🎁 CreatorFlow Waitlist is Open — 2 months free for the first 100 signups

Reply to DMs, capture leads, and send links automatically. Turn engagement into customers with simple tools made for creators.

CreatorFlow
EN - EnglishES - EspañolIT - ItalianoPT - Português
  • Solutions

    BY CREATOR TYPE

    Content Creators
    Engage your audience automatically
    Affiliate Creators
    Auto-send product links 24/7
    Creative Professionals
    Share portfolio and book clients
    Coaches & Educators
    Build your list and book calls
    Service Businesses
    Capture leads instantly

    BY USE CASE

    Drive Conversions
    Turn engagement into sales
    Grow Followers
    Build your audience automatically
    Auto-Respond to Comments
    Never miss a comment again
    Send Links in DMs
    Instant link delivery
    Collect Emails
    Build your email list
    Story Replies
    Automate story responses
  • Pricing
  • Resources
    Blog
    Learn automation strategies
    Instagram DM Automation Guide
    Complete 2026 playbook for creators
    Instagram Tools
    Free calculators & link generators
    About
    Our story and mission
Sign InGet Started Free
Solutions
BY CREATOR TYPEContent CreatorsAffiliate CreatorsCreative ProfessionalsCoaches & EducatorsService BusinessesBY USE CASEDrive ConversionsGrow FollowersAuto-Respond to CommentsSend Links in DMsCollect EmailsStory Replies
Resources
BlogInstagram DM Automation GuideInstagram ToolsAbout
Pricing
Sign InGet Started Free
EN - EnglishES - EspañolIT - ItalianoPT - Português

Privacy Policy

Effective Date:November 24, 2025

Last Updated:November 24, 2025

CreatorFlow ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Instagram DM automation platform ("Service"). Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

Table of Contents

  1. 1. Information We Collect
  2. 2. How We Use Your Information
  3. 3. How We Share Your Information
  4. 4. Data Retention
  5. 5. Your Rights and Choices
  6. 6. Account Settings and Control
  7. 7. Data Security
  8. 8. International Data Transfers
  9. 9. Children's Privacy
  10. 10. Third-Party Links and Services
  11. 11. Meta Partnership and Instagram Integration
  12. 12. Email Collection and GDPR Compliance
  13. 13. Changes to This Privacy Policy
  14. 14. Contact Us

1. Information We Collect

We collect information that you provide directly to us, information we obtain automatically when you use our Service, and information from third-party sources.

1.1 Information You Provide

  • **Account Information:** When you create an account, we collect your name, email address, and password.
  • **Profile Information:** Username, profile picture, and any other information you choose to provide.
  • **Instagram Account Data:** When you connect your Instagram account via Meta's official Graph API, we receive access to your Instagram username, profile information, and permissions to manage direct messages on your behalf.
  • **Payment Information:** If you subscribe to a paid plan, our payment processor (Stripe) collects your billing information. We do not store complete credit card numbers.
  • **Email Collection Data:** When your followers provide their email addresses through our email capture feature, we store these emails securely in your account.
  • **Communications:** When you contact us for support or feedback, we collect the content of your messages.

1.2 Information Collected Automatically

  • **Usage Data:** Information about how you use the Service, including DM automation activity, message templates, and feature usage.
  • **Device Information:** IP address, browser type, operating system, device type, and unique device identifiers.
  • **Log Data:** Server logs, including access times, pages viewed, and actions taken within the Service.
  • **Cookies and Similar Technologies:** We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities. See our Cookie Policy for more details.

1.3 Information from Third Parties

  • **Meta/Instagram:** We receive information from Meta's Graph API when you authorize our access to your Instagram account, including profile data and direct message permissions.
  • **Authentication Providers:** If you sign up using Google, Facebook, or GitHub, we receive basic profile information from these providers.
  • **Payment Processor:** Stripe provides us with payment confirmation and subscription status information.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • **Provide the Service:** To create and manage your account, process Instagram DM automations, and enable core features like comment-to-DM, story reply automation, and email collection.
  • **Process Transactions:** To process payments, manage subscriptions, and send billing-related communications.
  • **Customer Support:** To respond to your inquiries, provide technical support, and troubleshoot issues.
  • **Service Improvement:** To analyze usage patterns, identify bugs, develop new features, and improve the Service.
  • **Communications:** To send you service-related emails (e.g., account verification, password resets, subscription updates) and, with your consent, marketing communications about new features or promotions.
  • **Compliance and Safety:** To detect, prevent, and address fraud, security issues, technical problems, and violations of our Terms of Service.
  • **Legal Obligations:** To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

