When you connect an account, the network asks the account holder to approve a set of permissions. This page explains what Fluxi does with them, so you, or a client you manage accounts for, can approve with confidence.
What Fluxi uses a connection for
Fluxi uses a connected account for two things:
- Publishing the posts you schedule, at the time you schedule them.
- Showing which account is connected: its name, handle and profile picture, so you can tell accounts apart in the app.
Fluxi does not read your direct messages, reply to comments, follow accounts or post anything you did not schedule.
What the approval screen may list
Networks group permissions in their own way, so some approval screens list more than publishing:
- Instagram also lists permissions for messages, comments and insights. Fluxi does not use them.
- LinkedIn also lists permissions for the company Pages you administer. Fluxi only uses them to post as a Page, when you connect a LinkedIn Page.
- Facebook lists the Pages you choose to share, and permission to post to them.
- YouTube lists uploading videos and viewing your channel. Viewing is only used to show the channel's name and picture.
What Fluxi stores
- No passwords. Every network except Bluesky connects through the network's own approval screen, so Fluxi never sees the account's password. Bluesky uses an app password, which Fluxi uses once to start a session and then discards.
- An access token that the network issues for Fluxi. It is encrypted before it is stored.
- The account's name, handle and profile picture, for display in the app.
How to revoke access
In Fluxi: disconnect the account from the portfolio. See Connect a social account. This deletes the stored access token straight away, so Fluxi can no longer post to the account.
On the network: to remove Fluxi from the network's own list of connected apps as well, revoke it there. The menus move from time to time, but it is usually here:
| Network | Where to revoke |
|---|---|
| X | Settings and privacy → Security and account access → Apps and sessions → Connected apps |
| Settings → Data privacy → Permitted services | |
| Settings → Website permissions → Apps and websites | |
| Threads | Settings → Account → Website permissions |
| Settings and privacy → Settings → Business integrations | |
| TikTok | Settings and privacy → Security and permissions → Manage app permissions |
| YouTube | Your Google account → Security → Third-party apps and services |
| Bluesky | Settings → Privacy and security → App passwords |
Revoking on the network cuts off Fluxi's access. The account stays listed in Fluxi, but posts scheduled to it will fail until it is reconnected, and it shows Reconnect needed once Fluxi's next attempt to refresh the connection is refused. If you do not plan to reconnect, disconnect it in Fluxi as well.
Managing a client's accounts? The client can revoke Fluxi's access from their side at any time, without asking you and without changing their password.