Privacy Policy
Last updated:
This page explains what Osintgram collects, why, who processes it on our behalf, how long it is kept, and the rights you have. Plain language, no traps.
1. Who operates Osintgram
Osintgram is an independent web tool for Instagram open-source intelligence (OSINT). It is not affiliated with Instagram or Meta. For any privacy-related question or anything about this policy, write to [email protected].
2. What we collect
We collect only what is needed for the service to work and to defend it against abuse.
Account data
When you sign in, our authentication provider stores your email address, a display name or username, and a stable user identifier. This lets us link your lookups to your account, show your credit balance, and enable paid features.
Search queries
When you run a lookup, we record the Instagram username you looked up, the module you requested, the success or failure, and the timestamp. If the lookup returns data, the consolidated report is saved in your history so that you can reopen it without spending another credit.
Technical data tied to each request
We store your IP address with each request. This data is used to enforce rate limits, detect abuse, and provide an audit trail.
Payments and credits
When you buy credits, our payment provider (Stripe) processes your card data. We never see your card number. We do store the checkout session ID, the payment intent ID, the amount, the currency, and the credits granted, so that we can reconcile your wallet and answer billing questions.
Cookies and similar storage
We use strictly necessary cookies for login sessions, a little local storage for the locale and theme preference, and product analytics cookies (set by our analytics provider, hosted in the EU) once you are signed in. No advertising cookies, no third-party trackers for marketing purposes.
3. What we do NOT collect
- We never notify or interact with the Instagram accounts you look up. We only read data Instagram already exposes publicly, through our data provider.
- We do not ask for or store your Instagram password, and we never log in to Instagram on your behalf.
- We do not enrich reports with third-party sources (data brokers, private breach databases) behind the scenes.
- We never sell your data.
4. Why we process your data (legal basis)
- Contract. To run the lookups you ask for, save your history, debit your credits, and process payments.
- Legitimate interest. To prevent abuse (rate limiting, fraud detection, debugging), measure aggregate usage, and improve the product.
- Legal obligation. To retain billing records and respond to lawful requests.
- Consent. For optional product analytics, where local law requires it.
5. Who processes data on our behalf
We rely on a small number of providers. Each one is a processor under GDPR, contractually required to process your data only on our instructions.
- Authentication provider. Stores your sign-in credentials and account profile.
- Our data provider. We send it the Instagram username you look up and the module you requested; it queries Instagram and returns the public profile data. Each provider request costs one credit.
- Stripe. Processes card payments for credit purchases.
- Cloudflare. Acts as CDN and proxy in front of the site, sees IPs, blocks abusive traffic.
- Product analytics provider (EU-hosted). Records usage events to help us improve the product. Profiles are only created for signed-in users.
- Database and hosting provider. Stores account, history, and credit ledger, in the EU.
An up-to-date, detailed list of processors is available on request.
6. How long we keep data
- Account data: as long as your account exists. Deleted on account-deletion request.
- Lookup history (reports): kept until you delete the entry from your history. Once deleted, they are immediately hidden from your side; a short-lived copy is retained for fraud and abuse defense before purge.
- Search logs (IP, query, success): kept for abuse defense. Purged periodically.
- Payment records: kept according to tax and accounting obligations (typically several years).
7. Your rights
If you are in the EU, the UK, or a jurisdiction with similar law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Erase your data (right to be forgotten).
- Export your data in a portable format.
- Restrict or object to processing.
- Withdraw your consent at any time, where processing is based on consent.
- Lodge a complaint with your data protection authority.
To exercise a right, write to [email protected]. We respond within 30 days.
8. About the accounts you look up
Osintgram is an OSINT tool. By design, every lookup reads a public Instagram profile's data (profile details, follower and following counts, public posts, stories, highlights) through our data provider. We do not notify the account, we keep nothing about it beyond the report you generated, and we do not enrich the data with third-party sources behind the scenes.
If you are the account owner and want a saved report about you removed, write to [email protected]. Provide enough to identify the report; we will confirm and delete.
9. Changes to this policy
We may update this page. The date at the top reflects the latest revision. For material changes, signed-in users will be notified by email or via an in-app banner before they take effect.
10. Contact
Privacy questions, deletion requests, processor list, breach notifications: [email protected].