Privacy Policy

Last updated: 24 July 2026

1. Data controller

In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), the following details are provided about the data controller:

2. Data we collect

We process the following categories of personal data:

  • Account data: email address for authentication. If you sign in with Google, we also receive the name and profile picture associated with that Google account.
  • Instagram session credential: only if you choose to connect one in order to check private accounts. It is stored encrypted at rest and is used exclusively to run the checks you request, on your behalf. It is never used for any other account, never shown back to you in full, and is deleted when you disconnect.
  • Payment data: card and payment details are processed directly by Stripe; we do not store full card details. We retain the payment identifier, amount, and date.
  • Private-check records: when you spend a coin, we record the handle checked, the timestamp, and the resulting balance movement. This ledger is what makes automatic refunds and balance disputes possible, so it cannot be switched off while you use paid checks.
  • Technical data: IP address, session identifiers, browser type, and server logs.

What we deliberately do not collect: free public searches are not stored. The handle you type into the public search is used to answer that one request and is not written to any database, not linked to you, and not retained afterwards. Your IP address is held briefly in server memory to enforce a short-term request limit, and is not used to build any profile.

Results of a search may include personal data of third parties (public Instagram handles, display names, profile pictures). That information is read live from Instagram to display the answer and is not stored by us afterwards.

3. Purposes and legal basis

  • Create and manage your account — performance of contract (Art. 6.1.b GDPR).
  • Run the searches you request and deliver results — performance of contract (Art. 6.1.b).
  • Store your Instagram session and act on your behalf — performance of contract, on your explicit instruction (Art. 6.1.b).
  • Sell coins and keep the balance ledger — performance of contract (Art. 6.1.b).
  • Comply with tax and accounting obligations — legal obligation (Art. 6.1.c).
  • Handle queries and support — performance of contract / legitimate interest (Art. 6.1.b/f).
  • Prevent fraud, abuse, and chargeback loss — legitimate interest (Art. 6.1.f).

4. Retention periods

  • Account and coin balance: for as long as you keep the account active.
  • Instagram session credential: until you disconnect it or delete your account, whichever is first. Sessions Instagram has invalidated are unusable and removed on the next connection attempt.
  • Coin ledger (including checked handles): kept while the account exists, because it is the record behind every balance and refund.
  • Billing data: 6 years, in accordance with applicable accounting and tax law.
  • Technical logs: up to 12 months, for security purposes.
  • Public searches and their results: not retained.

5. Recipients and processors

To provide the service, we share data with the following sub-processors, with whom the data processing agreements required under Article 28 GDPR have been signed:

  • Supabase Inc. (USA) — authentication, database, and encrypted storage of the Instagram session credential.
  • Stripe Payments Europe Ltd. (Ireland) — payment processing.
  • Google Ireland Ltd.— only if you choose “Sign in with Google”, for authentication.
  • Our hosting provider — running the application and its server logs.

Searches are executed by our servers against Instagram's own endpoints. Meta Platforms therefore sees the request, and — for a private check — sees it as coming from the session you connected. We have no control over what Meta records about it; their processing is governed by their own privacy policy, not this one. No data is shared with any other third party unless required by law.

6. International transfers

Some of the providers listed above are located outside the European Economic Area (mainly the USA). These transfers are carried out with appropriate safeguards under Chapter V GDPR: Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and, where applicable, adherence to the EU–U.S. Data Privacy Framework.

7. Your rights

You may exercise the following rights at any time:

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Erasure (“right to be forgotten”).
  • Restriction of processing.
  • Data portability.
  • Objection to processing.
  • Withdrawal of any consent given.

To exercise these rights, write to [email protected] from the address associated with your account. If you consider that your rights have not been properly addressed, you may lodge a complaint with the supervisory authority in your country of residence; in the EU, a list is available at edpb.europa.eu.

If you appear in someone else's search results and want your public account excluded from this service, write to [email protected] — you do not need an account with us to make that request.

8. Security

We apply appropriate technical and organisational measures: encryption in transit (HTTPS), encryption at rest for the stored Instagram session credential, row-level access controls so one account can never read another's data, server-side-only handling of secret keys, and audit logs.

9. Automated decisions

We do not carry out automated decision-making that produces legal effects or similarly significantly affects you. Ordering results newest-first is a mechanical sort, not a profiling decision.

10. Minors

The service is not directed at people under 18 years of age, and accounts may not be created by them.

11. Cookies

We use strictly necessary technical cookies only. See the Cookie Policy for the full list.

12. Changes to this policy

We may update this policy to reflect legal or service changes. The current version is always available on this page, with the date of the last update shown at the top.