Privacy Policy

Comprehensive Disclosure � Last Updated: April 08, 2026

ZackFlow ("the Application," "we," "our," or "us") is committed to protecting your privacy and ensuring transparency in how we handle your data. This Privacy Policy provides a comprehensive disclosure of how our application accesses, uses, stores, and shares Google user data in compliance with the Google API Services User Data Policy and Google APIs Terms of Service.

This policy applies to all ZackFlow products and services that integrate with Google APIs, including but not limited to our LinkedIn Growth Dashboard, Facebook Premium Growth Dashboard, and any future Google Workspace-integrated tools. By using our Application, you consent to the practices described in this policy.

1. Google User Data Accessed

To deliver its core functionality as a social media growth and content strategy infrastructure, the Application accesses the following specific types of Google User Data through Google APIs:

1.1 Google Sheets Data

  • Active Spreadsheet Content: The Application reads and writes data within the specific Google Sheet to which it is installed. This includes cell values, formulas, and formatting related to your content calendars, strategy plans, and growth metrics.
  • Sheet Metadata: Access to sheet names, tab structures, and cell ranges necessary for proper dashboard functionality.
  • User-Entered Profile Data: Text data you manually input or paste into the spreadsheet (e.g., LinkedIn profile information, target audience descriptions, brand voice parameters, competitor analysis notes).
  • Generated Content: AI-generated posts, hashtags, scheduling data, and engagement tracking metrics created by the Application within your spreadsheet.

1.2 Google Apps Script Properties

  • Script Properties: Configuration settings and preferences you define within the Application's setup wizard or settings panel.
  • User Properties: Account-specific preferences and API credentials stored locally within your Google Workspace environment using Google Apps Script's PropertiesService.

1.3 Data We DO NOT Access

The Application explicitly does NOT access:

  • Your Google Contacts or address book
  • Your Google Calendar events or schedules
  • Your Google Drive file listings or folder structures
  • Your Gmail messages or attachments
  • Any Google Sheets other than the one where the Application is actively installed
  • Your Google account credentials, passwords, or authentication tokens
  • Location data, photos, or personal media files

2. Purpose & Use of Google User Data

The Application processes accessed Google User Data exclusively for the following purposes, directly related to providing social media growth and content automation services:

2.1 Core Functional Processing

  • Profile Auditing & Analysis: Processing your pasted profile text and social media data to identify growth opportunities, analyze current performance patterns, and recommend optimization strategies.
  • AI-Powered Content Generation: Using your brand parameters, target audience definitions, and historical content data to generate platform-specific posts, captions, and hashtag strategies via Google Gemini AI API integration.
  • Strategy Development: Translating your interview responses and business objectives into structured 30/60/90-day content calendars and actionable growth roadmaps.
  • Dashboard Population: Programmatically writing generated strategies, content calendars, task lists, KPI trackers, and analytics dashboards back into your active Google Sheet.

2.2 User Experience Enhancement

  • Preference Persistence: Saving your brand voice settings, target audience profiles, content tone preferences, and API configurations locally so you can regenerate content without re-entering your details.
  • Workflow Automation: Automating repetitive content planning tasks, scheduling calculations, and performance tracking to reduce manual effort and save operational time.
  • Template Customization: Adapting pre-built dashboard templates and content frameworks to match your specific industry, niche, and growth objectives.

2.3 Analytics & Improvement

  • Usage Metrics: Anonymous aggregation of feature usage patterns to improve Application functionality and prioritize future development (processed separately from your identifiable Google User Data).
  • Error Diagnostics: Processing error logs and execution failures to troubleshoot issues and maintain Application stability.

Legal Basis for Processing:

We process Google User Data based on your explicit consent when you install and authorize the Application, and as necessary to fulfill the service functionality you have requested. You may withdraw consent at any time by uninstalling the Application or revoking its permissions.

