Data Handling & Security

Comprehensive documentation of how GoTyps collects, stores, secures, and manages user data.

1. What Data We Collect

Data TypeSourcePurposeRetention
Instagram User IDOAuth token exchange (Instagram Login)Account identification and linking to the GoTyps user profileCleared immediately on disconnect or account deletion
Username, name, profile pictureOAuth token exchange + Graph API (graph.instagram.com/me)Display the connected account in the creator dashboardCleared immediately on disconnect or account deletion
Post Engagement Metrics (impressions, reach, likes, saved, engagement)Graph API (per-post insights, fetched on demand and via a scheduled poller — never a webhook)Campaign tier verification and reward calculationRetained as part of the campaign record for as long as the account exists (see Privacy Policy §8); not deleted on a fixed schedule
OAuth Access TokenMeta OAuth FlowSecure API access for reading engagement metricsAuto-refreshed before its ~60-day expiry; deleted immediately on disconnect or account deletion
Rehosted post cover imageDownloaded from the post at submission time (Instagram/TikTok CDN, whose own link expires)Show a stable preview of the creator's own submitted postDeleted on account deletion (see Privacy Policy §13)

2. What We Never Collect

  • ✗Follower or following lists
  • ✗Direct messages or private conversations
  • ✗Location data or GPS coordinates
  • ✗Contact information (email, phone number) from Instagram
  • ✗Browsing behavior outside the GoTyps platform
  • ✗Device information or IP addresses for tracking purposes
  • ✗Photos or media content beyond what is needed for post verification

3. Where Data Is Stored

🗄️ Database

  • • Platform: Supabase (PostgreSQL)
  • • Region: EU (France)
  • • Encryption: Encrypted at rest and in transit (TLS 1.3)
  • • Access: Restricted to authenticated application layer only
  • • Backups: Automated daily backups with 7-day retention

🔒 Security Measures

  • • Row-Level Security (RLS) policies enforced
  • • No third-party data sharing or selling
  • • Infrastructure hosted on Supabase, which publishes its own SOC 2 Type II report
  • • GDPR compliant data processing

4. Token Security

OAuth Token Handling

GoTyps implements industry best practices for OAuth token security:

  • ✓Tokens stored encrypted in Supabase using AES-256 encryption
  • ✓Tokens never exposed to client-side JavaScript
  • ✓All Graph API calls made server-side only (Next.js API routes)
  • ✓Automatic token refresh before 60-day expiry
  • ✓Immediate token invalidation on user disconnect

5. User Control & Revocation

👤 User Rights

  • ✓Disconnect anytime: Creators can disconnect their Instagram account from their dashboard at any time
  • ✓Immediate token deletion: On disconnection, OAuth token is immediately invalidated and deleted from our database
  • ✓Disconnect: deletes the stored OAuth token and clears the account's Instagram identity fields immediately, not on a delay. Campaign records (which video was submitted, its metrics, whether a reward was paid) are kept as business records, consistent with how Meta's own account-deauthorization callback is handled.
  • ✓Full account deletion: anonymizes the account, deletes all stored OAuth tokens, and deletes any rehosted post cover images (see Privacy Policy §13) — triggered immediately from the app, not queued.

📧 Exercising Your Data Rights

Users can delete their account directly from the app, or reach us for any other data request:

  • • Email: legal@gotyps.com
  • • In-App: account deletion is available from account settings
  • • Privacy Policy: full list of GDPR rights and how to exercise them

Requests handled outside the in-app flow are acknowledged and processed within one month, per GDPR Article 12.

6. Compliance & Certifications

🇪🇺

GDPR Compliant

Full compliance with EU General Data Protection Regulation

📋

Meta Platform Terms

Adherence to all Meta Platform Policies and Developer Agreement

🔐

Supabase Infrastructure

Database and auth hosted on Supabase, which publishes its own SOC 2 Type II report

Data Handling & Security - GoTyps Meta App Review | GoTyps