Legal

Privacy Policy

This policy explains what personal data MakerFlow collects, why, who processes it for us and what you can do about it. We have tried to say what the product actually does, in plain language.

Last updated: 3 October 2026

Who we are

MakerFlow is a workspace for creators: content planning, analytics from the social accounts you connect, AI assistance, and a public creator profile and directory. MakerFlow is an unregistered sole proprietorship operated by Prateek Singh, based in Lucknow, Uttar Pradesh, India (“MakerFlow”, “we”, “us”).

For the personal data of people who hold an account with us, we are the “Data Fiduciary” under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). For the business records you enter about other people (for example a brand contact in a deal), you decide what to store, and we process it on your behalf.

This policy covers: creators who use MakerFlow; people who visit a creator’s public profile or the creator directory; brands who send an enquiry to a creator; and people who comment on a creator’s blog post.

Data we collect

When you create an account

  • Your name and email address, and either a password or your Google account identifier if you sign in with Google. Passwords are stored only as a one-way hash, never in readable form.
  • Technical account records: whether your email is verified, sign-in times, and session tokens (stored hashed).
  • Emails we send you about your account (verification, password reset, invitations).

What you put into your workspace

  • Your creator profile: display name, bio, niche, target audience, location, languages, goals, brand voice and posting targets.
  • Content you create or import: ideas, scripts, plans and library items.
  • Video uploads for publishing are not enabled yet. If they are enabled, the uploaded files are stored with the object-storage provider described below.
  • Business records you choose to keep, such as brand deals, invoices and contracts. These can contain names and contact details of other people. Please only enter details you are entitled to store.
  • If you use the newsletter feature: your subscriber list (email address, optional name, subscription status and where each person came from) and the issues you send. You are responsible for having the right to email the people on your list.
  • If you publish a public profile, media kit, link page or blog: the content, handle, rate card and self-reported audience details you choose to make public. Public pages can be read by anyone and indexed by search engines.

From people who interact with public pages

  • Brand enquiries: the name, email address and message a brand submits on a creator’s enquiry form. These are delivered into that creator’s workspace as a brand-deal record, where the creator can see them.
  • Blog comments: the name, email address and comment a visitor submits. The email address is stored but not shown publicly.
  • Profile visits: for a creator’s analytics we record the referring site, device type, a coarse country when our hosting provides one, and a one-way hash (made from the day, IP address and browser details) to avoid counting the same visitor twice in a day. We do not store the IP address in this analytics record.
  • Server logs: our servers log each request’s method, address, time and the IP address it came from, for security and debugging.

Billing

Paid plans are not yet open for purchase. When they are, payment will be handled by a payment provider and we will not store your card details. We keep your plan, subscription status and invoice records (amount, currency, dates and a link to the invoice).

Connected social accounts

We read data from YouTube, Instagram, LinkedIn and X only if you choose to connect that account and approve the permissions on the platform’s own consent screen. What we ask for:

PlatformWhat we request
YouTubeView your channel (read-only) and its analytics (read-only). If you choose to publish a video from MakerFlow, permission to upload videos to your channel.
InstagramBasic profile information and account insights for a professional account.
LinkedInYour basic profile, and data for the organisation pages you administer (including their analytics).
XYour profile and posts (read), and an ongoing connection so we can refresh your numbers without asking you to sign in again.

From these accounts we store the account name and handle, follower counts, performance metrics (such as views and engagement) and a daily history of those numbers. The access tokens the platform gives us are encrypted before they are stored.

We use this data to show you your own analytics, to power the AI features you use, to publish content you ask us to publish, and, if you publish a profile, to show the audience numbers on it. We do not sell this data and do not use it for advertising. When you use an AI feature, the analytics it needs (including numbers from YouTube) are sent to our AI provider to produce the result you asked for; see “AI features” below.

MakerFlow’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. YouTube features also use YouTube API Services; by using them you are bound by the YouTube Terms of Service and the Google Privacy Policy.

How to disconnect

  • In MakerFlow, open your connected accounts settings and disconnect the account. We immediately delete the stored access tokens and stop syncing.
  • Disconnecting does not delete the numbers already synced (your analytics history). To have those deleted, see “Your rights” below.
  • To also revoke MakerFlow’s access at the platform, remove MakerFlow from the app-permissions or connected-apps settings of that platform. For Google, you can do this at myaccount.google.com/permissions.

AI features

When you use an AI feature, MakerFlow sends a request to OpenRouter, a service that routes it to a third-party language-model provider. The request contains what you typed plus context for that feature, which can include your creator profile fields (name, niche, audience, brand voice, goals), your saved ideas or content, and analytics numbers from your connected accounts.

We keep a usage log with the feature used, the model, token counts, cost, time and any error. We do not keep the prompt or the response in that log. Anything you save from an AI result (for example an idea or script) is stored in your workspace like your other content. Some suggestion results are cached for up to 24 hours to avoid repeating the same request.

Please do not enter sensitive personal data (such as health details, government identifiers or financial account numbers) into AI features.

