Privacy Policy โ plain-language summary
This page summarizes how Onflow Ads handles personal data โ what is collected, why, who sees it, where it goes, how long it is kept, and what control you have over it.
This is a summary, not the policy itself. The full Privacy Policy is at onflowads.com/privacy and runs to 30 numbered sections. If this summary and the full policy ever differ, the full policy controls. The legal page shows its "Last updated" date at the top, and ยง27 carries any disclosure published since the page was last deployed.
The short versionโ
- Onflow Ads collects only what a feature actually needs to run, to keep the marketplace honest, and to give you analytics.
- Your personal data is never sold โ not for money, not for "valuable consideration", not to a data broker, and not for behavioural advertising.
- A trading partner never sees your full email address, your wallet balance, your ledger, your payout details or your other campaigns.
- Analytics is always on; advertising is not. The preference centre has two categories, and only one of them is yours to switch โ see Cookies and tracking and the walkthrough on Cookie preferences.
- Closing your account deletes more than you might expect, and less. Your account, orders and the wallet ledger inside the platform are deleted; the accounting record of money that moved survives with the books and the payment provider, as do security logs and a few other things โ see What survives closure.
- One address does everything: [email protected].
How to read this pageโ
The full policy has 30 numbered sections in eight parts. This summary follows the same order, and each heading below links to the section that binds.
| Part | Sections | Covered below |
|---|---|---|
| The basics | 1โ3 | Who is responsible |
| What we collect | 4โ9 | What is collected, People who are not users, What is never collected |
| Why we use it | 10โ12 | How it's used, Automated decisions, AI |
| Who else sees it | 13โ17 | What others see, Who data is shared with, Leaving the country |
| Your device | 18โ19 | Cookies and tracking, Messages |
| Keeping and protecting | 20โ21 | How long data is kept, Security |
| Your control | 22โ24 | Your rights, Children, Complaints |
| The rest | 25โ30 | Breaches, changes and contact |
Who is responsibleโ
For your account, orders, payments, support and security logs, Onflow Ads decides what happens to the data. It is the Data Fiduciary under India's DPDP Act and the controller under the GDPR.
For personal data you put into the platform โ a face or a name inside your creative, your own channel's members, data you collect on a landing page you send traffic to โ you are responsible. You need a lawful basis for it and you must honour the rights of the people it belongs to. See ยง3 of the full policy.
One feature puts you squarely in the controller's seat, and ยง3.2 names it: outbound webhooks. Order records go to a host you nominate, and what happens to them there is yours to answer for.
Telegram is a third platform. What Telegram does with your data is governed by Telegram's privacy policy, not this one.
What is collectedโ
You provide:
| Data | Examples |
|---|---|
| Account | Name, email address, password (stored only as an argon2id hash โ never the password itself), 2FA secret if you enable it |
| Channels | Telegram id, username or invite link, title, description, category, language, subscriber and engagement figures, your pricing |
| Campaigns | Ad copy, images, buttons, destination links, budgets, schedules, targeting |
| Money | Top-up and payout amounts, provider references, and your payout destination (UPI ID, bank details or crypto address) |
| Verification | Legal name and country only. No ID document, no selfie, no biometric |
| Support | Contact-form name/email/message; a support ticket also stores a phone number if you give one, plus the page, IP and browser it was raised from. Reporting an answer or a conversation also records which one, the reason you picked and any note you add |
Collected automatically: IP address, browser User-Agent, country inferred from IP, referring page, and what you did and when. There is a request-level activity record that keeps the email address or name carried by a request โ which is why it outlives the account.
Computed about you: your reliability score and standing, performance and delivery metrics, risk and abuse signals, commercial signals like tier and lifetime spend โ and a device identity (ยง5.5). On every signed-in page a script hashes a set of device traits separately in your browser (graphics renderer, platform, cores, colour depth; canvas, audio, graphics limits, screen, touch, languages, time zone) and the hashes are recorded against your account, with the IP as corroboration only. It answers one question โ does this device carry an unpaid debt โ and only a certain or strong match can act on its own, by refusing to let another account on that device start something new; a weaker match is logged for a person. It is not a tracking identifier and is not shared with any tag.
From Telegram sign-in: your Telegram user id, name, username and profile photo, sent with a signature we verify โ of which we retain only the id and display name. Not your phone number, contacts or messages.
