Jarvis Instagram Connection Privacy Policy
Updated October 8, 2026. This policy describes the current Instagram connection in the private Jarvis application provided by House of NIVREK. Visiting these information pages does not connect an account or authorize access.
Access and information
With your authorization, Jarvis identifies your eligible Business or Creator profile and reads recent posts. Direct Instagram Login requests instagram_business_basic. The Facebook Login option requests instagram_basic, pages_show_list and pages_read_engagement to find your managed Pages and the professional Instagram profile linked to the selected Page. Facebook Login for Business may automatically include basic public_profile and email grants. Jarvis does not request or fetch your Facebook email address. This option processes managed Page identifiers and names, the selected Page authorization, your Instagram identifier and username, media identifiers, captions and publication timestamps. The signed-in view displays up to ten recent captions.
The connector does not request publishing, messaging, comment-management or Instagram insights permissions. It does not collect your Instagram password.
Optional business portfolio access
Pages held by a Meta business portfolio require an additional business_management grant for Page discovery and a role on that business portfolio. Meta grants read and write capability with its Business Manager API through this permission. If Page access was assigned through Business Manager, Meta requires ads_read or ads_management to retrieve the linked Instagram profile. Jarvis uses the optional, narrower ads_read permission; it can grant advertising reporting and the ability to send web events. These permissions are shown and separately approved before sign-in when enabled.
Jarvis uses this access only to discover managed Pages and their linked professional Instagram profiles, verify the selected Page-to-profile connection and display recent captions. It does not call business-management write endpoints, retrieve ad accounts or advertising reports, send web events, or enable Instagram publishing through this connection. The selected Page authorization is encrypted; the broader user authorization is temporary during setup and is not retained in the saved connected profile.
Storage and use
Instagram authorization, including the selected Page authorization and Page identifier when using Facebook Login, is encrypted using AES-GCM in private Sites and Cloudflare cloud storage. The encryption key stays on the server. Authorization is bound to the Jarvis owner and connection and is not included in browser responses or shared with Jarvis AI. Before reading through a Page, Jarvis verifies that the Page still links to the saved Instagram profile.
Stored connection metadata includes owner and internal identifiers, Instagram identifier and username, connection status, permission state, revisions and timestamps.
Recent captions are temporary browser view data. The connector does not deliberately save them in browser storage, Jarvis conversations or memory. Closing the posts view, hiding or leaving the page, or ending the browser session clears that view.
Pending sign-in data and available profile choices are encrypted while setup completes. A connection attempt is usable for ten minutes. Its encrypted payload is cleared after successful selection, callback failure or expiration cleanup; its operational record may remain.
Meta processes Instagram authorization and API requests. Sites and Cloudflare provide Jarvis hosting, processing and storage. Requests use HTTPS. Sign-in also uses a Secure, HttpOnly, SameSite cookie lasting up to ten minutes to bind the callback to your browser. The connector does not save Instagram authorization in local or session browser storage.
Instagram responses are not automatically sent to AI features or saved to Jarvis conversations or memory. Separate AI features process content the owner supplies. Access to this connection is restricted to the authorized Jarvis owner and service processing needed to provide the feature.
Retention and removal
Saved Instagram authorization and connection metadata remain until disconnected or separately deleted. There is no automatic Instagram inactivity-deletion deadline.
Disconnect removes the selected connection's saved authorization and disables its use in Jarvis. Identifier, username, status and operational metadata remain. Disconnect does not automatically revoke access at Instagram, erase related pending sign-in choices, or delete your Instagram profile or posts. Pending choices become unusable after ten minutes and their encrypted payload clears during expiration cleanup.
While signed in as the Jarvis owner, open the selected Instagram card → Delete Jarvis connection data → Review data deletion. Review the exact profile, then choose Delete this Instagram connection. This removes that connection's saved authorization, identifiers, username, status, timestamps and Jarvis review records. It also clears all saved Instagram sign-in attempts for this Jarvis owner, including unfinished choices and completed setup records. Other saved connected profiles, email accounts and YouTube connections remain.
Jarvis deletion does not automatically revoke access at Meta. Remove the app through the account settings of the provider used to sign in: Instagram for direct Instagram Login, or Facebook for Facebook Login. Revoking a shared Meta app may also end other connections using that app. Keep passwords, authorization tokens and private messages out of support requests. Removal from hosting backups or operational logs may follow the hosting provider's retention processes; immediate erasure from those systems is not promised.
For instructions, see Delete Jarvis Instagram Connection Data. Meta's practices are described in the Instagram Privacy Policy.
Contact and changes
Use Contact House of NIVREK for privacy questions or deletion requests. Materially changed access or data use will be disclosed before that use begins, with additional authorization where required.