Security

Your fleet.
Your pages. Your data.

FLAY runs many fleets on one platform. The whole design assumes none of them should ever be able to see, touch, or post as another.

Who Sees What

Three roles.
No gray areas.

Access is decided by role and by boat assignment, enforced in the database, not by hiding buttons in the interface.

Level 1

Captain

Uploads and views media for the boats assigned to them. Nothing else.

  • Upload photos and video from the phone
  • See their own boats' library
  • See other boats or other fleets
  • Touch channels, calendar, or settings
Level 2

Fleet admin

Runs the business. Full control of everything inside their own fleet.

  • Boats, captains, and boat assignments
  • Media library, pool, calendar, captions
  • Social channels, slots, posting rules
  • See or affect any other fleet
Level 3

Platform

FLAY operations. Provisions fleets, watches health, fixes what breaks.

  • Create and configure fleets
  • Monitor errors and posting health
  • Restore from backups
  • Post to your pages on their own initiative
Isolation

Every row knows
who it belongs to

Every table in FLAY carries a fleet ID, and the database itself refuses to return a row to anyone from a different fleet. The app can't leak what the database won't hand over.

Fleet A
boatsfleet A
mediafleet A
channelsfleet A
calendarfleet A
storage/fleet-a/…
Fleet B
boatsfleet B
mediafleet B
channelsfleet B
calendarfleet B
storage/fleet-b/…
Fleet C
boatsfleet C
mediafleet C
channelsfleet C
calendarfleet C
storage/fleet-c/…

Row-level security on every table. Storage paths are prefixed per fleet. Your photos never sit in a shared folder.

Your Social Accounts

FLAY never sees
your password

🔗

OAuth only

You connect Facebook, Instagram and YouTube by logging in on their site and approving FLAY. FLAY receives a scoped token, never your credentials. Change your password and nothing breaks.

🎯

Least permission

The token asks for what posting needs: publish to your page, read your own post engagement. No messaging, no friend lists, no ad accounts.

🗄️

Tokens off the app

Facebook and Instagram tokens live in the publishing engine on its own server, not in the app database that the interface talks to. YouTube uses Google's refresh-token flow, one token per channel, revocable from your Google account.

✂️

Revoke any time

Disconnect a channel in FLAY, or remove FLAY from your Facebook or Google account settings. Either one stops posting instantly.

Posting Safety

Built to not get
your page flagged

🐢

One post per tick

Rapid-fire posting across channels is how pages get their API access pulled. FLAY publishes one post per 20-minute cycle and keeps at least 30 minutes between posts on any single channel.

🔁

Never a duplicate

Before firing, FLAY checks the channel's history. If that photo has ever posted there, the fire is refused. The calendar simply can't double-post.

🧯

Breakers

Three failures in a row on one channel and it pauses itself. If the publishing engine stops responding, all Facebook and Instagram firing pauses until a probe post succeeds.

🚫

No secrets in storage

API keys and passwords are never uploaded alongside media, never included in deployments, and never stored where a fleet could reach them.

Your Data

Plain terms

01
Your media is yours. Every photo and video you upload stays your property. Delete it and it's gone from storage and the database, not soft-hidden.
02
Your captions are yours. Everything FLAY writes for your fleet belongs to your fleet. Export it, edit it, use it anywhere.
03
Nothing is sold. No data brokers, no ad networks, no "anonymized insights." Your uploads train nothing outside your own account.
04
Backed up. Point-in-time snapshots of your library and calendar, plus versioned backups of the platform itself, so a bad day is recoverable.
05
Every action logged. Uploads, deletions, posts, failures, and who did what. When you ask "why did this post go out," there's an answer.
06
Leave with everything. Cancel and take your media and captions with you. No hostage exports.

Questions about
a specific concern?

Ask before you connect a single page. We'd rather answer now than after.

Talk To Us