Privacy for this development pilot
This app connects authorized Instagram Business or Creator accounts to a configurable website feed. It requests read-only basic account and media access. It does not publish posts, read messages or collect other people's private accounts.
What we store
Connected account identifiers, username, account type, encrypted access tokens and their expiry, up to 100 recent posts' captions, media links and timestamps, feed settings and operator sessions. Data is stored on this app's server, separately from the CRM. Source images are loaded from Instagram's CDN rather than copied into our storage.
What is public
Drafts and account credentials are private. Publishing a feed exposes the selected posts, captions and username to its embed readers. The website allowlist controls browser embedding; it is not a privacy or access-control guarantee. Instagram and its CDN receive requests when an embedded image is displayed.
Retention and deletion
Account data remains until disconnected or deleted through Instagram's data-deletion callback. Disconnect deletes local account data and its feeds immediately, and attempts provider revocation. Sessions expire after eight hours. Deletion confirmation codes expire after seven days. Hashed revocation markers prevent an in-flight connection from restoring deleted data. Tokens and account data are not included in server request logs.
Contact and account removal
Contact webdev@clarity-online.com for questions or removal. You can also request deletion or disconnect in the app.
This is a limited development pilot, not a statement of Meta approval. This notice and retention process must be reviewed before client rollout.