Flurra Privacy Policy
How Flurra protects connected account data.
Connected Instagram, TikTok, and YouTube accounts
Flurra lets users connect Instagram, TikTok, and YouTube through each platform's authorization screen. We only read social account data after the user signs in to the platform and authorizes Flurra.
- Instagram, TikTok, and Google/YouTube access tokens are exchanged server-side.
- Access and refresh tokens are encrypted before they are stored in Flurra's backend database.
- Tokens are never stored in localStorage and are never exposed in client-side API responses or browser state.
Data Flurra reads
After authorization, Flurra may read profile information, posts or videos, and available analytics or insight metrics needed to show creator performance and AI content recommendations.
Platform data access depends on the scopes approved by Instagram, Meta, TikTok, Google, and the user. If a scope is unavailable, Flurra shows a limited-data state instead of treating the account as failed.
YouTube API Services and Google user data
Flurra uses YouTube API Services. By connecting a YouTube account, you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
Flurra requests read-only access to YouTube data (the youtube.readonly and yt-analytics.readonly scopes). With that authorization, Flurra reads your channel profile, your recent videos, and their performance analytics — including view, like, and comment counts and audience retention curves — and stores them in Flurra's backend database to power your dashboards and content insights. Stored YouTube data is refreshed on an ongoing basis (retention analytics typically weekly, and in all cases at least every 30 days) so it stays consistent with what YouTube reports.
Flurra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Flurra does not:
- use Google user data for serving personalized or targeted advertising;
- sell Google user data, or transfer it to data brokers, advertising platforms, or other information resellers;
- use Google user data to train, develop, or improve generalized or non-personalized AI or machine-learning models;
- use Google user data for determining credit-worthiness or for lending purposes; or
- allow humans to read Google user data, except with your affirmative consent for specific data, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymized and used for internal operations.
Any AI processing of Google user data is performed solely to provide or improve the specific user-facing Flurra features you request, and only by data processors bound to those same Limited Use restrictions.
Disconnecting YouTube from Flurra settings revokes Flurra's Google authorization and deletes the stored connection, tokens, and the YouTube Analytics data Flurra captured through the API. You can also revoke Flurra's access at any time from your Google security settings. If you delete your Flurra account, stored Google user data is deleted with it — Flurra does not retain YouTube data after the connection or account it belongs to is gone, except where retention is required by law.
How Flurra protects your data
Flurra treats connected-account data — including the Google user data it obtains through YouTube API Services — as sensitive, and protects it with the safeguards below.
- Encryption in transit. All traffic between your browser or the Flurra app and Flurra's servers, and between Flurra and Google's APIs, is encrypted with TLS 1.2 or higher. Flurra sends an HTTP Strict Transport Security header on every response, so browsers refuse to reach Flurra over plain HTTP.
- Encryption at rest. Flurra's database and its backups are encrypted at rest by its managed hosting providers. On top of that, every Google OAuth access and refresh token is individually encrypted with AES-256-GCM authenticated encryption before it is written to the database, using a key held only in Flurra's server environment and never stored beside the data it protects.
- Credentials never reach the client. The OAuth code exchange, token refresh, and every YouTube Data API and YouTube Analytics API call run server-side. Access and refresh tokens are never returned in API responses, never written to browser storage, cookies, or device storage, and never written to application logs or error reports.
- Authenticated, per-account authorization. Flurra accounts are authenticated through a managed identity provider (Clerk) that supports email verification and multi-factor authentication. Every request for connected-account data is authorized on the server and scoped to the signed-in user's own account and workspace, so one user cannot read another user's Google data.
- Protected authorization flow. The authorization request Flurra sends to Google carries a signed, expiring HMAC-SHA-256
statevalue that is bound to an httpOnly, SameSite cookie and compared in constant time when Google returns, so a third party cannot attach a YouTube channel to a Flurra account it does not own. - Least privilege. Flurra requests only the read-only
youtube.readonlyandyt-analytics.readonlyscopes. It holds no upload, editing, or channel-management access and is technically unable to post, modify, or delete anything on your channel. - Restricted internal access. Production credentials, environment secrets, and database access are limited to the small number of authorized personnel who need them to operate the service, and are held in managed secret stores rather than in source control. Staff do not read Google user data except with your affirmative consent, to investigate abuse or a security incident, or where required by law. Access is reviewed and credentials are rotated when personnel or providers change.
- No onward exposure. Google user data is excluded from Flurra's product analytics and error-monitoring events, is never sold or transferred to data brokers or advertising platforms, and is disclosed only to the AI processors named below, which are contractually bound to the same Limited Use restrictions and may use it solely to deliver the feature you asked for.
- Bounded retention and deletion. Flurra stores only the YouTube data needed for the features described above, keeps it refreshed against YouTube, and deletes it — together with the stored tokens — when you disconnect YouTube or delete your Flurra account.
- Incident response. If Flurra becomes aware of a security incident affecting Google user data, it will investigate, revoke and rotate the affected credentials, delete or restore affected data as appropriate, and notify affected users and any applicable regulator without undue delay. Security concerns can be reported to support@flurra.io.
Disconnecting and deletion
Users can disconnect Instagram, TikTok, or YouTube from Flurra settings. Disconnecting removes Flurra's stored connection for that platform and prevents future syncs unless the user reconnects.
Users can also request deletion of connected account data by emailing support@flurra.io. See the dedicated data deletion instructions for details.
How data is used
Flurra uses authorized social data to populate dashboards, summarize performance by platform, show top posts, and generate contextual content insights for the user. Flurra does not sell connected account tokens or use connected account data to post content on the user's behalf.
To generate insights, Flurra may process authorized account data with AI service providers — currently Anthropic (Claude), Google (Gemini), and OpenAI — acting as data processors on Flurra's behalf. These providers process the data only to deliver the requested analysis and are not permitted to use it for their own purposes, including model training.
Contact
Questions or deletion requests can be sent to support@flurra.io.