The short version
Connecting a social account does exactly two things: it proves the account is yours, and it lets us show your real follower and engagement numbers instead of self-typed ones. We only ever read. We can never post, comment, message, edit, or delete anything on your accounts, because we never request permissions that allow it.
We use Instagram's business login with two permissions. Your account must be a professional account (Creator or Business; the switch is free in the Instagram app).
- instagram_business_basic: your username, name, profile picture, follower count, and media count. This fills your profile and shows your verified follower number.
- instagram_business_manage_insights: your account insights, such as reach and views. Despite Meta's naming, this permission is read-only; it powers the stats on your media kit. Instagram provides no insights for accounts under 100 followers.
We connect Facebook Pages (not personal profiles) with two permissions.
- pages_show_list: the list of Pages you manage, so you can pick which one to connect.
- pages_read_engagement: your Page's name, picture, and follower count.
YouTube
We connect your channel through Google sign-in with two read-only scopes.
- youtube.readonly: your channel's name, handle, thumbnail, subscriber count, total views, and video count. This fills your profile and shows your verified subscriber number.
- yt-analytics.readonly: your own channel's recent views, watch time, likes, and comments, which power the stats on your media kit. We only ever query your own channel.
Disconnecting a YouTube channel also revokes Rekomi's access with Google directly, in addition to deleting our copy of the tokens.
TikTok
We connect your account through TikTok sign-in with four read-only scopes.
- user.info.basic and user.info.profile: your avatar, display name, and username, which fill your profile.
- user.info.stats: your follower count, following count, total likes, and video count, shown as verified figures.
- video.list: your most recent videos' view, like, comment, and share counts, which power your engagement stats. We never see drafts or private analytics, and TikTok's API offers no audience demographics to anyone.
Disconnecting a TikTok account also revokes Rekomi's access with TikTok directly, in addition to deleting our copy of the tokens.
Twitch
We connect your channel through Twitch sign-in with one read-only permission.
- moderator:read:followers: your own channel's follower count (you count as a moderator of your own channel; we can never read anyone else's). We also read your public channel name, handle, and avatar, which need no permission.
Disconnecting a Twitch channel also revokes Rekomi's access with Twitch directly, in addition to deleting our copy of the tokens.
X (Twitter)
We connect your account through X sign-in with read-only access.
- users.read (with its companion tweet.read, which X requires alongside it): your own profile only, meaning your username, display name, avatar, and public counts of followers, following, posts, and lists. We read your profile once a day and nothing else: we never read your posts, timeline, messages, or anyone else's account, and we can never post as you.
- offline.access: lets the daily stats refresh run without asking you to sign in again.
Disconnecting an X account also revokes Rekomi's access with X directly, in addition to deleting our copy of the tokens.
We connect your account through Pinterest sign-in with one read-only scope.
- user_accounts:read: your own account's profile (username, avatar) and its public counts: followers, following, pins, boards, and monthly views. We can never read your boards' contents, your saved pins, or anyone else's account, and we can never create or edit anything.
Disconnecting deletes our copy of the tokens immediately. Pinterest does not offer apps a revocation API, so to also remove the grant on Pinterest's side, remove Rekomi under Settings > Security in your Pinterest account.
We connect your account through LinkedIn sign-in, and we keep no access token at all.
- openid and profile: your name and profile photo, read once during sign-in to confirm the account is yours. LinkedIn's open API offers no follower or engagement statistics, so a LinkedIn connection shows a verified badge rather than verified numbers.
The sign-in token is used for that single read and never stored, so there is nothing to expire and nothing to revoke: after connecting, Rekomi holds only your name, photo, and the date you verified. You can also remove Rekomi any time under Settings > Data privacy > Permitted services in your LinkedIn account.
Threads
We connect your profile through Threads sign-in with two read-only scopes.
- threads_basic: your username, display name, and avatar, which fill your profile.
- threads_manage_insights: your own follower count, shown as a verified figure. We never read your posts or replies, and we can never post as you.
Removing Rekomi inside your Threads or Instagram settings notifies us and we revoke our copy of the access right away, the same as the other Meta platforms.
Discord
We connect your account through Discord sign-in with two read-only scopes.
- identify: your username, display name, and avatar.
- servers (guilds): the list of servers you belong to, from which we keep only aggregate numbers about servers you OWN: how many, and their member counts. We never join your servers, never read messages or member lists, and keep nothing about servers you are merely a member of.
Disconnecting a Discord account also revokes Rekomi's access with Discord directly, in addition to deleting our copy of the tokens.
Bluesky
We verify your account with an app password used exactly once, and store no credentials.
- One-time app password check: you create an app password in Bluesky (Settings > Privacy and security > App passwords) and paste it into Rekomi. We use it for a single sign-in that proves the account is yours, then delete that session immediately. The app password is never stored, and you can revoke it in Bluesky at any time.
- Public stats: your follower, following, and post counts come from Bluesky's public API, which requires no credentials at all.
What we store and for how long
We store the account's id and handle, its current stats, and a daily history of those stats so your page can show growth honestly. Stats history is kept for 24 months, then deleted. The access token each platform gives us is encrypted at rest and is deleted the moment you disconnect.
Your controls
- Disconnect any time from your page settings. We stop reading immediately and delete the access token. Your last verified numbers stay visible to you, greyed, until you remove them.
- Removing the app inside Instagram or Facebook has the same effect; Meta notifies us and we revoke our copy of the access right away.
- Data deletion: requesting deletion through Meta's tools erases the connection and its entire stats history from Rekomi automatically. You can also email privacy@rekomi.com.
What we never do
- Post, comment, message, follow, or change anything on your accounts.
- Read your DMs, drafts, or anything non-public beyond the metrics listed above.
- Sell or share your social data with anyone; brands only see what your public media kit shows.