  • **Meta/Instagram:** Your Instagram account credentials are authenticated via Meta's official OAuth flow. We use Meta's Graph API to send automated direct messages on your behalf.
  • **Payment Processing:** Stripe processes all payment transactions. See Stripe's Privacy Policy at https://stripe.com/privacy.
  • **Cloud Hosting:** We use cloud infrastructure providers (AWS, Google Cloud, or similar) to host our Service and store data.
  • **Analytics:** We use Google Analytics and Facebook Pixel to analyze usage patterns. See our Cookie Policy for opt-out options.
  • **Email Services:** We use email service providers to send transactional and marketing emails.
  • **Customer Support Tools:** We may use third-party tools to manage customer support tickets and communications.

3.2 Business Transfers

If CreatorFlow is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your information is transferred and becomes subject to a different privacy policy.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government agencies).

3.4 Protection of Rights

We may disclose information when we believe it is necessary to: (a) protect our rights, property, or safety, or that of our users or others; (b) enforce our Terms of Service; (c) detect, prevent, or address fraud, security, or technical issues.

4. Data Retention

We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • **Active Accounts:** While your account is active, we retain your account information and usage data.
  • **Deleted Accounts:** When you delete your account, we delete or anonymize your personal information within 90 days, except where retention is required for legal, accounting, or security purposes.
  • **Email Collection Data:** Emails collected through our service are retained in your account until you delete them or close your account.
  • **Log Data:** Server logs and usage data are typically retained for 12 months for security and analytics purposes.
  • **Legal Obligations:** Some data may be retained longer if required by law (e.g., tax records, transaction history).

5. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

5.1 European Users (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have the following rights:

  • **Right to Access:** Request a copy of the personal information we hold about you.
  • **Right to Rectification:** Request correction of inaccurate or incomplete personal information.
  • **Right to Erasure:** Request deletion of your personal information ("right to be forgotten"), subject to certain exceptions.
  • **Right to Restriction:** Request restriction of processing of your personal information.
  • **Right to Data Portability:** Request transfer of your personal information to another service provider.
  • **Right to Object:** Object to processing of your personal information based on legitimate interests.
  • **Right to Withdraw Consent:** Withdraw consent for data processing at any time (without affecting lawfulness of processing before withdrawal).
  • **Right to Lodge a Complaint:** File a complaint with your local data protection authority.

5.2 California Users (CCPA)

If you are a California resident, you have the following rights:

  • **Right to Know:** Request disclosure of personal information we collect, use, and share.
  • **Right to Delete:** Request deletion of your personal information, subject to certain exceptions.
  • **Right to Opt-Out:** We do not sell personal information and have not sold personal information in the past 12 months.
  • **Right to Non-Discrimination:** We will not discriminate against you for exercising your CCPA rights.

5.3 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@creatorflow.so or through your account settings. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

6. Account Settings and Control

You can manage your information and privacy settings through your account:

  • **Update Profile:** Edit your name, email, and profile information in account settings.
  • **Disconnect Instagram:** Revoke CreatorFlow's access to your Instagram account at any time.
  • **Delete Collected Emails:** Delete emails collected through our service from your account dashboard.
  • **Manage Automations:** Pause or delete automated message flows at any time.
  • **Email Preferences:** Unsubscribe from marketing emails using the link in any email or through account settings.
  • **Delete Account:** Permanently delete your account and all associated data from your account settings.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

  • **Encryption:** Data is encrypted in transit using SSL/TLS and at rest using industry-standard encryption.
  • **Access Controls:** We limit access to personal information to employees, contractors, and agents who need access to perform their job functions.
  • **Authentication:** Passwords are hashed using bcrypt with industry-standard salt rounds.
  • **Infrastructure Security:** Our cloud infrastructure providers maintain SOC 2 Type II compliance and industry-standard security practices.
  • **Regular Audits:** We conduct regular security reviews and vulnerability assessments.
  • **Incident Response:** We have procedures in place to detect, respond to, and notify users of data breaches as required by law.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

8. International Data Transfers

CreatorFlow is based in [Your Country/Region]. If you access the Service from outside this region, your information may be transferred to, stored, and processed in countries where our servers are located or where our service providers operate. These countries may have data protection laws that are different from the laws of your country.

