UGCFlow · Adl AI Inc.

Privacy policy

This policy explains how UGCFlow, operated by Adl AI Inc., handles account, content, and social-provider data when creators and teams use the service.

Last updated July 24, 2026

Who operates UGCFlow

Adl AI Inc. is responsible for UGCFlow. Privacy and deletion questions can be sent to support@ugcflow.online.

Information we collect

We process account information supplied to UGCFlow, including a user’s name, email address, role, workspace access, social-account handle, submitted media, captions, review decisions, publication settings, publication status, and operational audit records.

When a user connects a provider, we receive the provider identity and authorization data described below. OAuth access and refresh tokens are sent to the UGCFlow backend and are not exposed to browser JavaScript after the authorization callback.

UGCFlow uses an essential HTTP-only session cookie to keep users signed in and protect authenticated requests. The cookie is not used for advertising or cross-site tracking. UGCFlow does not store Google OAuth credentials in local storage or session storage.

YouTube

Google

Data requested

Channel identifier, channel name, and metadata or status for videos uploaded through UGCFlow.

youtube.upload · youtube.readonly

Why UGCFlow uses it

Identify the channel selected by the user, upload a user-selected video, and show the resulting publication status.

User control

Every upload starts from an explicit publish action. New review uploads default to Private. Disconnecting revokes Google access, deletes stored credentials and channel identity data, and cancels unpublished scheduled videos.

Instagram

Meta

Data requested

Instagram professional account identifier, username, profile details, and publishing authorization.

instagram_business_basic · instagram_business_content_publish

Why UGCFlow uses it

Show the connected professional account and publish a user-selected video as an Instagram Reel.

User control

The user chooses the content and whether the Reel is shared to the profile feed before publishing.

Threads

Meta

Data requested

Threads account identifier, username, basic profile details, and publishing authorization.

threads_basic · threads_content_publish

Why UGCFlow uses it

Show the connected Threads account and publish a user-selected video thread.

User control

The user initiates each publication and chooses who can reply before the post is queued.

TikTok

TikTok

Data requested

Basic account information identifies the connected creator. UGCFlow also uses current creator posting capabilities, Direct Post authorization, and publication status for content sent through UGCFlow.

user.info.basic · video.publish

Why UGCFlow uses it

user.info.basic identifies the connected creator. video.publish loads current creator posting capabilities, sends only approved creator-selected content after explicit consent, and checks publication status.

User control

OAuth tokens are encrypted at rest. Connecting a TikTok account alone never publishes content. Disconnecting removes the stored credential and prevents future publishing.

How we use provider data

  • Identify the social account selected by the user and show that identity inside UGCFlow.
  • Publish only content selected and confirmed by the user, with the settings shown before publication.
  • Track the operational status of publications created through UGCFlow and show actionable errors.
  • Protect the service, prevent duplicate account claims, investigate misuse, and comply with provider policies.

UGCFlow does not sell Google, Meta, or TikTok user data. We do not use it for targeted advertising, data brokerage, credit decisions, or training generalized or non-personalized artificial-intelligence or machine-learning models.

How we use, process, and share user information

UGCFlow uses the information described above for the following purposes:

  • Provide the service: authenticate users, display connected accounts, execute creator-approved publishing actions, and show publication status.
  • Maintain and protect the service: prevent duplicate account claims, detect and investigate misuse, enforce terms of service, and perform security monitoring.
  • Comply with legal obligations: respond to lawful requests, maintain required financial records, and satisfy provider policy requirements.

UGCFlow does not use user information for targeted advertising, data brokerage, credit decisions, user profiling, or training generalized artificial-intelligence or machine-learning models.

Internal sharing

Within Adl AI Inc., access to user information is restricted to:

  • Backend services that perform authorized provider operations (publishing, status checks, token refresh).
  • Authenticated users viewing their own connected accounts and workspace administrators managing team accounts.
  • Engineering and operations personnel who require access to maintain, debug, or secure the service, subject to access controls and audit logging.

External sharing

UGCFlow shares user information with external parties only in the following circumstances:

  • Social platform providers (Google/YouTube, Meta, TikTok): only to execute the specific API calls the user explicitly initiates (for example, uploading a video the user selected or refreshing a token).
  • Infrastructure service providers: hosting, database, encrypted storage, and logging providers that process information on our behalf under contractual obligations that prohibit use of user data for their own purposes.
  • Legal or safety requirements: when required by law, court order, or governmental authority, or when necessary to protect the rights, safety, or property of users or the service.
  • Corporate transactions: in connection with a merger, acquisition, or sale of assets, subject to confidentiality and notice obligations.

