Instagram is rolling out new features over six months that help users manage third-party app permissions, including removing them and seeing requested data
Dami Lee / The Verge :
Context & Ripple Effects
This rollout extends a privacy-controls arc Instagram has been building since the GDPR era: the platform shipped a data download tool ahead of the law's May 2018 deadline, then an activity dashboard with time limits that fall. The new layer moves from what users can see about their own data to what they can revoke from others — cutting off third-party apps' access and inspecting exactly what those apps requested.
The significance is where the boundary sits: until now, revoking permissions and auditing shared data was largely a Facebook-side capability, and Meta only brought the equivalent off-site activity controls to Instagram in 2023 via its third-party website activity controls. This 2019 rollout is the first step of that migration onto Instagram itself.
First-order effects
- Users gain direct control over which connected apps keep their Instagram access and visibility into the specific data each app requested, ending reliance on Facebook's settings surface for these actions.
Second-order effects
- Third-party app developers built on Instagram's API face churn as users audit and cut long-forgotten connections during the six-month rollout, pressuring them to justify the data they request.
Third-order effects
- If the pattern holds, permission management becomes table stakes across Meta's family of apps rather than a Facebook-only feature, shifting the industry default from silent data sharing toward user-audited connections.
The trend: Consumer platforms are converting regulatory-era transparency tools into standing user controls over third-party data access, with Instagram catching up to capabilities Facebook already offered.