MBX Flow
ProductPricingWhy usFor ArtistsBlog

Privacy Policy

Last Updated: 2026-08-07

This Privacy Policy explains how data is handled for the MBX Flow™ software, license purchases and activation, and the mbxflow.com website, provided by MediaBoxEnt Digital Studio LLC. It should be read together with our Terms of Service and EULA.

MBX Flow™MediaBoxEnt Digital Studio LLC

Read together with our other legal documents linked at the bottom of this page.

01

Hosted Plans — Data We Host on Your Behalf

MBX Flow is currently sold as a Hosted service, so this is the section that describes most readers. On a Hosted plan, MediaBoxEnt provisions and operates a dedicated, single-tenant MBX Flow instance for you on cloud servers we manage (currently DigitalOcean). Everything listed below under "Data the Software Stores for You" — your connected-account tokens and API keys, content, schedules, license, publish history, analytics, and logs — is stored on that managed server.

We process that data solely to operate your instance for you, acting as a processor/service provider: we do not use it for any other purpose, we do not sell it, and staff access is limited to what operations and support require. Access tokens and API keys are encrypted at rest by the Software itself, exactly as in a self-hosted installation. You remain the data controller for the content and audiences you process with the Service.

The Hosted Service does not include a backup service: we do not keep restorable copies of your instance. When a Hosted subscription or trial ends, the instance is suspended and, if not reactivated within 14 days, permanently deleted. Server-level snapshots taken by our hosting provider for disaster recovery may briefly retain a copy afterwards until they rotate; those snapshots cover a whole server, are never used to restore an individual instance, and are not accessible as one. Your right to receive a copy of your own data, described under "Your Rights" below, is unaffected and is served by writing to support@mbxflow.com. The full lifecycle is described in the Hosted Service Addendum.

02

If You Self-Host — We Do Not Collect Your Content

This section applies only if you run your own installation. New self-hosted licenses are not offered for purchase at this time, but self-hosting may be offered again in the future, and some installations still run this way.

When you self-host, MBX Flow runs entirely on a server you provide and control. MediaBoxEnt never sees, collects, stores, or processes your accounts, credentials, content, or audience data — that data lives in your own installation, and you are responsible for backing it up and securing it. The Software sends us only the minimal data described below: an anonymous installation ping, and, if you activate a license, license validation data.

03

Installation Ping

Once a day, the Software sends mbxflow.com a randomly generated installation ID, the Software version, the license tier, the operating system type (e.g., "linux"), and the Node.js major version, so we can count installations and the versions and environments in use. This contains no accounts, credentials, content, personal information, or IP address, and the random ID is not linked to you. You can turn it off at any time from Settings → Anonymous Usage Reporting in the app.

04

License Activation & Validation

Every installation activates a license key — including the free Community Edition, obtained by email at mbxflow.com/community. Activating a key makes your installation contact our license server at activation and roughly once a day afterward, sending only the key, the same random installation ID, and the Software version. We store the license record (tier, add-ons, the email address it was issued to, installation count, and expiration) so we can validate it and support you. This is required for the Software to function.

05

Purchase & Billing Information

When you buy a plan, checkout is handled entirely by Stripe, our payment processor. We never receive or store your full card number. Stripe shares with us the information needed to fulfill your purchase: your email address, the plan and billing interval purchased, the Stripe customer and subscription identifiers, and payment status (paid, refunded, disputed, etc.). We use this to create and email your license key, keep your license in sync with your subscription (renewals, cancellations, plan changes), and provide support.

We keep evidence that you accepted our Terms of Service and EULA at checkout (the acceptance timestamp, the document version, your email, and the purchase reference), as required to demonstrate a valid agreement.

Your license key and any account-recovery or delivery emails are sent through Resend, our transactional email provider — Resend receives the recipient address and message content needed to deliver that one email.

06

License Recovery & Subscription Management

If you use mbxflow.com/recover to recover a lost key, we email your license key(s) to the address you entered — we do not confirm or deny whether an address has licenses in the page response itself, to protect other customers' privacy. If you use mbxflow.com/manage, we verify your license key and email match before handing you off to Stripe's Customer Portal, where you manage billing directly with Stripe.

07

Data the Software Stores for You

To do its job, MBX Flow stores data inside your instance, including:

  • the access tokens, API keys, and credentials you enter for the accounts you connect;
  • the posts, captions, hashtags, images, and other content you create or schedule;
  • your schedules, settings, license key, and publish history;
  • engagement metrics and audience analytics fetched from the platforms and services you connect;
  • operational/debug logs used for troubleshooting.

On a Hosted plan this data lives on the managed server we operate for you, as described in "Hosted Plans" above. On a self-hosted installation it lives on your own server, under your control, and you are responsible for backing it up and securing it.

08

Artist Pages & Fan Emails (mbxartists.com)

The optional MBX Flow for Artists module can publish public pages and download gates to mbxartists.com, which MediaBoxEnt hosts. For those pages we process, as a hosting conduit: the page content the artist chose to publish, anonymous per-day view and click counters (including coarse country/city totals derived by our CDN — no visitor profiles, no visitor identifiers), and — when a fan submits their email address on a gate or subscribe form — that address, which we hold only until the artist’s own installation collects it, and never longer than 60 days, after which it is deleted from our systems.