No user information is shared with advertisers, data brokers, analytics vendors, or any other third parties beyond those listed above. UGCFlow does not sell user data.

YouTube-specific data handling

When a user connects YouTube, UGCFlow receives the channel ID, channel title, and channel profile image from Google APIs. This information is stored in our database and displayed only to the authenticated user and authorized workspace administrators so they can identify which account is connected. The data is processed solely to enable the user-selected publishing actions described above.

UGCFlow does not combine YouTube data with data from other sources for profiling or cross-site tracking. We do not build user profiles, interest graphs, or audience segments from YouTube API data.

Google and YouTube data

UGCFlow uses YouTube API Services. Its use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google processes information under the Google Privacy Policy.

The YouTube permissions are used to identify the selected channel, upload a user-selected video, and read channel or uploaded-video information needed to display publication status. UGCFlow does not access watch history, subscriptions, private messages, or unrelated Google products.

Users can also review or revoke UGCFlow’s Google access from Google’s connected-app permissions.

TikTok data and Direct Post

UGCFlow requests only user.info.basic and video.publish. Basic account information identifies the connected creator. The publishing permission loads that creator’s current posting capabilities, sends only approved creator-selected content after the creator reviews the exact video and gives explicit consent, and checks the resulting publication status.

Connecting TikTok alone never publishes content. UGCFlow encrypts TikTok OAuth tokens at rest, and disconnecting TikTok removes the stored credential and prevents future publishing. Creator-selected content is sent only through the explicit Direct Post flow.

How we store and protect information

OAuth credentials are encrypted at rest and access is limited to the backend services that perform authorized provider operations. Creator media is stored in private encrypted object storage. Production traffic uses HTTPS, application workloads run in private network segments, and administrative actions are access-controlled and audited.

No security system can guarantee absolute protection. We review access controls and service configuration as the product changes.

Sharing and service providers

We send information to Google, Meta, or TikTok only when needed to complete the provider action requested by the user. We also use infrastructure providers for hosting, databases, encrypted storage, logging, and service delivery. These providers process information on our behalf and are not permitted to use it for their own advertising.

We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate confidentiality and notice obligations.

API data refresh, update, and deletion

YouTube API data is fetched from Google only when needed to complete a user-initiated action:

  • Connection time: Channel identity (channel ID, title, profile image) is fetched once when the user connects their account and is stored until the account is disconnected.
  • Publication status: Video upload and processing status is queried periodically while a video is being published (typically every 20–30 seconds during processing), then never again once the video reaches a terminal state (published or failed).
  • Token refresh: OAuth access tokens are refreshed automatically when they are within 5 minutes of expiry. Refresh tokens are never used or transmitted except during this automatic refresh operation.
  • Disconnect: When a user disconnects YouTube, UGCFlow immediately requests token revocation from Google, then deletes the stored access token, refresh token, channel identity data, and channel profile image from UGCFlow systems. Channel identity data is not cached or retained after disconnection.

No YouTube API data is refreshed or updated on a fixed recurring schedule. Data is fetched only in response to explicit user actions and is deleted immediately upon disconnect.

Retention and deletion

OAuth credentials are retained only while the provider connection is active. When a user disconnects YouTube in UGCFlow, the backend first requests revocation from Google, then deletes the stored access and refresh tokens and authorized channel identity data, cancels unpublished scheduled publications for that channel, and prevents future authorized access. This deletion occurs immediately after successful revocation.

Users may also revoke UGCFlow directly from Google’s connected-app permissions. Provider-side revocation prevents future API access. Users can then use UGCFlow’s data deletion instructions or contact support@ugcflow.online to remove associated UGCFlow records.

Account, submitted-content, publication, and audit records are retained while needed to provide the service, resolve disputes, prevent abuse, and meet legal obligations. A user may request broader deletion by following the data deletion instructions. Adl AI Inc. will complete verified requests within 30 days unless specific information must be retained for legal, security, fraud-prevention, or financial-record obligations.

User choices and rights

Users can choose whether to connect a provider, decline an OAuth consent screen, choose which account receives a publication, set available privacy and interaction controls, disconnect a provider, or request deletion. Depending on location, users may also have rights to access, correct, export, object to, or restrict processing of personal information.

Changes to this policy

We will update this page when our data practices materially change. If a change affects how provider data is used, we will update relevant in-product disclosures and provider-review configuration before relying on the new use.