From your channel: the figures โ subscribers, views, reactions, timing โ plus a snapshot of your recent public posts, shown to signed-in advertisers on your listing so a buyer can see what you publish. Never the member list, and never who viewed or reacted. There are exactly two identity reads: the administrator list, which is how ownership is proved (the bot's presence in it is the proof, which is why no screenshots are asked for); and, in a cross-promotion where both sides agreed to join each other's channel, a periodic check of whether that one counterparty is still a member. Neither gives Onflow Ads a member list.
From the bot (ยง6.2): the bot is an executor โ the website decides, the bot carries out. Telegram passes it your user id, display name, username, language and any message you send, and it answers with a pointer back to the website; it keeps no conversation. What it holds is your account link, the work it carried out (posts published and taken down, placements, proof captures, monitoring readings), joins through a campaign invite link as salted hashes, the facts it reports for the website to price, and a display mirror of your plan. It holds no money and no money record โ every settlement is computed and paid by the website. Where Google Analytics is configured it reports campaign events server-side keyed by your Telegram user id, which the cookie banner cannot cover.
The bot also looks at the channels you connect, because that is how the platform checks what actually happened: whether the channel exists and whether you administer it, its subscriber count and recent public posts to measure reach, and โ while a placement you agreed to is running โ whether that post is still there. It reads public channel content and the posts the platform's own placements created, nothing else. What it observes is recorded against the placement and can move your reliability score, so it is kept for as long as a dispute could still turn on it.
It never messages your subscribers privately, never posts anything outside the campaigns and slots you accept or book, and is never given your subscriber list โ Telegram does not hand one to a bot. The same three limits are contractual, in Terms ยง4.2. Remove the bot as an administrator, or disconnect the channel, and its access ends immediately.
People who are not usersโ
The audience of a channel never signed up for anything, so the full policy gives them their own section (ยง8). Every link in an ad, in every engine, follows one rule, and three things can be measured:
- A join through an invite link โ where the destination is a channel the advertiser connected, the ad carries a per-campaign invite link and Telegram tells our bot about each join. What is recorded is a salted one-way hash of the Telegram user id, the channel, and the join and leave times โ enough to recognise the same person leaving again, never enough to name them. The channel's public subscriber count is noted at the start and as the run proceeds.
- A tap at our redirect (our short ad links, including the older forms still in cross-promotion posts) โ the IP address and User-Agent as sent, a one-way salted hash of the two, plus country, referrer, device type, operating system, browser and preferred language. The IP address and User-Agent are deleted after 90 days, automatically, leaving the hash and the derived values; no cookie is set and no advertising profile is built. Taps are deduplicated per visitor per day; link-preview crawlers and other automated requests are served but never counted, and are recorded as such. This applies whether or not you have an account โ most people whose taps are recorded are reading someone's channel, not using Onflow Ads.
- A landing or conversion on the advertiser's own site โ only where the advertiser adds the Onflow tag to their page. The tag reads the campaign tags off the address, writes the link's token into that site's session and local storage (local storage persists until the visitor clears that site's data), reports one landing per link per tab, and lets the page report a conversion with a label and a value. It sets no cookie and reads nothing on the page. The record on our side is the same salted hash, so a tap and a later action join into one device-level record for that advertiser's own funnel โ no profile follows anyone across the web, and the advertiser must disclose the tag in their own notice.
The one place a tapper is identified is closing: buttons on older Subscriber Exchange placements that still open the bot record the tapper's numeric Telegram user id (no name, no username, no phone) so genuine taps can be paid for; nothing new is published that way. Older cross-promotion buttons that open the bot hold the id only in the bot's cache for about a day.
Anyone, user or not, can exercise every right in ยง22 by writing to [email protected].
What is never collectedโ
These are commitments in ยง9 of the policy, and narrowing one requires 30 days' notice:
- Sensitive data โ health, biometrics, genetics, sexual orientation, religion, politics, union membership, caste or community.
- Full payment credentials โ card numbers, CVVs, UPI PINs, banking passwords. Nobody at Onflow Ads will ever ask for one.
- Your channel's member list, or the identity of individual viewers or reactors.
- Precise device location โ no GPS, no location permission. "Location" means country, inferred from IP.
- Data from children โ see Children.
Onflow Ads also does not buy personal data from brokers, enrich your record from third-party datasets, or scrape personal data to build lists.
