SAFETY & PLATFORM POLICIES

Platform rules to respect

Every platform SocFlow connects to has its own automation policy, enforced by that platform — not by SocFlow. Know these before you turn on a write action.

X (Twitter)

No posting identical or near-identical content repeatedly. Automated DMs and replies require the recipient to have already asked for contact — following or mentioning you isn't consent. No following/unfollowing in bulk or based on a keyword search alone.

Risk if not: Rate-limiting, temporary action blocks, or account suspension for repeat violations.

Reddit

No identical or substantially similar content across subreddits, bots must not impersonate humans, and a descriptive per-account identifier is required on every request. Reply is currently paused app-wide — see the Reddit examples page.

Risk if not: Subreddit bans, account suspension, and — per Reddit's Responsible Builder Policy — loss of API access for the app itself.

Mastodon

Each instance sets its own automation policy — check your instance's rules. Bots should self-identify (the bot flag, applied automatically at connect). Unsolicited replies and indiscriminate bulk following are treated the same way as on X, even though Mastodon's API won't reject them for you.

Risk if not: Silent moderation action from your instance's admins — there's no automatic API rejection like X's duplicate-content check, so violations can go unnoticed until action is taken.

Bluesky

Interactions (like, repost, reply, follow) should be opt-in — only engage with an account that has tagged this one. Bans artificially manipulating follower counts. Generous rate limits (roughly 1,666 posts/hour), but that headroom doesn't make an untargeted rule safe.

Risk if not: Account restrictions for bulk/spam-like or non-opt-in engagement, even within the stated rate limit.

You're responsible for what your rules do

SocFlow refuses to build a handful of specific combinations these platforms flatly prohibit — automated DMs on X, replying or following based on a keyword search alone on X/Mastodon, non-opt-in engagement on Bluesky, and more (see each platform's examples page). But that's a floor, not a review process — SocFlow doesn't check every rule you build against every platform's policy, and a rule that stays inside the guardrails can still be configured too broadly (a keyword filter that's too generic, a trigger that fires constantly). The consequences of a rule that violates a platform's rules (rate-limiting, restrictions, suspension, bans) land on your account, because it's your account and your rule. Start narrow, test with low-volume triggers first, and widen a rule only once you've confirmed it behaves the way you expect.