3. Data Sharing & Third-Party Disclosure

✓“ Zero-Selling Policy

We are committed to a strict Zero-Selling Policy. We do NOT sell, rent, lease, or trade your Google User Data to third-party marketers, data brokers, advertisers, or any other external entities for their own marketing, advertising, or commercial purposes.

3.1 Third Parties We Share Data With

Your Google User Data is shared only in the following limited circumstances:

Google Gemini AI API (Google Cloud)

Purpose: To power AI-driven content generation, profile analysis, and strategy recommendations.

Data Transmitted: Your profile text, brand parameters, target audience definitions, and content requests are transmitted to Google Gemini AI API (generativelanguage.googleapis.com) via encrypted HTTPS connection.

Important Note: This data flows directly from your Google Sheets environment to Google Cloud's AI infrastructure. ZackFlow developers never see, receive, proxy, or store this data on external servers. The transmission is secured using industry-standard TLS/SSL encryption.

Google Workspace Infrastructure

Purpose: To maintain Application functionality within your Google environment.

All user data is inherently stored within your own Google Workspace (Google Drive, Google Sheets, Apps Script Properties). This means your data is protected by Google's own security infrastructure and access controls. We do not extract or transfer this data to any external database or cloud storage under our control.

Legal Compliance & Protection

We may disclose your Google User Data if required to do so by law, regulation, legal process, or governmental request.

We may also share data to:

  • Protect the rights, property, or safety of ZackFlow, our users, or the public
  • Enforce our Terms of Service or other agreements
  • Investigate or address suspected security vulnerabilities or breaches
  • Respond to emergencies or prevent fraud/illegal activity

3.2 Service Providers & Processors

ZackFlow does not employ external data processors or sub-processors for handling Google User Data. All AI processing is performed directly through Google's own Gemini API infrastructure. We do not use third-party analytics providers that access your Google User Data.

3.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your Google User Data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website before your Google User Data becomes subject to a different privacy policy. We will require the successor entity to honor this Privacy Policy.

4. Data Storage & Security Practices

ZackFlow employs a "Client-Side Persistence" architecture, meaning your data security is managed by Google's enterprise-grade infrastructure within your own Google Workspace environment. We maintain zero external servers, databases, or cloud storage facilities for your Google User Data.

4.1 Storage Architecture

  • Google Drive Native Storage: All strategic plans, content calendars, audits, and generated content reside exclusively within your Google Drive as Google Sheets files. These files are protected by Google's access controls and encryption.
  • Apps Script PropertiesService: Your API keys, preferences, and configuration settings are stored in Google Apps Script's PropertiesService. This data is encrypted at rest by Google and is completely inaccessible to ZackFlow developers or any external party.
  • No External Data Repositories: We do not maintain, operate, or have access to any external database, cloud storage bucket, or server that contains your Google User Data.

4.2 Security Measures

  • Encryption in Transit: All API communications, including transmissions to Google Gemini AI API, are performed exclusively over HTTPS using TLS 1.2 or higher encryption protocols.
  • Encryption at Rest: Your data stored within Google Sheets and Apps Script Properties is encrypted at rest by Google's infrastructure using AES-256 or equivalent encryption standards.
  • Access Controls: Access to your Google User Data is restricted to users who have been granted explicit permissions to the Google Sheet where the Application is installed. The Application respects and enforces Google's native sharing and permission settings.
  • Principle of Least Privilege: The Application requests only the minimum OAuth scopes necessary to function (specifically, access to the active spreadsheet). We do not request broad Drive or account-wide permissions.
  • Regular Security Audits: We periodically review our code and data handling practices to identify and remediate potential vulnerabilities.

4.3 Data Breach Response

While the risk is minimal given our architecture, in the unlikely event of a confirmed data breach affecting your Google User Data, we will:

  • Notify affected users via email within 72 hours of discovery
  • Provide clear information about what data was affected and potential impact
  • Offer guidance on protective steps users can take
  • Cooperate with relevant regulatory authorities as required
  • Implement corrective measures to prevent recurrence

5. Data Retention & Deletion Rights

You maintain complete control over the lifespan of your Google User Data. Our retention policy is straightforward: your data persists for as long as you keep it within your Google Workspace.