How it's usedโ
Every purpose is paired with a lawful basis in ยง10. In short: running your account and delivering orders is contract; taking and moving money adds legal obligation; reliability scoring, fraud detection, security and product analytics are legitimate interests; advertising tags are consent, withdrawable at any time from Cookie preferences in the site footer. Marketing email is consent โ it is off until you tick the unticked "Send me product news and offers" box at sign-up or on a top-up checkout (or switch it on in your notification settings), and it is switched off again in one click.
Data collected for one purpose is not silently reused for another.
Automated decisionsโ
Reliability scores, eligibility floors, abuse and fraud signals, content-safety checks and rate limits are all decided by code first. So are two newer ones: the debt gate (a wallet below zero cannot start anything new, and every credit goes to the negative first โ Terms ยง12.11) and the device-debt block (a certain or strong device match to an account carrying an unpaid debt refuses this account when it tries to start something new; it charges nothing, and a weaker match only ever goes to a person โ ยง5.5, ยง11.1).
No automated decision permanently closes an account, confiscates a wallet balance or cancels a payout on its own โ those need a person. An automated decision can suspend, hold or block pending that review. You can ask for a human to look again, put your side, and have the decision reconsidered.
AIโ
AI drafts copy, suggests targeting, describes channels, summarises analytics, checks creative for prohibited content and spots duplicates. ยง12 lists exactly what reaches a model provider โ including the parts most policies leave out:
- Your brief, creative and channel profile when you use an AI feature.
- A task you ask the support chat to carry out sends nothing beyond your message: the task runs on our server, as you, after you confirm it, and the proposal and result are kept on your ticket as an action log (ยง4.6, ยง12.2).
- Support ticket threads, including your name, when AI drafts or triages a reply. Every message you send the support chat goes to the model provider to generate the reply โ and that is true whether you are signed in or not: a signed-out visitor gets a small free allowance, metered against an opaque handle in a cookie with the last IP kept for abuse triage and cleared after 180 days.
- A screenshot you attach in the support chat, whole, where the account has that turned on โ carried to the provider with the message so the agent can look at the problem rather than be told about it. Nothing crops or masks it first, so a screen grab carries whatever else was on the screen: crop before you send. Up to three per message, 4 MB each, PNG/JPEG/WebP/GIF only, and the type is read from the file's own bytes rather than from what the browser claimed.
- Your own account facts, on the plans that include it โ the reference you pasted and what it names, the events behind a reliability change, which recent top-ups are still refundable and for how much, and suggested partner channels. Only ever your data: someone else's reference returns the same "no information" answer as one that does not exist.
- Both sides' history and money lines when AI assists on a dispute or fraud review.
- Your commercial figures when AI narrates your analytics.
Never sent: credentials, your 2FA secret, your payout destination, the payment instrument you paid with, or another user's account contents outside a dispute they are party to or what is already published to you in the marketplace. Money figures do go where an AI feature runs over them; money instruments never do.
To keep AI out of your support entirely, ask before you write โ there is a per-account switch and support will set it for you, after which a person handles every ticket from the first message. A request typed inside a message has already been sent by the time anyone reads it.
The engine is one of a small set of established commercial model providers; the full policy lists categories rather than brand names and will tell you which is in use if you ask (see below). Your data is not used to train AI models, and Onflow Ads will only configure a provider whose business terms bar training on customer content. Prompts and responses are not stored in the AI call log โ with two deliberate exceptions: text that a safety check blocks is kept as the evidence for that decision, so an appeal can be judged on what was actually written; and a screenshot you attached in the support chat is kept with the message it rode on, readable by the support team exactly as the transcript is, and deleted in the same operation as the conversation. A picture uploaded and never sent is swept within six hours. There is no gallery and no public address for one.
Who gets the paperclip. Screenshot reading is not open to everyone โ it costs a multimodal model call per picture. It is on for accounts whose lifetime top-ups have passed the published threshold, an administrator can grant it below that threshold or block it for any account, and there is a global switch that turns it off for everybody at once. A signed-out visitor never has it: there is no account to have spent. When it is off the paperclip is simply absent and the chat says in one line why.
What others seeโ
A trading partner sees your channel's public profile and figures, the creative and order details for your deal with them, your public trust signals, and the delivery evidence.
Your full email address, your wallet balance, your transaction ledger, your payout destination, your legal name from verification, your IP address, your other channels, or your other campaigns. One precision: where a channel owner needs to tell two advertisers apart they see the advertiser's display name โ the name that member set on their own account, or, until they set one, the readable part of their address with the domain dropped (john.doe@โฆ reads as John Doe). No form of the address itself, whole or masked, reaches a counterparty's screen.
