API Permissions

Detailed justification for each Instagram Graph API permission requested by GoTyps.

📋 Permission Request Philosophy

GoTyps follows the principle of minimal data access. We request only the permissions absolutely necessary to deliver our core functionality, and we never use these permissions for purposes beyond what is explicitly stated below.

1. instagram_business_basic

Reads basic profile information from an Instagram Business or Creator account.

Why GoTyps Needs This

To identify the connected account (captured once at OAuth) and to display the creator's name, username, and profile picture in Settings, so the creator can confirm the right account is linked.

Feature Using This Permission

Account connection and profile display (Settings → Comptes Sociaux)

Data Fields Accessed

user_id (from the OAuth token exchange)usernamenameprofile_picture_url

What Happens If Denied

Creator cannot connect their Instagram account or participate in campaigns.

What We Do NOT Use This For

  • ✗Accessing follower or following lists
  • ✗Retrieving contact information (email, phone)
  • ✗Tracking user location or device information
  • ✗Building user profiles for advertising purposes

2. instagram_business_manage_insights

Reads engagement metrics and insights from a creator's own Instagram posts.

Why GoTyps Needs This

To verify whether a creator's submitted post meets the engagement tier thresholds defined in a campaign.

Feature Using This Permission

Campaign reward verification (a manual "Actualiser" refresh, and a scheduled cron poller) — never a webhook subscription

Data Fields Accessed

impressionsreachlikessavedengagement

What Happens If Denied

GoTyps cannot read engagement metrics, making it impossible to verify campaign eligibility or issue rewards.

What We Do NOT Use This For

  • ✗Monitoring behavior patterns across posts unrelated to active campaigns
  • ✗Tracking competitor performance or market research
  • ✗Selling or sharing engagement data with third parties
  • ✗Continuous monitoring of user activity

Permission Summary Table

PermissionPurposeRetention Period
instagram_business_basicAccount verification & displayCleared immediately on disconnect or account deletion
instagram_business_manage_insightsEngagement metric verificationRetained as part of the campaign record for as long as the account exists (Privacy Policy §8)
API Permissions - GoTyps Meta App Review | GoTyps