When you connect an account, the network asks the account holder to approve a set of permissions. This page explains what Fluxi does with them, so you, or a client you manage accounts for, can approve with confidence.
What Fluxi uses a connection for
Every connection is used for two things:
- Publishing the posts you schedule, at the time you schedule them.
- Showing which account is connected: its name, handle and profile picture, so you can tell accounts apart in the app.
Some features need more, and only run when you turn them on:
- Automations read a post's likes and reposts after it publishes, and repost it or reply underneath it as you set up.
- Keyword replies read the comments on the account's posts and the direct messages it receives, and send a reply or message to people who use one of your keywords.
Fluxi never posts, replies or sends a message you did not set up, and it does not follow accounts or like posts. If an account has no automations and no keyword replies, Fluxi does not read its comments or messages at all.
What the approval screen may list
Networks group permissions in their own way, so here is what each one is for:
- Instagram lists messages, comments and insights. Fluxi uses them for keyword replies and automations.
- Facebook lists the Pages you choose to share, and permission to post to them, read and manage engagement and send messages as the Page. The last ones are for automations and keyword replies.
- Threads lists publishing, replies and insights. Replies and insights are for automations and keyword replies.
- X asks for permission to read, write and send direct messages. Direct messages are only used for keyword replies.
- LinkedIn also lists permissions for the company Pages you administer. Fluxi only uses them to post as a Page, when you connect a LinkedIn Page.
- YouTube lists uploading videos, viewing your channel and managing comments. Viewing is used to show the channel's name and picture, and comments are only used for keyword replies.
- Bluesky uses an app password. If you want keyword replies, tick Allow access to your direct messages when you create it.
What Fluxi stores
- No passwords. Every network except Bluesky connects through the network's own approval screen, so Fluxi never sees the account's password. Bluesky uses an app password, which Fluxi uses once to start a session and then discards.
- An access token that the network issues for Fluxi. It is encrypted before it is stored.
- The account's name, handle and profile picture, for display in the app.
- Comments and direct messages, only for accounts with a keyword reply turned on, so Fluxi can answer them and show you its activity. They are deleted when you disconnect the account or delete the portfolio.
How to revoke access
In Fluxi: disconnect the account from the portfolio. See Connect a social account. This deletes the stored access token straight away, so Fluxi can no longer post to the account.
On the network: to remove Fluxi from the network's own list of connected apps as well, revoke it there. The menus move from time to time, but it is usually here:
| Network | Where to revoke |
|---|---|
| X | Settings and privacy → Security and account access → Apps and sessions → Connected apps |
| Settings → Data privacy → Permitted services | |
| Settings → Website permissions → Apps and websites | |
| Threads | Settings → Account → Website permissions |
| Settings and privacy → Settings → Business integrations | |
| TikTok | Settings and privacy → Security and permissions → Manage app permissions |
| YouTube | Your Google account → Security → Third-party apps and services |
| Bluesky | Settings → Privacy and security → App passwords |
Revoking on the network cuts off Fluxi's access. The account stays listed in Fluxi, but posts scheduled to it will fail until it is reconnected, and it says Reconnect to keep publishing once Fluxi's next attempt to refresh the connection is refused. If you do not plan to reconnect, disconnect it in Fluxi as well.
Managing a client's accounts? The client can revoke Fluxi's access from their side at any time, without asking you and without changing their password.