Delivery-proof and certificate pages are unlisted but reachable by anyone holding the link โ treat the link as the secret.
Who data is shared withโ
Personal data is not sold, and not shared for cross-context behavioural advertising. What actually happens instead:
| Who | What they get |
|---|---|
| Hosting, database, cache | Everything, as the infrastructure that runs the platform |
| Network protection & edge | Request metadata (IP, User-Agent); bot-check tokens; uploaded media |
| Payment providers | Amount, currency, references. Card and UPI details are entered on their own checkout and never reach Onflow Ads. The crypto gateway gets no name, email or account id |
| Suppliers (Boost fulfilment) | The service, the target link and the quantity โ never who you are. Note that Telegram member/subscriber services require a private invite link, which is a working key into a private channel โ see ยง14.4 before ordering one |
| AI providers | The content an AI feature operates on (see AI) |
| Email, push, error monitoring | Your address and message content; your browser's push endpoint; technical error context |
| Analytics and support tools, where enabled | Behaviour, and for two of them your identity โ email, name, tier, role and credit balance |
The full policy describes each provider by what it does and what it receives rather than by brand. A published map of the infrastructure is a target list for anyone attacking it, and that risk lands on you as much as on Onflow Ads. You can have the names on request โ email [email protected], no reason needed, answered on the ยง22.2 timetable. Anything that runs in your own browser โ every cookie, every third-party tag โ is still named in full, because withholding those would hide nothing from an attacker while stopping you giving informed consent.
Significant events are mirrored, as they happen, into a private operations channel only operators can read: the acting account's name and email, account id, IP, country, browser, the action and its outcome, and for money operations the amounts and references. A messaging provider therefore carries a copy of those operational records. ยง14.5 discloses this rather than calling it "internal logging".
What does not go into it: your payout destination (only its last four characters, so an operator can spot a changed destination without being able to use it), the legal name you gave for verification (dropped entirely), any phone number, and credentials of any kind.
Leaving the countryโ
Onflow Ads is operated from India and its providers sit in several countries. Transfers rely on Standard Contractual Clauses or an adequacy decision where the EEA/UK is involved, and no data goes to a territory restricted under the DPDP Act.
Contractual safeguards bind the company data is sent to. They do not bind a foreign government. What Onflow Ads controls is how little crosses a border โ a supplier gets a link, a crypto gateway gets an amount, an AI provider gets the text you are editing.
Cookies and trackingโ
This is ยง18 of the policy, and it is the section most people actually want. It has three separate pieces: the cookies Onflow Ads sets itself, what is kept in your browser and never sent, and the third-party tags โ only some of which sit behind the banner.
For the how-to โ where the entry point is, what each button does, what happens after you save โ see Cookie preferences.
The cookies Onflow Ads setsโ
All first-party, all only ever sent over an encrypted connection, and none is used for advertising. Most are marked so no script on the page can read them; the two that page script can read are marked below, with the reason. ยง18.1 is careful about a distinction most policies blur: the first four are strictly necessary in the sense the law uses; the rest are functional or protective.
| Cookie | What it does | Lifetime |
|---|---|---|
| Sign-in session | Keeps you signed in. Holds a random token only โ no data about you is inside the cookie | 48 hours, or 30 days if you tick "remember me" |
| Verification flow | Carries you through one verification โ sign-up, first-email attachment, password reset, or the second step of two-factor sign-in | 30 minutes |
| Telegram sign-in binding | Binds a Telegram sign-in to the browser that started it, so a code cannot be completed from somewhere else | 10 minutes |
| Google / Apple sign-in state | Anti-forgery state tying the round trip to the browser that began it | 10 minutes |
Device identity (onflow_dev) | Carries the device signature from ยง5.5 โ a hash computed in your browser, never a raw trait โ so it can be read before the page script runs. Readable by page script, because that script writes it. One purpose: does this device carry an unpaid debt | 400 days |
Referral attribution (onflow_ref) | Set only when you arrive through a member's share link or a partner link. Holds their code and nothing about you; cleared the moment a sign-up binds | 90 days |
How you first found us (onflow_src) | Written on your first page view and never rewritten, so a link you followed in March still gets the credit for an account you open in May. Holds the referring page, the page you landed on, any campaign tags in the link and the time of that visit โ nothing about you. Copied onto your account once if you create one; otherwise it just expires. Never used for advertising | 90 days |
Marketplace side (onflow_pp_side) | While you are signed in and enlisted in Paid Promotions: one word โ advertiser or owner โ so a marketplace page draws the right navigation on first paint. Readable by page script by design; a hint, never an authority | 48 hours, cleared on sign-out |
Welcome intro markers (onflow_intro, onflow_live) | That the welcome animation was seen in this browser session, and the bare fact that a sign-in session exists โ shared with the guide at docs.onflowads.com so it can skip the intro | The browser session; the life of the sign-in session |
Support chat allowance (onflow_anon) | Set only if you use the help widget's AI chat while signed out. Holds a random handle โ no account, no email, nothing derived from you โ so the free messages that browser has used can be counted and given back when the cycle rolls | 180 days, after which the handle and its counter are deleted |
Staff sign-in (onflow_admin, onflow_admin_verify) | Set only for Onflow Ads' own administrators on the admin console; a member never receives them | โ |
"Strictly necessary" is a legal test, and ยง18.1 refuses to stretch it over a business rule. The support-chat handle makes a feature work as intended by metering a signed-out visitor's free AI messages โ the chat would still answer without it. Against that handle the platform also stores the IP address of the last message, for abuse triage. Signed in, your account carries the allowance instead and this cookie is not used. The Onflow tag an advertiser may place on their site sets no cookie of ours at all.
