Comprehensive documentation of how GoTyps collects, stores, secures, and manages user data.
| Data Type | Source | Purpose | Retention |
|---|---|---|---|
| Instagram User ID | OAuth token exchange (Instagram Login) | Account identification and linking to the GoTyps user profile | Cleared immediately on disconnect or account deletion |
| Username, name, profile picture | OAuth token exchange + Graph API (graph.instagram.com/me) | Display the connected account in the creator dashboard | Cleared immediately on disconnect or account deletion |
| Post Engagement Metrics (impressions, reach, likes, saved, engagement) | Graph API (per-post insights, fetched on demand and via a scheduled poller — never a webhook) | Campaign tier verification and reward calculation | Retained as part of the campaign record for as long as the account exists (see Privacy Policy §8); not deleted on a fixed schedule |
| OAuth Access Token | Meta OAuth Flow | Secure API access for reading engagement metrics | Auto-refreshed before its ~60-day expiry; deleted immediately on disconnect or account deletion |
| Rehosted post cover image | Downloaded from the post at submission time (Instagram/TikTok CDN, whose own link expires) | Show a stable preview of the creator's own submitted post | Deleted on account deletion (see Privacy Policy §13) |
GoTyps implements industry best practices for OAuth token security:
Users can delete their account directly from the app, or reach us for any other data request:
Requests handled outside the in-app flow are acknowledged and processed within one month, per GDPR Article 12.
Full compliance with EU General Data Protection Regulation
Adherence to all Meta Platform Policies and Developer Agreement
Database and auth hosted on Supabase, which publishes its own SOC 2 Type II report