For fan emails, the artist — not MediaBoxEnt — is the data controller. The fan list lives in the artist’s own installation (self-hosted, or a Hosted instance we operate on the artist’s behalf), and emails to fans are sent through the artist’s own email provider account; MediaBoxEnt never sends them and cannot read them. Unsubscribe clicks are recorded on our infrastructure only as one-way codes that solely the artist’s installation can match back to an address — we cannot. Every hosted artist page links to a per-artist privacy notice at mbxartists.com/privacy/<artist> naming the artist as the party responsible for that fan data.

If an artist stops using the Software, their fan list remains theirs, in their own installation — no fan data stays with us beyond the temporary mailbox described above (and, for Hosted instances, the instance data lifecycle described in "Hosted Plans").

09

Third-Party Services You Connect

When you connect a service inside the Software, it sends data directly from your server to that service, under your own account, to perform the action you requested — publishing to the social/publishing platforms available in the Software (the current list is shown in the app's Accounts page, since it changes over time), generating content with your chosen AI provider (e.g., Anthropic, OpenAI, OpenRouter, Google), uploading images to Cloudinary, or, if you enable Campaign Analytics, reading data from your own Google Analytics (GA4) property. If you set up the optional Telegram Assistant, the Software sends operational status messages (publish/error summaries, queue actions you request) to your own Telegram bot through Telegram's servers — never account keys, tokens, or passwords. Each provider handles that data under its own privacy policy, and MediaBoxEnt is not a party to your relationship with them.

10

Data Retention

We retain license and purchase records (including acceptance evidence) for as long as the license is active and for a reasonable period afterward for accounting, legal, and support purposes. Installation ping data is aggregate and not retained per-installation beyond what is needed to compute active-install statistics. Recovery/portal request logs are kept briefly for abuse prevention.

11

You Are the Operator (Data Controller) for Your Installation

Because you decide what content and audiences to process with the Software, you act as the data controller for that activity — whether you self-host or use a Hosted plan (where MediaBoxEnt processes that data only on your behalf, as your processor). You are responsible for complying with the privacy and data-protection laws that apply to you and your audience (for example, GDPR or CCPA where applicable).

12

Your Rights Over the Data We Process Directly

This section covers the personal data MediaBoxEnt processes itself as described above — your license/purchase record and the installation ping — not the content or audience data inside your installation, which you control directly through the app whether self-hosted or Hosted (see "Data the Software Stores for You" and "Hosted Plans" above; for Hosted instances we act only as your processor and will assist with requests you cannot fulfil through the app itself).

Depending on where you live, you may have the right to access, correct, delete, export (portability), or restrict the personal data we hold about you, and to object to certain processing. To exercise any of these rights, contact support@mbxflow.com with enough detail for us to locate your record (e.g., the email used at checkout); we may need to verify your identity before acting on the request. If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority.

13

Hosting, Subprocessors & International Transfers

mbxflow.com is hosted on Cloudflare Pages and uses Cloudflare for content delivery and bot/abuse protection (including the challenge you may see during checkout); Cloudflare processes visitor IP addresses and request metadata as part of that infrastructure service.

We use a small number of service providers ("subprocessors") to run the website and licensing system: Cloudflare (hosting, CDN, bot protection), Stripe (payment processing), and Resend (transactional email delivery). For Hosted plans, DigitalOcean (cloud infrastructure) additionally hosts your instance and its data, and Cloudflare provides hosting, CDN and bot protection for our websites. Each acts on our behalf under its own data processing terms and may process data outside your country, including in the United States, using that provider's standard contractual safeguards for international transfers.

14

Cookies on This Website

mbxflow.com may use cookies or local storage strictly needed for checkout, license recovery, and abuse-prevention (the Cloudflare bot-protection challenge described above). We do not use third-party advertising cookies or cross-site tracking on this site.

15

Children

MBX Flow is a professional tool intended for adults and is not directed to children.

16

Changes to this Policy

We may update this Privacy Policy from time to time. Minor changes — clarifications, corrections, or a replacement subprocessor of the same kind — take effect when the revised version is posted here, and the "Last Updated" date above tells you when that happened.

Where a change is material — a new purpose for which we process your personal data, a new category of data, a new recipient, or anything that reduces your rights — we will notify you in advance by email at the address on your account, at least 30 days before it takes effect, so that you have time to object, exercise your rights, or close your account first. Where the law requires your consent for a change, we will ask for it: continued use is not treated as consent.

Nothing in this section affects any right you have under applicable data-protection law.

17

Contact

Questions about this Privacy Policy? Contact support@mbxflow.com.

18

Related Documents

This document should be read together with:

  • End User License Agreement (EULA)
  • Terms of Service
  • Refund Policy
  • Hosted Service Addendum
  • DMCA Policy
MBX Flow AI Content Distribution Engine
MBX Flow™AI Content Distribution EngineCreate Once. Publish Everywhere.A product of MediaBoxEnt Technologies
MBX Flow™© 2026 MediaBoxEnt Digital Studio LLC — A product of MediaBoxEnt TechnologiesAll Rights Reserved.EULATerms of ServicePrivacy PolicyRefund PolicyHosted AddendumDMCA PolicyDisclosure