Data and security
How client data is protected
onfleeksocial.com · operated by on fleek GmbH
on fleek Social holds the content, the media and the account connections of independent companies we work for. Each of these companies has an area of its own, and its contacts see that one area and nothing else. The separation is not a matter of the interface — it is enforced on the server with every access: a client login receives only data of the company that follows from its signed-in session, never data of a company that arrived with a request.
The second sensitive point is the access tokens of the connected social media accounts. They are stored encrypted in the database, are decrypted on the server only and only immediately before the platform in question is called, and never reach the browser.
A separate area for every client company
A client login belongs to exactly one company. Whatever else is held in the application does not exist for that login.
- A client company's login is tied to that company's area. Posts, media, comments, accounts and analytics belonging to other companies are neither visible nor retrievable through it.
- The assignment is derived from the session on the server. An identifier passed in with the request changes nothing: the server checks every record retrieved against this assignment.
- The on fleek team works across the companies it serves, because it produces the content; individual team members can be restricted to particular clients. When an agency login requests a client's data, the server checks whether it may look after that client. Within the team, the right to manage client records, to connect and disconnect social accounts, to use the AI features, to approve on the client's behalf or to archive and delete posts can be graded further. Only agency admins may add and remove portal users, delete clients and take on the view of a client login.
- If someone from the team temporarily takes on the view of a client login in order to help, the real identity behind it is written to the audit log.
Logins and signing in
on fleek creates the logins. There is no open self-registration — no page exists on which anyone could create an account for themselves.
- A newly created account is not sent a password in plain text by email, but a signed sign-in link that is valid for that one account and expires. The user chooses the password.
- Passwords must be at least ten characters long. Resetting works through a single-use, time-limited link sent to the address on file.
- Agency logins can require a second step at sign-in: a code from an authenticator app, or alternatively a code by email, together with backup codes for emergencies.
- When a login is suspended, the suspension applies to every further request — not only from the next sign-in onwards.
Platform access tokens
Connecting an Instagram, Facebook, TikTok or YouTube account makes that provider issue tokens: depending on the platform an access and a refresh token, for Facebook Pages also a page token. We store no password belonging to the account holder, only these tokens — encrypted with AES-256-GCM, using a key that exists in the server environment alone.
Decryption happens on the server only, and only at the moment a call to the platform is due or a token is being refreshed. Tokens are never logged and never handed to the browser; no record that reaches the interface carries them. A key change is provided for: a stored previous key still allows older values to be read, while writing always uses the current one.
The connection status of every account is visible in the application — connected, expiring, disconnected or in error. When a connection runs out or the account holder revokes the grant as a whole, the application deletes the stored tokens as soon as it detects this, and shows it in the connection's status instead of passing over it silently. When the regular checks of Meta and TikTok connections detect it, an email also goes to the agency team as the connection enters this state; for Meta's revocation callback and for YouTube it stays with the status display. If someone removes only individual accounts from the grant at Meta, those accounts are put into an error state and nothing further is published through them; the connection's tokens are then kept for the remaining accounts until they are disconnected or reconnected, as is the page token of a Facebook Page removed in this way.
Media
Images and videos are not left open on the internet. The server delivers them only after checking the sign-in; what a signed-in browser has loaded once, only that browser may cache.
Signed in, or not at all
The exception when publishing
Checked media
Stored per client
Hosting and transport
- Hosted in Germany: application, database and media storage run in an environment of their own on a server of Hetzner Online GmbH in the Nuremberg data centre — not in a shared multi-tenant system of a third-party provider.
- The application is reachable over HTTPS only; browsers are pinned to it via HSTS.
- Further protective headers prevent the application from being embedded in other sites and block access to camera, microphone and location.
- No tracking takes place. Only technically necessary cookies are set, such as the session cookies for signing in, on request a cookie that remembers a device as trusted for two-factor sign-in, and, inside the agency area, a cookie that remembers the client last selected; the privacy policy describes the individual cookies. Fonts and other assets come from our own servers — including the profile pictures of connected accounts, which the server fetches from the platform instead of sending the browser there. The exceptions are the bug reporting tool, which we operate ourselves on the same server, and the Reel music preview in the agency's post editor, which the browser loads directly from Meta when a track is played.
- The staging environment is separate from production and never publishes against real platform APIs.
The record: who approved what, and when
Publishing is a commitment we make to the client. That is why it stays traceable how a post got there.
Every status change of a post runs through a single, checked transition function and writes an entry to the audit log as it does so: who acted, whether as the agency, as the client company or as an automated job, when it happened, and which status followed which. Entries are only appended, never overwritten, and are deleted automatically after 24 months. They change afterwards in two cases only: when a login or client is deleted, the entries' link to it is dropped (its bare identifier may remain as the record concerned), and we remove the email address of a deleted login from the entries. And names of connected platform accounts that older entries still contain are removed no later than 30 days after the entry.
Only what has been approved and then scheduled is ever published — the application holds no route around this state machine. The on fleek team sees the log entries in an activity view of its own, filtered by client and by the kind of actor. In addition, the application keeps the approval history per post, with comments, change requests and versions.
Disconnecting and deletion
- An account holder can revoke the permission granted to on fleek Social at any time, directly with the platform. For Facebook and Instagram, Meta notifies us of the revocation of the grant through a callback: the stored access tokens are deleted straight away and the connection is marked as disconnected. In addition, the application checks the Meta tokens every hour: invalid or expired tokens are deleted; if only individual accounts were removed from the grant, those accounts are put into an error state and nothing further is published through them, while the connection's tokens remain for the other accounts, as does the page token of a Facebook Page removed from the grant. For TikTok and YouTube the application does not process any such notification — there it notices the revocation at the next token renewal, for TikTok at least once a day, for YouTube for example during the nightly metrics run or at the next publishing attempt. It then deletes the stored tokens straight away, puts the connection into an error state and publishes nothing further through it.
- When an account is disconnected inside the application, its tokens are deleted straight away; the shared token of a Meta connection serving several accounts once all of those accounts are disconnected. For YouTube we also ask Google to revoke the grant. The application publishes nothing further through a disconnected account.
- When work with a client company ends, we delete it in the application once all of its accounts are disconnected and no publishing is in progress: posts, media, connections and the logins of its contacts in one step from the database, the files immediately afterwards from storage. Audit log entries remain until their 24-month period ends, without the email addresses of the deleted logins. Whatever has already been published on Instagram, Facebook, TikTok or YouTube stays online there. Statutory retention obligations remain unaffected.
- Access to information and deletion can be requested at any time at info@agenturonfleek.com — by an account holder directly, too, without going through us as the agency.
Which data is processed for which purpose, how long it is kept and what rights data subjects have is set out in full in the privacy policy.
Questions about data and security?
on fleek GmbH · Industriestr. 10 · 92360 Mühlhausen · Germany. We answer questions about connected accounts, stored data and deletion ourselves.