What is kept in your browser and never sentโ
Clearing site data removes all of it:
| Stored | What it is for |
|---|---|
| Your cookie choice | Which categories you allowed and when, so you are not asked again and the preference centre can show what you chose |
| Display preferences | Which currency you prefer to see prices in |
| Basket and saved channels | What you put in a basket or saved, held locally until you check out |
| Welcome message state | Stops a welcome message repeating in the same browser tab. This tab only |
| Your support conversations | The help widget remembers your name, the email address you gave it, and the code, reference and subject of your last few conversations, so it can list them when you return |
"Your support conversations" is the only entry in that list that names a person, and the conversation code it stores opens that conversation for whoever holds it (ยง13.3). On a shared or public computer, clear site data when you are done.
Third-party tags, and what the banner actually coversโ
The preference centre has two categories and you decide one of them.
- Essential โ always on. Your sign-in session, the security tokens, the preference this dialog stores โ and the analytics the service is run and repaired with: PostHog, Microsoft Clarity (which records a replay of how pages are used) and Google Analytics 4 / Tag Manager in its advertising-denied state. These load with the page whether or not you answer. The policy states the cost of that outright: your IP address, device and browser reach those providers, and Clarity records a replay of your interactions. None of them is used for advertising, none builds an advertising profile, and none is used to identify you to anyone else.
- Marketing โ yours to refuse. Every advertising pixel: Meta, TikTok, Snapchat, Pinterest, LinkedIn, Reddit and X. Choose Reject all, or answer nothing at all, and not one of them ever loads.
ยง18.3 marks each of them rather than burying it: the analytics tools, which are in the always-on category; Google's own tag, which runs with every advertising purpose denied โ but still sets its analytics cookie, and hits still reach Google whether you accept, decline or never answer; the Trustpilot review widget where an operator has enabled it, which can set its own storage before you answer; and a third-party live-chat widget where one is enabled, which is placed in the page itself.
There is a fifth case a consent banner structurally cannot cover: Google Consent Mode is JavaScript, so a visitor browsing with scripts disabled has no banner to answer, and Google Tag Manager's no-JavaScript fallback still loads.
Three more rows in ยง18.3 are not consent questions at all:
- Security โ Cloudflare Turnstile, the security check on the sign-up, sign-in, forgot-password and contact forms, on withdrawal requests, on the support chat for signed-out visitors and, from the third attempt, on the admin console's sign-in. Strictly necessary, no consent needed; it does see your IP and browser, as any anti-abuse check must. See Fraud and bot protection.
- The support chat you actually get is Onflow Ads' own AI chat, which is part of the page rather than a third-party tag. Your messages go to the platform's AI model provider as a processor (ยง12.2); no chat vendor is involved. Crisp remains an alternative an operator can enable instead, and that one is a third-party widget.
- Platform and page assets โ Telegram's sign-in script on the Telegram sign-in pages, a payment provider's checkout script on the top-up page, and the library CDNs behind a few interactive pages. Loading a script from another host discloses your IP and browser to that host, as it would on any website.
