Connected Platforms
Alnara connects to each platform through its official API and OAuth flow. This page lists every platform, the exact permissions we request, what each permission is for, what we store, and how to switch access off. We request nothing beyond what the features you use require.
How we treat platform data
- Least privilege. We request only the permissions the features you use need. Where a platform offers a broader scope and a narrower one that suffices, we take the narrower.
- Your data is not the product. We do not sell platform data, do not use it for advertising, and do not use it to train machine-learning models.
- Tokens are encrypted at rest with AES-256-GCM and are never sent to your browser or exposed through our API.
- You can disconnect at any time. Disconnecting deletes the stored token immediately. See Data Deletion.
- Each platform’s own terms still apply. Connecting a platform through Alnara does not replace your agreement with that platform.
Google API Services — Limited Use
Alnara’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we use Google user data only to provide the features you have asked for, we do not transfer it except as necessary to provide those features or where required by law, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and de-identified.
By using Alnara’s YouTube features you also agree to the YouTube Terms of Service, and the Google Privacy Policy describes how Google handles your data. You can revoke Alnara’s access to your Google account at any time from the Google security settings page.
Publish and schedule posts as yourself or as a company page you administer, and read back the comments on page posts.
Permissions we request
- Identify you and show whose account is connected —
openid, profile, email - Publish and schedule posts as you —
w_member_social - Publish as a company page you administer, and read its comments —
w_organization_social, r_organization_social - List the pages you administer, and your role on each, so publishing can be blocked where your role does not allow it —
rw_organization_admin
What we store. Your member URN, name, profile picture URL and email; for each connected page, its organization URN, name, logo URL and your role on it. The access token is encrypted at rest.
The organization permissions are only requested where this installation has been approved for LinkedIn’s Community Management API. A company page holds no token of its own — it is published to with the administrator’s.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Settings → Data privacy → Permitted services.
Manage the Pages you administer: publish and schedule posts, read and reply to comments, and handle Page messages.
Permissions we request
- Identify you and show whose account is connected —
public_profile, email - List the Pages you administer so you can choose which to connect —
pages_show_list - Publish and schedule posts to those Pages —
pages_manage_posts - Read and moderate comments and reactions on those Pages —
pages_read_engagement, pages_manage_engagement - Read and reply to Page messages in the inbox —
pages_messaging
What we store. Your user ID and name; for each connected Page, its ID, name, category, picture and Page access token. The access token is encrypted at rest.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Settings → Apps and Websites.
Publish to an Instagram professional account, and read and moderate its comments and direct messages.
Permissions we request
- Read the professional account linked to your Facebook Page —
instagram_basic - Publish images, videos and carousels —
instagram_content_publish - Read and moderate comments —
instagram_manage_comments - Read and reply to direct messages —
instagram_manage_messages - Show reach and engagement figures for what you published —
instagram_manage_insights
What we store. The Instagram business account ID, username and profile picture, and the media you publish through Alnara. The access token is encrypted at rest.
Instagram is not a separate sign-in. It is reached through the Facebook Page it is linked to, so revoking Facebook revokes Instagram with it.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Facebook Settings → Apps and Websites.
Send and receive messages through a WhatsApp Business number you own.
Permissions we request
- Send and receive messages on your business number —
whatsapp_business_messaging - Read the numbers and message templates on your WhatsApp Business account —
whatsapp_business_management, business_management
What we store. The phone number ID, business account ID, and the message history you send or receive through Alnara. The access token is encrypted at rest.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Meta Business Settings → Apps.
Connect a Google account to reach YouTube, and to read and write calendar events and contacts.
Permissions we request
- Identify you and show whose account is connected —
openid, email, profile - Manage your YouTube channel: uploads, comment moderation and live chat —
https://www.googleapis.com/auth/youtube, https://www.googleapis.com/auth/youtube.force-ssl - Show and create calendar events for scheduled publishing —
https://www.googleapis.com/auth/calendar - Read contacts for addressing messages —
https://www.googleapis.com/auth/contacts
What we store. Your Google account ID, name, email and picture; for YouTube, the channel ID, title and thumbnail. The access token is encrypted at rest.
Alnara requests no Gmail or Drive permission of any kind.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Google Account → Third-party apps with account access.
YouTube
Upload and manage videos, moderate comments, and read live chat on a channel you own.
Permissions we request
- Manage the channel, its uploads, its comments and its live chat —
https://www.googleapis.com/auth/youtube, https://www.googleapis.com/auth/youtube.force-ssl
What we store. The channel ID, title and thumbnail, and the videos and comments you manage through Alnara. The access token is encrypted at rest.
YouTube is reached through the Google connection rather than signed into separately.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Google security settings → Third-party access.
Discord
Post to and moderate channels on a server where the Alnara bot has been invited.
Permissions we request
- Identify you and show whose account is connected —
identify, email - List the servers you belong to so you can choose which to manage —
guilds
What we store. Your Discord user ID, username and avatar; for each connected server, its ID, name and icon. The access token is encrypted at rest.
Signing in identifies you but cannot post. Sending messages requires separately inviting the Alnara bot to the server, which somebody with Manage Server must do — the connection is a pair, and removing either half stops it.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: User Settings → Authorized Apps.
Slack
Post announcements to channels and read the threads that come back.
Permissions we request
- List channels so you can choose where to post —
channels:read, groups:read - Post messages —
chat:write - Read channel history and threads —
channels:history - Read and add reactions —
reactions:read, reactions:write - Resolve the names and avatars of people in a thread —
users:read - Show files shared in a conversation —
files:read
What we store. The workspace ID and name, the channels you connect, and the messages you send or read through Alnara. The access token is encrypted at rest.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Slack → Manage apps → Alnara → Remove.
Twitch
Read and send stream chat, and moderate it.
Permissions we request
- Identify you and show whose account is connected —
user:read:email - Read and send chat messages —
chat:read, chat:edit - Moderate chat: time out or ban, and delete messages —
channel:moderate, moderator:manage:banned_users, moderator:manage:chat_messages
What we store. Your Twitch user ID, login name and profile image, and the chat messages you send or moderate through Alnara. The access token is encrypted at rest.
How to revoke. Disconnect it in Alnara under Connections, and revoke at the platform itself: Settings → Connections → Other Connections.
Telegram
Send and receive messages through a Telegram bot you create and control.
Permissions we request
- Everything the bot can do is decided by Telegram and by you, not by a permission we request
What we store. The bot token you paste (encrypted), the bot’s ID and username, and the chats and messages it handles. The access token is encrypted at rest.
Telegram has no OAuth and no sign-in screen. You create a bot with @BotFather and paste its token, so no Telegram account of yours is ever authorized — the bot is the whole connection. Use /revoke in @BotFather to invalidate the token.
How to revoke. Remove it in Alnara under Connections. See Data Deletion for the platform-side step.
IRC
Join channels on an IRC network and read and send messages.
Permissions we request
- None — IRC has no authorization step
What we store. The server address, port, nickname and password you supply (encrypted), and the messages exchanged. The access token is encrypted at rest.
An IRC connection is a plain server credential you give us, not a grant from a third party. Deleting it in Alnara is the entire revocation.
How to revoke. Remove it in Alnara under Connections. See Data Deletion for the platform-side step.
Questions
If a permission listed here is not clear, or you believe we are requesting something we do not need, write to [email protected]. We treat over-broad permissions as a bug.