Contents
Before you connect
Connecting an account gives SocFlow permission to read activity on it and, if you build rules that use write actions, to take actions on it automatically. Read this before you connect anything.
What connecting an account gives SocFlow
Depending on the platform, connecting either uses OAuth (you authorize SocFlow directly on the platform's own sign-in screen) or an app password (a scoped credential you generate yourself, separate from your main password). Either way, SocFlow only requests the permissions a platform's automation actions need — typically read access plus write access for replies, posts, DMs, or labels. Each platform's connect guide lists exactly what's requested.
What SocFlow can and can't do with it
SocFlow can only do what a rule you've built tells it to do, using the permissions you granted. It can't read DMs you haven't given it access to, change your account settings, or take any action you haven't configured a rule for. It never sees or stores your platform password — connections use OAuth tokens or app passwords, and those are encrypted at rest (see data & token security).
Disconnecting doesn't delete your rules
Disconnecting an account pauses and archives its rules rather than deleting them. Reconnect the same account later and they come back. See disconnecting & reconnecting.
Rules to respect
SocFlow is an interface, not your account manager
Pick your platform below for the exact connection steps and permissions requested.