Earlier quoted context omitted.
The user is risking more than their own data; they are also risking the data of their friends. If I grant a friend permission to view my photos, I am not also granting some random 3rd party that permission.
>If I grant a friend permission to view my photos, I am not also granting some random 3rd party that permission. Assuming the "third-party" client is just that (a client app), there really shouldn't be an issue. If I use FluffyChat[0] instead of Element[1], do the FluffyChat folks have access to all my (and those with whom I communicate) Matrix communications? If I use Element, do they have such access? If you use Fi…
Tell me, for the OGApp what is the monetization scheme? How do they intend to make money? By default if you don't see anything upfront you should assume that your data is what is being monetized. And your data in this case includes everything the app can pull down from Instagram while it's acting as a proxy.
Similarly and I keep mentioning this: Just because there's no current evidence of them stealing your data does not make them trustworthy. A site asking you for Steam login details would be almost impossible to prove that it's phishing for login details, but it would be a bad, bad idea to put in your login info anyways.
If they want their app to be trusted then it should be made open source.