Privacy Policy
1. Information we collect
When you create an account we collect the details you provide (your email address, and your name and profile picture if you sign in with Google) and basic usage data needed to run the service.
2. Creator data
InstaVision surfaces information that is already publicly available on Instagram profiles. We do not collect private or non-public personal data.
3. How we use data
We use your information to provide and improve the service, respond to access requests, and communicate about your account. We do not sell your personal information.
4. Analytics and cookies
We use the tools below to see how the site is used and to fix what breaks. Some of them set identifiers in your browser, so we don't call them anonymous.
Yandex Metrica (Yandex) counts page views, clicks and form submissions (never what you type). It does not record sessions. It does not run in our internal admin area, or on a page whose address carries an invitation link, or an email address in its query. The page addresses we report as page views keep only campaign tags (Yandex's own ad-click id included) and a few page settings, with record ids replaced by placeholders; click reports carry the page's address as it is. Where a link to another website leads is not reported. Yandex Metrica sets its own cookies and browser-storage entries, among them the cookies _ym_uid (identifies a browser, 1 year), _ym_d (the date of your first visit, 1 year) and _ym_isad (an ad-blocker check, 20 hours). Yandex lists its cookies, with their lifetimes, at yandex.com/support/metrica/general/cookie-usage.html.
Vercel Web Analytics counts page views without cookies: Vercel recognises a visit by a hash of the request and discards it after 24 hours. The addresses of our pages it receives are cleaned the same way.
Sentry receives a report when something breaks. It also records a sample of sessions, and the sessions that hit an error, with all text masked and all images and media blocked; link and page addresses are recorded as they are.
Our own cookies. These four can be read only by our server:
- iv_did: a random identifier for this browser, used to spot repeat sign-ups for the free credits. 1 year.
- iv_ft: how you first arrived (see below). 1 year.
- iv_login_next: the page to return to after you sign in. 24 hours.
- iv_login_email: the email address you entered on the sign-in page, so the next page can show it. 24 hours.
These can also be read by scripts on the page:
- iv_goal: which way you signed up (Google, an emailed link, a code or an invitation), for our analytics. 10 minutes.
- Supabase session cookies (sb-…): keep you signed in. Up to 400 days.
The site also keeps a few entries in your browser's storage, for example so that a starter prompt is sent only once; Sentry keeps its own while it records a session.
The first time you arrive from a campaign link, an ad or another website, a first-party cookie (iv_ft) remembers for up to a year the campaign tags, the domain of the referring website (not the page), the page you landed on (with any ids or tokens removed) and the time you arrived. For an ad click it keeps only which kind of click identifier the link carried (for example gclid), never the identifier itself, and it drops anything that looks like an email address. If you sign up with an emailed link, these details may be copied into your new account's sign-in record when the link is sent, so they are not lost if you open the link on another device, and we remove them from that record once your sign-up has been recorded.
When you sign up we keep the first-visit details above, a hash of the browser identifier, a normalized copy of your email address and its domain (and whether that domain is a throwaway-mail service), and whether the sign-up looks like a repeat of an earlier account. We use this to protect the free credits from abuse.
5. Contact
Questions or data requests? Email admin@instavision.co.