Legal · Usage guidelines

How Vkit uses Instagram permissions

Vkit is a tool for Instagram creators: it replies automatically to the people who comment on or message them, and gives those conversations a page to land on. This page explains what each permission we request is for — in terms of the value the creator gets from granting it.

Last updated: July 17, 2026 · 18083690 Canada Inc. (o/a Vkit)

instagram_business_basic

This permission lets Vkit read the connected account’s own profile and media. It is the foundation the product stands on: without knowing which account is connected and what it has posted, nothing else Vkit does is possible. Concretely, we read:

  • Username and profile picture So the creator can see, at the moment of connecting and ever after, exactly which Instagram account Vkit is acting for. Automations send messages on the creator’s behalf — showing the wrong account here would be showing them the wrong identity.
  • Account ID The stable identifier Instagram sends with every webhook event. It is how a comment on the creator’s post reaches that creator’s workspace and nobody else’s — the routing key for the whole product.
  • Account type Automated messaging is only available to professional accounts. Checking the type at connect time lets Vkit say “this account can’t run automations yet” before anything is set up, instead of failing silently later.
  • The account’s own posts and Reels A comment automation watches a specific post the creator chooses. Vkit lists the account’s own media so the creator can pick it by sight — their posts, read with their permission, shown only to them.
  • Follower count Displayed on the creator’s own dashboard as basic account context. Never used for ranking, comparison, or anything visible to anyone else.

Everything read with this permission belongs to the account that granted it, and is shown only to that account’s owner inside their own workspace. Vkit reads no other account’s profile or media with it.

instagram_business_manage_messages

The value the creator signs up for: when someone messages them, Vkit sends the reply the creator wrote, immediately, without the creator being at their phone. Every conversation starts with the other person — a comment, a story reply, or a direct message. Vkit never messages anyone who has not contacted the creator first, and anyone who replies STOP is never messaged again.

instagram_business_manage_comments

Comment-to-DM is Vkit’s core workflow: a follower comments a keyword on the creator’s post, and Vkit replies privately with what the creator promised — a link, a guide, a next step. This permission is how Vkit learns the comment happened and posts the creator’s public reply. It applies only to comments on the connected account’s own posts.

What we do not do

  • No reading of other accounts’ profiles, media, or followers.
  • No scraping — everything arrives through Meta’s official API.
  • No selling or sharing of Instagram data with third parties.
  • No unsolicited messages: automation only ever responds to people who contacted the creator first, and sending is rate-limited to protect the account.

Data handling, retention, and deletion are covered in our Privacy Policy and data deletion instructions. Questions reach us at team@vkit.app.