Detailed justification for each Instagram Graph API permission requested by GoTyps.
GoTyps follows the principle of minimal data access. We request only the permissions absolutely necessary to deliver our core functionality, and we never use these permissions for purposes beyond what is explicitly stated below.
Reads basic profile information from an Instagram Business or Creator account.
To identify the connected account (captured once at OAuth) and to display the creator's name, username, and profile picture in Settings, so the creator can confirm the right account is linked.
Account connection and profile display (Settings → Comptes Sociaux)Creator cannot connect their Instagram account or participate in campaigns.
Reads engagement metrics and insights from a creator's own Instagram posts.
To verify whether a creator's submitted post meets the engagement tier thresholds defined in a campaign.
Campaign reward verification (a manual "Actualiser" refresh, and a scheduled cron poller) — never a webhook subscriptionGoTyps cannot read engagement metrics, making it impossible to verify campaign eligibility or issue rewards.
| Permission | Purpose | Retention Period |
|---|---|---|
| instagram_business_basic | Account verification & display | Cleared immediately on disconnect or account deletion |
| instagram_business_manage_insights | Engagement metric verification | Retained as part of the campaign record for as long as the account exists (Privacy Policy §8) |