Why we use your data

  • To create and run your account and workspace, and to provide the features you use.
  • To connect your platforms, sync your analytics and publish what you ask us to publish.
  • To provide AI assistance you request.
  • To show your public profile, media kit, blog and directory listing, if you publish them.
  • To send account emails (verification, password reset, invitations).
  • To keep the service secure: rate limiting, abuse prevention, moderation and debugging.
  • To manage your plan and, once payments are enabled, billing records.
  • To respond to support requests and to meet legal obligations.

We rely on your consent (given when you create an account, connect a platform or use a feature), and on the limited “legitimate uses” the DPDP Act allows, such as complying with the law. You can withdraw consent at any time (see “Your rights”); this does not affect what we did before you withdrew it.

Who receives your data

We do not sell personal data. We use these providers to run MakerFlow:

ProviderPurpose
RailwayHosts the MakerFlow website, the admin panel and our application servers (API), and our Redis instance, which holds short-lived data: rate-limit counters, the background-job queue and the suggestion cache.
NeonHosts our database, which holds your account and workspace data.
ResendSends account emails (verification, password reset, invitations) and, if you use the newsletter feature, the newsletters you send to your subscribers.
OpenRouter and the model providers it routes toProcess AI requests (see “AI features”).
Google (YouTube), Meta (Instagram), LinkedIn, XOnly for the accounts you connect: we call their APIs to read your data and, for YouTube, to publish.
Object storage provider (when video uploads are enabled)Video uploads for publishing are not enabled yet. When they are, the files will be stored with an S3-compatible object-storage provider.
Error-monitoring service (Sentry), where enabledReceives error reports so we can fix faults.
Payment provider, once paid plans are enabledProcesses payments. We do not store card details.

On the login and sign-up pages, if Google sign-in is offered, your browser loads a script from Google. Authorised MakerFlow staff may open your workspace to give support; each such access requires a recorded reason and is logged. We may also disclose data where the law requires it, or to protect rights and safety, and as part of a sale or restructuring of the business, with notice to you where required.

Cookies and local storage

We use only what the service needs to work. We do not use advertising or third-party analytics cookies or scripts, so we do not show a cookie banner.

NameTypePurpose
creator_os_rtCookie (httpOnly, essential)Keeps you signed in. Lasts up to 30 days.
creator_os_sessionCookie (essential)Tells the website a session probably exists, so signed-out visitors do not trigger a sign-in request. Lasts up to 30 days.
creator-os-color-modeLocal storageRemembers your light or dark theme.
creator_os_state_v1Local storageA copy of your creator profile details kept in your browser (and, for accounts that used an older version, saved data kept so it can be imported once).
Onboarding flagSession storageRemembers that you dismissed an onboarding prompt for this visit.

How long we keep data

  • We keep your account and workspace data while your account exists. We do not currently run automatic deletion for inactive accounts.
  • Disconnecting a social account deletes its access tokens at once, but keeps the analytics history already synced until you ask us to delete it.
  • When we action a verified deletion request we delete your personal data within 30 days from a verified request, except records we are required by law to keep (such as payment records), which we keep separately, and usage records that are anonymised. Copies in database backups or snapshots held by our provider may persist for a limited period after that.
  • Server logs are kept for security and debugging. Rate-limit counters and cached suggestions are short-lived.
  • We keep billing records for as long as the law requires.

Your rights and how to use them

Under the DPDP Act you can:

  • ask for a summary of the personal data we hold about you and who we share it with;
  • ask us to correct or complete inaccurate data;
  • ask us to erase your personal data;
  • withdraw consent you have given;
  • nominate another person to exercise these rights if you die or become incapacitated;
  • complain to our Grievance Officer and, if unresolved, to the Data Protection Board of India.

How to ask

Email support@makerflow.in from the address on your account, saying what you want (access, correction, deletion or withdrawal of consent). We may ask you to confirm your identity first.

Please note: MakerFlow does not yet have a self-service button to delete your account or download your data. Both are handled manually on request, as above. You can edit most of your profile and workspace data yourself inside the product.

Deleting data collected through Instagram, YouTube, LinkedIn or X

  1. Disconnect the account in MakerFlow (stops syncing and deletes the stored tokens).
  2. Optionally revoke MakerFlow’s access in the platform’s app-permissions settings.
  3. Email support@makerflow.in asking us to delete the data synced from that platform, naming the platform. We will delete it as described under “How long we keep data”.

How we protect data

  • Access tokens for connected platforms are encrypted at rest (AES-256-GCM).
  • Passwords are stored as salted argon2id hashes; sign-in sessions use a httpOnly cookie.
  • Each workspace’s data is separated from others in our application code, and requests are rate-limited.
  • Staff access to a workspace for support requires a recorded reason and is logged.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the authorities as the law requires.

Children

MakerFlow is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, email support@makerflow.in and we will delete it.

International transfers

Some of our providers, including AI model providers and email delivery, operate servers outside India, so your data may be processed in other countries. We share data with them only to provide the service, and only to the extent the DPDP Act and any restrictions notified under it permit.

Changes to this policy

We will update this page when our practices change, and change the “Last updated” date at the top. If a change is significant we will tell you in the product or by email.

Grievance Officer and contact

For privacy questions, to exercise your rights, or to complain, contact our Grievance Officer:

We will acknowledge and respond within the timelines the law requires. General support: support@makerflow.in.