The Trustpilot invite in the footer is, since September 2026, our own link to Trustpilot's review page โ it loads nothing from Trustpilot and sets nothing; only a paid TrustBox, where an operator has configured one, still renders Trustpilot's own widget. The Google review badge beside it is not a third-party tag at all: it is Onflow Ads' own markup showing a rating entered by hand, and it reaches Google only if you click it.
Because analytics sits in the always-on category, the preference centre is not the control for it โ your browser is. Every current browser ships tracking protection and every content blocker stops the tools in ยง18.3 from loading at all. Onflow Ads does not detect, discourage or work around any of them, does not degrade the service when one is on, and nothing on the site is built to survive being blocked. The service works normally with every analytics tool blocked (ยง18.5).
One line of caution on going further: the four strictly necessary cookies in the table above are the sign-in mechanism, not a tracking layer. Blocking those will sign you out and stop you signing back in.
What GPC asks a site to stop is selling or sharing โ in practice, the behavioural-advertising tags. A GPC signal is honoured automatically (ยง18.4): where your browser sends one, marketing is recorded as refused in that browser, no advertising tag loads, and the banner is not shown at all; the preference centre in the footer stays reachable if you ever want to change it. A browser without the signal is simply asked, and Reject all puts it in the same state. The older "Do Not Track" header has no agreed meaning and is not relied on.
Three more things ยง18.3 states about the analytics itself: a signed-in member is identified to Google Analytics or PostHog by their public OFA- id, never their email; the admin console loads no analytics at all; and the guide at docs.onflowads.com carries the same Google tag and the same Clarity tag, added as each page is served, in the same advertising-denied state, with no banner because nothing refusable runs there.
The consent requirement itself is an operator setting, and it is on. Turning it off would let the advertising tags load without asking, so ยง18.3 treats switching it off as a material change to the policy needing the 30 days' notice in ยง26.1 โ exactly as narrowing any other commitment would.
Messagesโ
- Service messages โ codes, receipts, order and payout notices, expiry reminders โ cannot be switched off while you hold an account.
- Marketing is opt-in: nothing is sent unless you ticked the unticked "Send me product news and offers" box at sign-up or on a top-up checkout, or switched it on in your notification settings. Every such email carries a one-click unsubscribe that works without signing in, and the setting is re-checked as each message is sent. Segments are built from tier, role and signup recency โ never from your message content, creative or tickets.
- Telegram messages stop if you turn the category off or block the bot. Browser push needs your browser's permission and stores only the endpoint, keys and User-Agent.
How long data is keptโ
| Data | Retention |
|---|---|
| Account, profile, channels, listings | While the account is open; deleted or anonymised on closure |
| Orders, deals, delivery evidence | Up to 8 years from completion |
| Payments, payouts, invoices | Up to 8 years as an accounting record โ with the books and the payment provider. The wallet ledger inside your account is deleted when the account is |
| Support tickets | Up to 3 years after the matter closes |
| AI support conversations | 14 days after the last message, deleted automatically โ unless escalated to a ticket, which then governs, or reported to the team, in which case the conversation is kept while the report is open and the ordinary 14-day rule resumes once the report is closed. A chat auto-closes after 30 idle minutes and its transcript is emailed to you |
| Device records (ยง5.5) | While the account is open and while any debt they corroborate is unpaid; no automatic expiry today |
| Taps, landings, conversions and invite-link joins | With the campaign โ they carry a salted hash, never a person |
| The signed-out support-chat handle and its counter | 180 days from last use |
| Verification codes and sessions | Minutes to hours โ they expire by design |
| Security and activity records | See below โ the honest answer is longer |
| Aggregate statistics | Indefinitely (not personal data) |
There is no automatic expiry over security and activity records today. They are kept while useful for security, fraud investigation and defending claims, and reviewed periodically. The policy says so rather than quoting a period the system does not yet enforce. You can ask for them to be dealt with sooner under ยง22.
Backups: encrypted copies of the database are taken on a regular cycle and held off-site for a limited period, so deleted data can persist in a backup for a short time afterwards. Backups are never used to restore a record that was deliberately deleted. The schedule, the retention window and where they live are deliberately not published โ that detail would help an attacker and tells you nothing about your own data.
What survives closureโ
- Financial and order records, for the periods above.
- Security and activity records โ including the email address and name carried by the request, the IP, country and browser โ with the link to the account severed but the entries kept.
- Support tickets, and copies of emails already sent to you.
- Referral and affiliate attribution, and the identifiers inside a completed cross-promotion pairing โ both describe a relationship with another user.
