Trust & Security

How we look after your data and money

This page is maintained by the Flow Monetizer team to answer common security and privacy questions about our platform. It is editable app content, not an independent audit or certification.

Authentication & accounts

  • • Email + password and Google sign-in via our managed auth provider.
  • • Sessions are stored in your browser and refreshed automatically.
  • • Admin areas are protected by a server-verified role check, not just a UI guard.
  • • You can reset your password from the sign-in page at any time.

Data in transit & at rest

  • • All traffic to Flow Monetizer is served over HTTPS.
  • • Application data is stored in our managed Postgres database with row-level security.
  • • Sensitive creator fields (balances, payout details, legal name) are only readable by the owner of the record.
  • • Public creator storefronts only expose display-safe fields (handle, name, bio, avatar, socials).

Payments

  • • Fan payments settle in ETH straight into platform escrow. We never hold card numbers.
  • • Every escrow transaction is verified on-chain before a balance is credited.
  • • Creator payouts are reviewed by an admin and marked paid only after the funds leave our account.

What we collect

  • • Account: email, display name, handle, optional avatar and bio.
  • • Creator profile: optional payout method, location, social links you choose to share.
  • • Activity: clicks on your money links and completed purchases — used to power your dashboard.
  • • We do not sell personal data and we do not use third-party advertising trackers.

Shared responsibility

Flow Monetizer secures the platform — authentication, database access rules, payment verification and admin tooling. You are responsible for keeping your account credentials safe, choosing a strong password, and protecting access to the email address tied to your account. Report anything suspicious immediately.

Reporting a security issue

If you believe you have found a vulnerability or you want to request account deletion, contact us from the in-app security@flowmonetizer.world page. We aim to acknowledge security reports within 3 business days.

This page reflects current practices and may be updated as the product evolves. It does not constitute legal advice or an independent security certification.