Security and data

Your credentials stay on your Mac.

SignalFlow is built so that the parts that touch your accounts are the smallest and best-guarded parts of the app. This page describes how it works today.

Principles

Six rules the code follows

One user-only credential file

Platform tokens and API keys live in a single file on your Mac that only your user account can read.

Tokens stay out of the interface

You can type a Meta app secret or token into Settings, but the interface only ever reads back whether one is set. Page tokens are used by the desktop process and the local control plane.

No cookie or password extraction

Subscription routes drive a visible browser profile that SignalFlow owns. SignalFlow never reads your everyday browser profile, its cookies or its saved passwords.

No secrets in queues or databases

Publishing jobs carry approved content only. The control plane refuses any field shaped like a token, cookie or key before it saves anything.

Local services only

The control plane and the background worker listen on your own computer only, and the worker refuses to forward jobs without a shared authorisation token.

A person approves every post

Automation creates drafts. Approval, a publishing preflight and an idempotency key guard every post that reaches the public.

Where your data goes

Nothing reaches us by default

Brands, drafts, schedules and media records
A local database on your Mac
Platform tokens and API keys
The user-only credential file on your Mac
Prompts and brand context
The AI provider you choose, under its own terms
Approved posts
The platforms you connect, through their official APIs
Meton Labs
Nothing, unless you send us logs or screenshots for support

This website has no forms, accounts or tracking cookies. Read the full privacy policy for details. Privacy policy

Review the code

Read it for yourself

A sanitized snapshot of the SignalFlow source is public on GitHub. Client data has been removed, sample data is fictional, and the browser-automation modules are encrypted.

Report a vulnerability

Found something? Tell us first.

Email [email protected] with the steps to reproduce the issue. Please give us a chance to fix it before you share it publicly. Our security.txt has the same contact details.