5.1 Data Retention Period

  • Active Retention: Google User Data is retained within your Google Sheet for as long as you choose to maintain the file and its permissions within your Google Drive.
  • No Automatic Deletion: ZackFlow does not impose any automatic or scheduled deletion of your Google User Data. The data remains accessible until you manually remove it.
  • Account Dependency: Data retention is tied to the status of your Google Workspace account. If your Google account is suspended or deleted by Google, the associated data will be handled according to Google's own retention policies.

5.2 How to Delete Your Data

You have multiple accessible methods to request and execute the deletion of your Google User Data:

  • Delete the Google Sheet: Permanently deleting the Google Sheet file where the Application is installed will remove all associated strategy data, content calendars, and generated content from your Google Drive.
  • In-App Data Clear: Navigate to the "Settings" tab within your ZackFlow Dashboard and click the "Clear All Data & Keys" button to wipe stored preferences and API credentials while preserving the template structure.
  • Manual Cell Deletion: You may manually delete specific cells, tabs, or data points within your spreadsheet at any time.

5.3 Revoking Application Access

You can revoke the Application's access to your Google Account at any time:

  1. Visit your Google Account Third-Party Permissions page
  2. Locate the ZackFlow Application in the list
  3. Click "Remove Access" or "Revoke Access"

Revoking access will prevent the Application from reading or writing to your Google Sheets going forward, but will not automatically delete data already written to your spreadsheets.

5.4 Data Deletion Requests

If you require assistance with data deletion or believe we hold any Google User Data outside of your Google Workspace, you may contact us at zack.flow.ai@gmail.com. We will respond to deletion requests within 30 days.

Please note: Since we do not maintain external databases or servers containing your Google User Data, in most cases you can achieve complete deletion simply by removing the Application from your Google Sheet and/or deleting the Sheet file itself.

6. Your Rights & Choices

Depending on your jurisdiction, you may have certain rights regarding your Google User Data:

Access & Portability

You have the right to access all your Google User Data directly within your Google Sheets environment. You can export, download, or port this data to other formats at any time using Google Drive's native export features.

Rectification

You can correct, edit, or modify any data within your Google Sheets at any time. The Application will process updated data on its next execution.

Objection & Restriction

You may object to the Application's processing by uninstalling it or revoking permissions. You can restrict processing by removing API keys from the Settings tab.

Complaint Rights

If you believe your data has been mishandled, you have the right to lodge a complaint with your local data protection authority. Please contact us first so we can address your concerns.

7. Children's Privacy

ZackFlow is not directed to individuals under the age of 18 (or the minimum age required by law in your jurisdiction). We do not knowingly collect, process, or share Google User Data from children. If we become aware that we have inadvertently received data from a child without proper consent, we will delete such information promptly.

8. International Data Transfers

Your Google User Data is processed and stored within your Google Workspace environment, which may be hosted in data centers located in various countries depending on Google's infrastructure. When your data is transmitted to Google Gemini AI API, it may be processed in any country where Google Cloud maintains operations.

All such transfers and processing are governed by Google's own data protection commitments, including Standard Contractual Clauses where applicable. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email (if you have provided one) or through a prominent notice on our website or within the Application
  • For significant changes, we may seek your renewed consent where required by law

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your Google User Data. Your continued use of the Application after changes are posted constitutes your acceptance of the revised policy.

Contact Our Privacy Team

If you have questions, concerns, or requests regarding this Privacy Policy, our data handling practices, or wish to exercise your rights regarding Google User Data, please contact us:

Email: zack.flow.ai@gmail.com

Response Time: We will respond to your inquiry within 2-4 business days.

Security Reports: If you wish to report a perceived security vulnerability or data handling concern, please email us with details. We take all security reports seriously and will investigate promptly.