Skip to main content

Is Clue Labs safe to connect to my Instagram?

What this article covers: What Clue Labs can and cannot do with your connected Instagram account, how the connection is secured, and what data is and isn't stored.

Written by Inge

The short answer

Yes. Clue Labs uses read-only access to your Instagram account. It cannot post, modify, delete, or interact with your account in any way. The connection is secured by Nango, a trusted OAuth infrastructure provider, and your access credentials are never stored by Clue Labs.


How the connection works

When you connect your Instagram account, you authorise Clue Labs through Meta's official OAuth flow — the same secure authorisation system used by every legitimate third-party app that connects to Instagram.

The connection is managed by Nango, a specialist OAuth infrastructure provider. Your Facebook and Instagram login credentials pass directly through Meta's own systems — Clue Labs never sees your password.

What Clue Labs receives is an access token — a temporary key that allows it to request specific types of data from your account via Meta's official API. That token is encrypted and stored securely. It gives Clue Labs access only to the specific data types you authorised during the permissions flow.


What Clue Labs can do with your account

Clue Labs can read:

  • Your post history — captions, formats, published dates

  • Your post performance data — reach, impressions, engagement signals, saves, shares, comments, link clicks, profile visits

  • Your account insights — follower count, growth data, audience signals

  • Your Instagram profile information — name, username, profile category

That is the complete list. Clue Labs uses this data to analyse your account's performance and generate recommendations.


What Clue Labs cannot do

Clue Labs cannot:

  • Publish, schedule, or draft posts on your behalf

  • Edit or delete any of your existing posts

  • Send messages or respond to comments

  • Follow or unfollow accounts

  • Access your Instagram inbox or read your DMs

  • Change any settings on your account

  • Access any data beyond what was listed above

Clue Labs is a read-only platform. It observes and analyses. It never acts.


For social media managers connecting client accounts

If you manage social media for clients and are connecting their Instagram accounts to Clue Labs, this is what your clients need to know:

Clue Labs has read-only access to the specific account you connect. It cannot access other accounts they manage. It cannot post anything. It cannot access their inbox or any private messages.

Clients can verify exactly what Clue Labs has access to at any time by going to their Facebook Settings → Business Integrations. Every connected third-party app and its specific permissions are listed there and can be revoked at any time — without affecting their Instagram account in any way.

Revoking Clue Labs' access from Facebook Settings will disconnect the account from Clue Labs. Their Instagram account itself is completely unaffected.


GDPR and data compliance

Clue Labs operates in compliance with GDPR. Key points:

Your post data belongs to you. Clue Labs processes your post and performance data on your behalf to generate recommendations. It is not sold to third parties. It is not used to power recommendations for other accounts.

Your data is scoped to your account. The performance data from your Instagram account is used only to generate recommendations for your account specifically. It is not shared with or visible to other Clue Labs users.

You can request deletion. If you cancel your Clue Labs subscription, your data is permanently deleted after 30 days in line with our privacy policy. You can also request deletion at any time by contacting the team.

Top Fans data. The Top Fans feature surfaces engagement signals (comments, story replies, DMs) from your followers. This data is processed on your behalf as the account owner — it represents activity your followers have already made visible to you through their interactions with your public business account. Clue Labs does not store message content, only engagement signals.


Common questions

Can Clue Labs see my Instagram messages? No. Clue Labs does not access your Instagram inbox or the content of any direct messages.

Can Clue Labs post on my behalf? No. Clue Labs is read-only. It has no ability to publish, schedule, or interact with your account.

If I revoke access, what happens to my Clue Labs account? Your Clue Labs account remains intact but your Instagram data will stop syncing. To reconnect, go to Brand Connections and use the Reconnect Account flow.

Is my login information stored by Clue Labs? No. Your login credentials are handled entirely by Meta's OAuth system and Nango. Clue Labs never receives or stores your Facebook or Instagram password.

What happens to my data if I cancel? Your data is retained for 30 days after your subscription ends, then permanently deleted. See the data retention article for full details.


Related articles

  • How Clue Labs uses your data

  • Why you need to select "all" when connecting your account

  • How to reconnect a disconnected account

  • What happens to my data if I cancel?

  • Connections and pricing

Did this answer your question?