Local-first and data sovereignty for your Instagram export
Data sovereignty means you decide where your archive lives and who can touch it. A local-first design keeps custody in your hands by default, with opt-in sync only under strict constraints.
Sovereignty is simple: you choose what happens to your archive. Local-first means custody stays with you unless you explicitly opt into a feature that requires sharing.
What sovereignty means here
- Custody first. By default, nothing leaves your device. The ZIP, parsed results and derived insights stay local.
- Explicit opt-in. Any networked capability is opt-in only, gated by configuration. If it is not on, it is off.
- No single point of leak. For the optional sync tier, split-key custody (2-of-4) means no single party can decrypt alone.
- No media in sync. Media is never stored in the opt-in sync path.
- Right to erase. Instant erase with 30-day grace for opt-in synced data.
Practical takeaways
You do not need to trust a server to read your own export. You can verify by running offline. If you choose to sync later, you do so with clear constraints and revocable custody.
What does data sovereignty mean for an export?
It means you retain control: decide where it lives, who touches it, and when it is removed.
Is sync required?
No. Sync is strictly opt-in and off by default.
Can I erase synced data?
Yes. Opt-in synced data supports instant erase with 30-day grace.
Sources of truth
- Product posture: local mode default; claim layer opt-in only when both required env vars set.
- Profile sync plan: split-key 2-of-4, no media stored, messages only under explicit opt-in, instant erase + 30-day grace.
SECURITY.mdandAGENTS.mdsecurity posture.