Who operates UGCFlow
Adl AI Inc. is responsible for UGCFlow. Privacy and deletion questions can be sent to support@prepiko.ai.
Information we collect
We process account information supplied to UGCFlow, including a user’s name, email address or Telegram identity, role, workspace access, social-account handle, submitted media, captions, review decisions, publication settings, publication status, and operational audit records.
When a user connects a provider, we receive the provider identity and authorization data described below. OAuth access and refresh tokens are sent to the UGCFlow backend and are not exposed to browser JavaScript after the authorization callback.
YouTube
Data requested
Channel identifier, channel name, and metadata or status for videos uploaded through UGCFlow.
youtube.upload · youtube.readonly
Why UGCFlow uses it
Identify the channel selected by the user, upload a user-selected video, and show the resulting publication status.
User control
Every upload starts from an explicit publish action. New review uploads default to Private, and the connection can be removed at any time.
Meta
Data requested
Instagram professional account identifier, username, profile details, and publishing authorization.
instagram_business_basic · instagram_business_content_publish
Why UGCFlow uses it
Show the connected professional account and publish a user-selected video as an Instagram Reel.
User control
The user chooses the content and whether the Reel is shared to the profile feed before publishing.
Threads
Meta
Data requested
Threads account identifier, username, basic profile details, and publishing authorization.
threads_basic · threads_content_publish
Why UGCFlow uses it
Show the connected Threads account and publish a user-selected video thread.
User control
The user initiates each publication and chooses who can reply before the post is queued.
TikTok
TikTok
Data requested
Open ID, display name, username, basic profile details, and Direct Post authorization.
user.info.basic · user.info.profile · video.publish
Why UGCFlow uses it
Identify the selected TikTok account and Direct Post a user-selected video.
User control
The user chooses an account-supported privacy level and interaction settings before each post. UGCFlow does not post in the background without a user action.
How we use provider data
- Identify the social account selected by the user and show that identity inside UGCFlow.
- Publish only content selected and confirmed by the user, with the settings shown before publication.
- Track the operational status of publications created through UGCFlow and show actionable errors.
- Protect the service, prevent duplicate account claims, investigate misuse, and comply with provider policies.
UGCFlow does not sell Google, Meta, or TikTok user data. We do not use it for targeted advertising, data brokerage, credit decisions, or training generalized or non-personalized artificial-intelligence or machine-learning models.
Google and YouTube data
UGCFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The YouTube permissions are used to identify the selected channel, upload a user-selected video, and read channel or uploaded-video information needed to display publication status. UGCFlow does not access watch history, subscriptions, private messages, or unrelated Google products.
How we store and protect information
OAuth credentials are encrypted at rest and access is limited to the backend services that perform authorized provider operations. Creator media is stored in private encrypted object storage. Production traffic uses HTTPS, application workloads run in private network segments, and administrative actions are access-controlled and audited.
No security system can guarantee absolute protection. We review access controls and service configuration as the product changes.
Sharing and service providers
We send information to Google, Meta, or TikTok only when needed to complete the provider action requested by the user. We also use infrastructure providers for hosting, databases, encrypted storage, logging, and service delivery. These providers process information on our behalf and are not permitted to use it for their own advertising.
We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate confidentiality and notice obligations.
Retention and deletion
OAuth credentials are retained while the provider connection is active. Disconnecting a social account in UGCFlow removes its stored OAuth credentials and prevents future publications through that connection. Revoking access at the provider also stops future authorized access.
Account, submitted-content, publication, and audit records are retained while needed to provide the service, resolve disputes, prevent abuse, and meet legal obligations. A user may request broader deletion by following the data deletion instructions. Adl AI Inc. will complete verified requests within 30 days unless specific information must be retained for legal, security, fraud-prevention, or financial-record obligations.
User choices and rights
Users can choose whether to connect a provider, decline an OAuth consent screen, choose which account receives a publication, set available privacy and interaction controls, disconnect a provider, or request deletion. Depending on location, users may also have rights to access, correct, export, object to, or restrict processing of personal information.
Changes to this policy
We will update this page when our data practices materially change. If a change affects how provider data is used, we will update relevant in-product disclosures and provider-review configuration before relying on the new use.