). All connections use TLS encryption.

4. AI Processing

Your topics and voice samples are sent to Anthropic (Claude) and OpenAI APIs solely for content generation and voice analysis. These providers process data according to their enterprise API terms - your data is not used for model training.

5. Data Sharing

We do not sell, share, or provide your data to any third parties for advertising or marketing purposes. Data is only shared with:

  • AI providers (Anthropic, OpenAI) for generation - under their API terms
  • Payment processor (Razorpay) for billing
  • Infrastructure providers (Supabase, Cloudflare) for hosting

6. Data Retention & Deletion

Your data is retained while your account is active. When you delete your account, your login is disabled immediately and your content is no longer visible in Kraflio. We retain account records for up to 24 months for legal and business purposes, after which they are erased. To request earlier erasure where legally permitted, email privacy@kraflio.com. This complies with GDPR, India's DPDP Act, and Apple/Google app store requirements.

Platform Data obtained from connected social accounts (for example Instagram/Meta access tokens, account identifiers, and post metrics) is an exception to the 24-month record-retention period above: it is deleted promptly when you disconnect the account or delete your Kraflio account, in line with the Meta Platform Terms.

To request account deletion, use the in-app account deletion feature or email support@kraflio.com.

7. Cookies

We use a single authentication token stored in localStorage to keep you signed in. We do not use tracking cookies, analytics cookies, or advertising cookies.

8. Your Rights

You have the right to:

  • Access your data (available in-app)
  • Export your generated posts
  • Delete your account and all associated data
  • Withdraw consent for data processing

9. Connected Accounts and Platform Data (LinkedIn, Instagram, X, Bluesky)

Kraflio connects to the social accounts and Company Pages you choose to link, using each platform's official authorization (OAuth). We store an access token for each connected account so we can publish on your behalf. We do not store your social platform passwords.

For LinkedIn specifically:

  • When you connect a personal LinkedIn profile, or a LinkedIn Company Page you administer, you grant Kraflio permission to publish posts that you have approved.
  • For a connected Company Page, Kraflio can also retrieve that page's post performance (impressions, reactions, comments, and shares) and show it to you as aggregate per-post numbers. Kraflio does not collect or display the profiles or personal details of individual members who engage with your posts.
  • Nothing is published without your explicit approval.

For Instagram (Meta) specifically:

  • Kraflio connects to your own Instagram professional (Business or Creator) account using Instagram's official login (OAuth). We do not use Facebook Login and do not access any Facebook Page.
  • We store your Instagram account's user ID and username to identify the connection, and an encrypted access token so we can publish on your behalf.
  • Using the instagram_business_content_publish permission, Kraflio publishes only the posts you have reviewed and approved, and only to your own connected account. Nothing is published without your explicit approval.
  • Using the instagram_business_manage_insights permission, Kraflio retrieves the performance of your own published posts (likes, comment counts, shares, saves, and views) and shows it to you in your analytics dashboard. Kraflio does not read the text of comments or messages, and does not access other people's accounts or profiles.
  • Your use of Kraflio's Instagram features is also governed by the Meta Platform Terms.

Disconnecting and deletion: You can disconnect any linked account inside Kraflio at any time. You can also revoke Kraflio's access directly from the platform: for LinkedIn, in Settings, then Data privacy, then Permitted services; for Instagram, in the Instagram app under Settings and privacy, then Apps and websites. When you disconnect an account or delete your Kraflio account, the stored access token and the data retrieved from that account (including Instagram/Meta identifiers and post metrics) are deleted immediately and are not subject to the 24-month record-retention period. To request data deletion, use the in-app account deletion feature, follow the instructions at kraflio.com/delete-account, or email privacy@kraflio.com.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.

11. Contact

Questions about this privacy policy? Email us at support@kraflio.com.