- Creative you published. Delivered images are cached to be fast and can stay retrievable by direct URL; creative sent to Telegram to be posted lives on Telegram's servers under their retention.
- What was done about the account, and why โ a suspension, a ban, a moderation decision and the reason given for it โ plus every Onflow Ads ID the account was ever issued (Terms ยง15.5, ยง24.4 and ยง29).
- An anti-evasion marker, but only if you leave with standing below baseline: a one-way hash of your email address plus the standing you would resume at. The restriction lifts after 90 days (upheld fraud) or 45 days (anything else). Leave in good standing and nothing is written at all. See Account standing.
- What another user legitimately holds about a deal you did with them, and content already published.
Securityโ
Encryption in transit; passwords stored only as argon2id hashes and re-hashed as parameters improve; optional 2FA; session tokens that rotate and can be revoked everywhere at once; forced sign-out from every device on a password reset; a sign-in email that you cannot change yourself once it is set (the team can move it for you: the new address confirms the change and the old one is told at once); rate limits and lockouts keyed on hashed identifiers; bot-checks on public forms; staff access granted area by area (read or act) with the most damaging actions reserved to the platform owner, administrators signing in again at least every twelve hours, and every administrative request โ a refused one included โ recorded with who did it, what it was and which member it concerned.
No system is perfectly secure, and the policy does not pretend otherwise. What it commits to is taking those measures, reviewing them, telling you when something goes wrong, and not quietly weakening a protection the document describes.
Onflow Ads will never ask you for your password, a verification code, a card number, a UPI PIN or your Telegram login code. Anyone who does is not Onflow Ads. Report a security flaw through the contact published at onflowads.com/.well-known/security.txt โ today the support mailbox, with "security" in the subject line โ or see Trust and safety; good-faith researchers will not be pursued. The rate limits and automated protections themselves are stated in plain terms in Terms ยง16.7, and ยง21.5 of the policy explains what their counters hold: an IP, an account id or a hashed email, for the window they meter, then gone โ and they all fail open.
Your rightsโ
Every right below is extended to every user, wherever you live:
| Right | What it means |
|---|---|
| Access | What is held, what is done with it, and who it went to |
| Correction and completion | Fix, complete or update anything wrong or stale |
| Erasure | Delete what is no longer needed โ with the honest limits above |
| Portability | A structured, machine-readable copy |
| Withdraw consent | The advertising tags behind the cookie banner, and marketing email โ both as easy to withdraw as to give: the toggle in your notification settings, or the one-click link in any such email |
| Object and restrict | Object to legitimate-interests processing, or pause it while a dispute is resolved |
| Human review | A person looks again at an automated decision |
| Nominate | Name someone to exercise your rights if you cannot (DPDP Act) |
| Opt out of sale/sharing | US state law โ honoured regardless, since neither happens |
| Non-discrimination | Exercising a right costs you nothing in service, price or standing |
How to use themโ
- Write from the account's email address to [email protected], or use the contact form.
- Name the right you are exercising.
- Include enough to find the record โ account email or OFA ID, and for anything order-related the reference and dates.
- For a correction, say what the correct value is. For a deletion, say whether you want the whole account gone or only specific data.
Acknowledged within 72 hours, answered within 30 days. It is free, unless a request is manifestly unfounded or repetitive โ and you would be told before, not after.
Some things need no request at all: disconnect a channel, update your own details from the dashboard, reopen Cookie preferences from the site footer, or control cookies in your browser.
A request can be declined where the law requires keeping the data, where it is needed for a legal claim or a live dispute, where complying would expose someone else's data, where the data is held on your instructions as controller, where identity cannot be verified, or where erasure would defeat the anti-evasion marker while it is still in force. You are told which reason applies, the rest of the request is honoured, and you can escalate.
Childrenโ
Onflow Ads is for adults: you must be at least 18, or the age of majority where you live if higher. No data is knowingly collected from anyone under 18, no advertising is directed at children, and no child is tracked or profiled. If a child has provided personal data, write to [email protected] and it will be dealt with promptly.
If your own channel's audience includes children, you must not use the Services to advertise to them anything you could not lawfully advertise to a child.
Complaintsโ
Raise it first with [email protected] with "Grievance" in the subject. Acknowledged within 24 hours, disposed of within 15 days.
If that does not resolve it: the Data Protection Board of India; your national supervisory authority in the EEA, UK or Switzerland; or your local authority elsewhere. You are never required to arbitrate or waive a statutory complaint route.
