Welcome to Zilfu ("we," "our," or "us"). This Privacy Policy explains how we collect, use, and protect information when you use our social media management platform at https://zilfu.app. By accessing or using our Service, you agree to the terms outlined in this policy.
1. Who We Are
Zilfu is operated by Kudo Consulting LLC, a limited liability company registered at 930 Washington Ave, Ste 210-19, Miami Beach, FL 33139, USA. Kudo Consulting LLC is the data controller responsible for the personal information described in this policy.
- Service: https://zilfu.app
- Contact for privacy matters: info@zilfu.app
2. Information We Collect
Our service collects specific types of information:
- Personal Information: When you create an account, we collect your name and email address. We do not collect phone numbers.
- Usage Data: We gather data about service usage, including IP addresses, browser types, and page visits.
- Cookies: We employ cookies to enhance user experience, which you can manage through your browser settings.
3. Connected Social Accounts
Zilfu's core purpose is to publish content you have written to social accounts and pages you own or administer. To do this, you connect each account to Zilfu through that platform's official authorization flow (OAuth), where the platform — not Zilfu — asks you to approve the specific permissions we request. Supported platforms are LinkedIn, Facebook, Instagram, Threads, X, TikTok, and Pinterest.
For each account you connect, we store:
- The account's identifier on that platform, its display name or handle, and its profile or page picture, so you can tell your connected accounts apart in the interface
- The access and refresh tokens the platform issues, together with the permissions you granted. Tokens are encrypted at rest and are never exposed in the interface or shared with anyone
- The content you compose in Zilfu and the schedule you set for it, along with the identifier the platform returns once the content is published
- Aggregate performance figures for your own posts and pages, such as impressions, reactions, comments, clicks, and follower counts
We use this information solely to operate the Service for you: to publish content you authored, at times you scheduled, to accounts you connected, and to show you how that content performed. We act only on your instructions and only on accounts you own or administer.
We do not collect, store, or display the personal data of other people who interact with your content on these platforms. We do not scrape, crawl, aggregate, sell, license, or otherwise redistribute platform data, we do not use it for advertising or ad targeting, and we do not use it to train machine learning or AI models.
You can disconnect any account at any time from within Zilfu. When you do, we delete the stored tokens and the platform profile data for that account. Your use of each platform remains governed by that platform's own terms and privacy policy.
4. Use of Information
We utilize collected information for these purposes:
- Service provision and maintenance
- Publishing and scheduling content to the social accounts you have connected
- Service improvement through analysis using PostHog
- Usage monitoring and service optimization
5. Analytics Implementation
Our service uses PostHog (provided by PostHog Inc.) to understand website usage patterns. PostHog data is processed on EU-based servers (eu.posthog.com). It collects:
- IP addresses
- Browser and device information
- Page visit and interaction data
- For signed-in users, an identifier linked to your name and email address
PostHog acts as our data processor and uses this information solely to provide analytics on our behalf. We do not sell this data or share it with third parties for advertising. For more detail, see PostHog's privacy policy.
Until you accept analytics cookies, PostHog runs in a cookieless mode: it stores nothing on your device and counts visits using a privacy-preserving identifier derived on the server, without cookies or local storage. Accepting analytics cookies enables full, cookie-based analytics (including linking activity to your signed-in account); you can withdraw this at any time from “Cookie settings”, which returns PostHog to the cookieless mode and clears its cookies.
6. Affiliate Partnership
Zilfu runs an affiliate program using Rewardful. When you arrive through an affiliate link, this system:
- Stores a referral identifier locally on your device
- Communicates with Rewardful to attribute the referral and credit the affiliate
- Does not share your personal data with Rewardful or other third parties for advertising
For more detail, see Rewardful's privacy policy.
7. Cookie Usage
Cookies are small data files stored on your device that help remember your preferences, understand site usage, and enhance your browsing experience. We group the cookies and similar technologies we use into three categories:
- Strictly necessary: Required for the site to function, including authentication, security, and remembering your current workspace. These are always active and cannot be disabled.
- Analytics: Help us understand how visitors use Zilfu so we can improve the product. We use PostHog, processed on EU-based servers.
- Marketing: Attribute sign-ups to the partner who referred you so we can credit our affiliates (Rewardful), and measure sign-ups that originate from our ads on Meta using the Meta Pixel and Conversions API (cookies _fbp and _fbc).
When you first visit, a consent banner lets you accept all categories, reject everything that is not strictly necessary, or choose individually. Non-essential cookies are not set until you opt in. You can review or change your choices at any time using the “Cookie settings” link in the footer, and you can also manage cookies through your browser settings, though disabling them might limit certain site functionalities.
We also offer an in-app support chat (Crisp) so you can reach us for help. The chat is available within the app, but it only stores a conversation cookie once you open and use it — a service you have explicitly requested — so it sits outside the categories above. See Crisp's privacy policy.
With your consent to marketing cookies, we measure sign-ups that originate from our advertising on Meta (Facebook and Instagram). We use the Meta Pixel together with Meta's Conversions API to record a single account-creation event. We share a hashed (irreversible) version of your email address and an account identifier, along with technical data such as your IP address and browser, so Meta can attribute the sign-up to a campaign and deduplicate the browser and server signals. This stores the _fbp and _fbc cookies on your device. Nothing is collected or sent to Meta unless you accept marketing cookies, and you can withdraw consent at any time from the “Cookie settings” link, which clears these cookies. See Meta's privacy policy.
8. Security Measures
We maintain security measures designed to protect the information we hold against unauthorized access, improper disclosure, and misuse:
- All traffic to and from the Service is encrypted in transit using TLS
- Social platform access and refresh tokens are encrypted at rest
- Access to production systems is restricted to authorized personnel and protected by strong authentication
- Your data is separated by workspace, and access is enforced on every request by ownership checks
No system can be guaranteed completely secure, but we review these measures regularly and act promptly on any issue we identify.
To find and fix faults, we use Sentry (provided by Functional Software, Inc.) to record technical details of errors that occur in the Service: the error itself, the page and browser it happened on, and the identifier of the account that was signed in. We use that identifier only to judge how widely a fault has spread and to reach you if it affected your work. We do not attach your name or your email address to these reports, and access tokens and other credentials are stripped from them before they are sent. An error report describes the failure, not what you publish. Because this is how we keep the Service working and secure rather than a way of measuring how you use it, it does not depend on cookie consent, and it stores nothing on your device. For more detail, see Sentry's privacy policy.
9. Data Retention and Deletion
We keep information only for as long as it is needed to provide the Service:
- Connected accounts: tokens and platform profile data are deleted when you disconnect the account or when your Zilfu account is closed
- Posts and media: retained while your account is open, so you keep your history and scheduled queue, and deleted when you delete them or when your account is closed
- Performance figures: retained while the related account remains connected
- Account and billing records: retained while your account is open, and afterwards only where we are legally required to keep them, such as for tax and accounting purposes
You can disconnect any connected social account, and delete your posts, media, and workspaces, directly in the product at any time. To close your Zilfu account entirely, write to info@zilfu.app and we will delete your personal information and platform data, except where we must retain records to comply with a legal obligation. Encrypted backups are rotated on a rolling schedule, and deleted data falls out of them as that rotation completes.
10. Policy Updates
This privacy policy may be updated periodically. We will:
- Post any changes on this page
- Consider changes effective upon posting
- Notify users of significant updates
11. Contact Information
For questions or concerns regarding this privacy policy, please reach out to info@zilfu.app.