Skip to content
What is kept

What happens to your data.

It comes from Instagram through the official connection, you can cut it off at any time, and most of what we hold is deleted on a fixed schedule.

Every kind of data has a day it gets deleted.

six things it holds, one year, and it repeats

  1. @maya.everyday

    Chrome on macOS

    a signed-in session

    30 days · sign-ins

  2. draft_contract ok 1.2s

    a line in the activity log

    90 days · activity log

  3. An invoice is properly late

    08:00

    a message it sent you

    120 days · notifications

  4. My 6am morning routine

    a copy of your numbers, taken when we last read Instagram

    180 days · sync snapshots

  5. Most people get the first ten minutes wrong.

    a line of a transcript

    365 days · transcripts

  6. Three things I stopped doing before 7am.

    a caption the AI wrote

    365 days · AI drafts

    The deadline passed and the deletion job refused to touch it.

Five of the six go. The sixth is the one the AI wrote for you, and the job that does the deleting refuses to touch it.

Windows are the product's own retention settings, for sessions, logs, notifications, raw_snapshots, transcripts, ai_generations. Each store says whether it is deleted or anonymised, and the one thing it refuses to purge says so in its own words.

The scheduled job

The one thing it refuses to delete is your own work.

DATA_GOVERNANCE

content

anonymise (strip your name off it and keep the rest)after 365 days

what the job wrote

refused: anonymising this table would destroy the creator's own work. Correct the governance map or implement it deliberately.

every run before this one

It is your library. A draft you wrote a year ago is work you are paying us to keep, so nothing strips your name off it.

The order is written into the retention rules as anonymise rather than delete, and the wording above is quoted from what actually runs rather than paraphrased.

Getting it out

7 files cover everything you can see in the product.

67 columns across them, and you can download them whenever you like.

analytics-daily.csv
DateFollowersReachImpressionsEngagement RatePosts
filters: daysempty until you connect an account

The file you download has the same numbers as the screen you downloaded it from.

Every column here is read from the code that writes the file. This one downloads from /api/analytics/export.csv, one file per dataset, with every dataset listed above.

The connection

Your data comes from Instagram, and you hold the switch.

The official connection, end to end. Your password is never part of it.

  1. You approve it at Instagram

    your password is typed on Instagram's page, never on ours

    You approve it on Instagram, on Instagram's own screen

  2. Instagram gives us a key that acts on your behalf

    it is stored scrambled, and only our servers can unscramble it

    Encrypted before it is stored, with a key we hold separately

  3. We ask Instagram for your data

    your own account's data comes through Instagram's official connection

    Instagram's official connection, on a pinned version

  4. Instagram tells us the moment something changes

    we check that every message really came from Instagram

    Every message is signature checked before we believe it

  5. We build your insights from it

    everything you see is worked out from your own account

    Built from your own history, nothing bought in

Nothing new arrives. What we already have is deleted on the same dates shown at the top of this page, and Instagram stops answering for you the moment you say so.

If the secret that scrambles those keys is missing, the product will not start. It does not quietly make a temporary one instead, because that would leave every key already stored unreadable.

Tokens are encrypted with AES-256-GCM before they are stored. We stay on a pinned version of Instagram's official interface rather than whatever is newest. Every delivery Instagram sends is signature checked in constant time before we act on it.

Getting in

Two of these can be handed to the wrong person.

The same sign-in, sent to two addresses four characters apart. Watch which of the three reaches both.

  • The app locks itself

    Your own face or fingerprint, on the phone. It never leaves the device.

  • Every session is listed

    Every device signed in now, and any of them ended from here.

  • Failed sign-ins are kept

    The attempts that did not work, which is the half that warns you.

You can turn all of this on today. None of it is compulsory, and the one that cannot be phished is the one nobody has to remember.

Passkeys are the web standard, with the origin checked on every use. The code is 6 digits on a 30 second step, accepted one step either side of now, and the secret encrypted at rest. Every session and every login is listed for you. The app lock uses the device's own biometry, so we never hold it.

See what it keeps on your own account.

Connect your Instagram and every window on this page applies to it from the first sync.

Cancel any time. Every dashboard and report is free to open.