ffamehire/ lab
Development POC

How this POC handles data

The app requests access to the professional Instagram account you authorize, its available insights, media, comments, and replies. It displays this information for you to inspect.

Temporary processing

Authentication data, including the Instagram access token, is encrypted in an HttpOnly, Secure, SameSite=Lax session cookie. JavaScript cannot read it. Servers decrypt it only to handle requests and enforce a 55-minute expiry; OAuth state expires after 10 minutes. Cookies have no persistent expiry, but browser session restore may retain them. The app has no server-side session database or shared session store.

Fetched results are held in page memory. There is no database, localStorage, sessionStorage, service worker, analytics integration, profile export, or application data file. API requests and responses use no-store. Development request logging is disabled to avoid recording OAuth callback codes. External hosting, tunnelling infrastructure, browser session restore, and Meta’s media servers have their own behaviour; this POC does not configure their retention.

Clear and revoke

Disconnect & clear removes the browser cookies and reloads the page, clearing displayed results. It does not revoke a copied cookie: that remains valid until expiry, encryption-key rotation, or token revocation at Meta. Closing a tab or restarting the server does not invalidate sessions. Disconnecting does not revoke Meta’s authorization grant.

To revoke access at Instagram, remove this app under Apps and websites. See removal instructions.

Scope

No profile analysis, matching, posting, comment moderation, messaging, or persistent data collection is performed. This is a development data-handling notice. Before public use, the app operator must provide their identity/contact information and complete the applicable Meta app requirements.