8.1 European Users

For users in the EEA, UK, or Switzerland, we ensure that any international data transfers comply with GDPR requirements through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where data is transferred to countries deemed to provide adequate protection
  • Other legally approved mechanisms to ensure appropriate safeguards

9. Children's Privacy

The Service is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@creatorflow.so, and we will delete the information from our systems.

10. Third-Party Links and Services

Our Service may contain links to third-party websites, services, or resources that are not owned or controlled by CreatorFlow. This Privacy Policy does not apply to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services before providing them with your information.

  • **Instagram/Meta:** Governed by Meta's Privacy Policy at https://www.facebook.com/privacy/policy
  • **Stripe:** Governed by Stripe's Privacy Policy at https://stripe.com/privacy
  • **Google Analytics:** Governed by Google's Privacy Policy at https://policies.google.com/privacy

11. Meta Partnership and Instagram Integration

CreatorFlow is a Meta Technology Provider and uses Meta's official Graph API for Instagram integrations. Important information about this partnership:

  • **OAuth Authentication:** We use Meta's OAuth 2.0 for secure authentication. We never ask for or store your Instagram password.
  • **API Permissions:** We only request Instagram permissions necessary for our Service (direct messaging, profile access).
  • **Meta's Terms:** Your use of Instagram through our Service is also governed by Meta's Terms of Service and Community Guidelines.
  • **Rate Limits:** Our Service respects Meta's API rate limits (200 DMs per hour, 24-hour messaging window).
  • **Revoke Access:** You can revoke CreatorFlow's access to your Instagram account at any time through your Instagram settings or Meta account settings.

12. Email Collection and GDPR Compliance

When you use our email collection feature to capture emails from Instagram followers:

  • **Consent Requirement:** You must obtain explicit consent from users before collecting their emails. Our service provides GDPR-compliant consent flows.
  • **Your Responsibility:** You are the data controller for emails collected through our Service. We act as a data processor.
  • **User Rights:** You must honor data subject requests (access, deletion, etc.) for emails in your account.
  • **Data Processing Agreement:** Our Terms of Service include data processing terms that comply with GDPR requirements.
  • **Data Portability:** You can export collected emails at any time from your account dashboard.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • **Notice:** We will post the updated Privacy Policy on this page and update the "Last Updated" date at the top.
  • **Material Changes:** For material changes that significantly affect your rights, we will notify you via email (to the address associated with your account) or through a prominent notice on the Service at least 30 days before the changes take effect.
  • **Continued Use:** Your continued use of the Service after the updated Privacy Policy becomes effective constitutes your acceptance of the changes.
  • **Review Regularly:** We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email:privacy@creatorflow.so

Support:support@creatorflow.so

For GDPR-related inquiries, you may contact our Data Protection Officer at dpo@creatorflow.so

Address:

[Your Company Name]
[Street Address]
[City, State ZIP]
[Country]

Have Questions?

If you have any questions about our legal policies or need clarification, our support team is here to help.

Contact Legal TeamGeneral Support
CreatorFlow

Make Instagram Conversations Work for You

Reply to Instagram DMs, capture leads, deliver links, and turn engagement into customers — built for creators who want results, not complexity.

⭐ Read our reviews on Trustpilot

Solutions

Content CreatorsAffiliate CreatorsCreative ProfessionalsCoaches & EducatorsService Businesses

Use Cases

Drive ConversionsGrow FollowersAuto-Respond to CommentsSend Links in DMsCollect EmailsStory Replies

Resources

Instagram DM Automation Guide

Compare

vs ManyChatvs LinkDMvs InstantDMvs Zorchavs ReplyRushvs GrocersList

Free Instagram Tools

ChatGPT for InstagramInstagram Chat Link GeneratorInstagram Engagement CalculatorInstagram Influencer Pricing CalculatorInstagram Caption GeneratorMetrics Knowledge QuizView All Instagram Tools →

Company

AboutHey AI, learn about usPricingBlogPress KitReviewsContactCareersAffiliate ProgramPrivacy PolicyTerms of ServiceCookie PolicyData Processing AgreementRefund Policy

© 2025 CreatorFlow. All rights reserved.

Meta-Approved Tech Provider • Creative Flow Labs SL, Madrid, Spain

Instagram is a trademark of Meta Platforms, Inc. CreatorFlow is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. CreatorFlow uses Instagram's official Graph API. Performance results shown are based on aggregated user data. Individual results vary based on audience size, niche, content quality, and engagement rates. Users are responsible for complying with Instagram's Terms of Service and Community Guidelines. Instagram/Meta may change API features, rate limits, or terms at any time.

CREATORFLOW