Breaches, changes and contactโ
-
Breaches โ you are notified without undue delay, in plain language: what happened, what data, likely consequences, what has been done and what you should do. Regulators are notified within their deadlines, including 72 hours where the GDPR applies. Notification will not be delayed to protect reputation.
-
Changes โ a material change gets 30 days' notice and applies prospectively only. Corrections and changes that reduce collection take effect on publication. Ask and you will be told what the policy said on any past date.
-
Additional Privacy Terms โ ยง27 anchors disclosures published between deploys (a new processor, a new purpose, a new country). It is filled from the platform when the page loads, each entry shows the date it was added, and each forms part of the notice. If the feed cannot be read the page shows the drafted policy alone rather than an error.
-
Onflow Ads IDs โ ยง28 covers the short reference carried by nearly every record (
OFA-204-7831). It is assigned at random, encodes nothing about you, is never an advertising identifier, and is pseudonymous personal data carrying every right in ยง22. The same section discloses what sits on a payment record โ the IP, User-Agent and device summary behind a top-up, withdrawal or refund request โ and what the ID registry and the moderation record keep after an account is deleted. See Your Onflow Ads IDs. -
Social media โ ยง30 covers the Follow us row of links to our Telegram updates channel and social profiles. It is made of plain links: it embeds no widget, feed or script from any network, so showing it sends them nothing. A platform learns of your visit only if you click, under its own policy. The links in emails carry no click-tracking redirect and the bot's buttons are plain links. We do not connect what you do on those profiles to your Onflow Ads account, keep no record of who follows us, and do not run support in their direct messages. See Official channels and social media.
Contact: privacy and data rights โ [email protected] ยท everything else โ [email protected] or onflowads.com/contact ยท a security vulnerability โ onflowads.com/.well-known/security.txt ยท the operator's registered name, address and Grievance Officer are stated in ยง1.1, ยง24.2 and ยง29 of the full policy
Frequently asked questionsโ
Does Onflow Ads sell my data?โ
No โ not for money, not for other valuable consideration, not to a data broker, and not for behavioural advertising. It is shared only with a counterparty to run your deal, and with providers who run part of the platform.
I rejected cookies. Why does the site still measure me?โ
Because the two categories are not what most banners imply. Marketing is what "Reject all" switches off, and it switches off completely. Analytics โ PostHog, Clarity and Google's tag in its advertising-denied state โ sits in the always-on Essential category and loads with the page. ยง18.3 states this rather than hiding it, and ยง18.5 points at the control that does stop it: your browser's tracking protection or a content blocker.
Can my trading partner see my email address?โ
No. They see your channel profile and figures, the creative, your public trust signals and the delivery evidence for your deal โ never your contact details, balance, ledger or other campaigns.
Does Onflow Ads store my card number?โ
No. Payment instruments are entered on the provider's own checkout. What comes back is an amount, a status and a reference.
Does the AI train on my content?โ
No. Your data is not used to train AI models and your content is not licensed to anyone for training.
Does my support ticket go to an AI?โ
It can, where AI drafts or triages the reply โ including your name and what you wrote. Ask support to switch AI off for your account and a person handles every message instead. A request typed inside a message has already been sent by the time anyone reads it.
Why did I never see a cookie banner?โ
It appears on a first visit only when there is something to disclose โ that is, only when at least one tracking or advertising tool is actually configured on the deploy you are using. Where none is, asking permission for nothing would be theatre, so nothing is shown. Cookie preferences in the footer opens the dialog at any time regardless.
Do you know who clicks my ads?โ
No. A tap at our redirect is a salted, non-reversible hash plus country, referrer and device; a join through a campaign invite link is a salted hash of the member. The only exception is a button on an older Subscriber Exchange placement that still opens the bot, which records the tapper's numeric Telegram user id so genuine taps can be paid for โ and nothing new is published that way.
If I close my account, is everything gone?โ
No, and the policy is explicit about it. Financial records, security and activity records, support tickets, sent-email copies, what was done about the account and โ if you leave below baseline โ a one-way anti-evasion hash all survive. Everything else is deleted or anonymised.
What ID documents do you need for payouts?โ
None through the platform. Verification collects your legal name and country. If a payment provider or the law ever requires more for a specific payout, you will be told what, who it goes to, and why, before you send it.
Next: Cookie preferences โ where the dialog lives, what each of its three buttons does, and why turning Marketing off reloads the page.