Connect through Meta
Authorization happens on Meta’s own sign-in page. Dadigram never asks for your Instagram or Facebook password. We request permissions for the analytics connection and the pages needed to find your professional Instagram accounts.
Protected credentials
Connected-account access tokens are encrypted on the server using AES-256-GCM. Your Dadigram password is hashed with bcrypt. Session credentials are stored in HTTP-only cookies and the database stores their hashes.
Access that stays yours
Analytics requests are scoped to the signed-in owner. Account connections, reports, and stored metrics belong to your workspace. Rate limits, origin checks, and single-use authorization state help protect important account flows.
A clear way out
Disconnect an Instagram account to remove its locally stored analytics and token. Delete your Dadigram account to remove your workspace. Meta deletion callbacks are authenticated before processing.
Report a concern
Please use the contact form with the Account support topic to report a suspected security issue. Include enough detail for us to reproduce the issue without including passwords, access tokens, or someone else’s private data.