CrowdClip Privacy Policy
Effective
This Privacy Policy explains what information CrowdClip processes, why it is used, and the choices you have. It is written in plain language and describes the data the current application actually handles or is being built to handle.
1. About CrowdClip
CrowdClip is a personal software project operated by John Uwaishe. It helps Instagram professional accounts manage fan-submitted concert media and request permission to use that media.
CrowdClip is not owned, operated, or endorsed by Meta or Instagram. “Instagram” and “Meta” are trademarks of their respective owners and are referenced here only to describe how the service works.
2. Information CrowdClip may process
Depending on how the service is used, CrowdClip may process the following. Some items describe data the application is being built to handle as features are enabled.
| Category | What this covers |
|---|---|
| Account details | Identifiers and connection credentials for an authorised Instagram professional account. |
| Platform events | Story-mention and messaging events Instagram sends to the service, with their associated identifiers and timestamps. |
| Media | Temporary previews of mentioned Stories, and original files a fan chooses to upload. |
| Consent records | Permission requests and responses, when they happened, and the terms accepted. |
| Service logs | Basic technical and security logs needed to operate and protect the service. |
CrowdClip does not sell personal information and does not use it for advertising.
3. Why the information is used
The information above is used to:
- Connect an artist’s authorised Instagram professional account.
- Receive Instagram Story-mention and messaging events.
- Identify potentially relevant fan-shot media.
- Allow an artist to contact a fan about their media.
- Request and record permission.
- Allow fans to upload original files.
- Deliver approved media to the artist.
- Prevent abuse and duplicate processing.
- Debug errors and protect the security of the service.
- Comply with valid legal and platform requirements.
4. Instagram access tokens
- Access tokens are used only to make authorised Instagram API requests on behalf of a connected account.
- Tokens are never displayed publicly.
CrowdClip is an early-stage project. At present the integration is used only with the developer’s own development and test accounts, and any access token is held in protected server-side environment configuration rather than in a public location or client-side code. As the project matures, tokens will be stored using an appropriate encrypted secrets system. A connected account can revoke CrowdClip’s access at any time through Instagram or Meta account settings, or request removal through the CrowdClip deletion process.
5. Media handling
- Instagram Story media URLs may be temporary and expire.
- CrowdClip may temporarily retrieve a copy of Story media in order to process a Story mention.
- Fan uploads are voluntary.
- Uploading a file does not transfer ownership of that file unless this is clearly stated in the separate permission terms the fan accepts.
- Artists only receive files for which the relevant permission workflow has been completed.
Temporary Story media that CrowdClip retrieves is retained for up to 7 days, and media associated with a declined or rejected request is retained for up to 7 days, after which it is deleted. These retention windows are configuration values used by the backend and this policy is kept in sync with them.
6. Sharing of information
To operate CrowdClip, information may be processed by service providers, such as:
- Meta and Instagram (to send and receive platform data).
- Hosting providers.
- Database providers.
- Object-storage providers.
- Monitoring or error-reporting providers.
These providers process information only to help run the service. CrowdClip does not sell personal information.
7. Data retention
- Access tokens are kept only while an account remains connected, or while needed for the authorised integration, and are removed on disconnection or on request.
- Temporary Story media is deleted according to the configured retention period described in section 5.
- Uploaded originals and permission records may be retained while needed to provide the service, to document the permission a fan granted, to resolve disputes, or to meet legal obligations.
- Users can request deletion at any time.
8. Data deletion and your rights
You can request access to, correction of, or deletion of your information. Full instructions are on the CrowdClip Data Deletion page, or you can .
To protect accounts, CrowdClip may need enough information to verify that you control the relevant Instagram account or submission before acting on a request.
9. Security
CrowdClip uses reasonable technical and organisational safeguards to protect the information it handles, including verifying the authenticity of incoming platform events and keeping secrets out of public and client-side code. However, no online service can guarantee absolute security. CrowdClip does not hold any security or compliance certifications.
10. Children
CrowdClip is not designed for or directed at children under 13. You should not submit content through the service if you are below the minimum age required to use Instagram in your jurisdiction.
11. Changes to this policy
CrowdClip is under active development, and this policy may be updated as the project changes. When it is materially updated, the effective date at the top of this page will be changed.
12. Contact
John Uwaishe
CrowdClip
Email: