Privacy policy

Short, because there is not much to describe.

What is collected

Links you paste. Sent to the server to be resolved, cached for fifteen minutes so repeat lookups are fast, then deleted. Not linked to you.

Your IP address, briefly. Used only to count requests for rate limiting. The counter expires within a minute and the address is not written to any log or database.

A session cookie. Only if you use the contact form or the admin area. Nothing is set for ordinary tool use.

What is not collected

No accounts, no email addresses unless you write to us, no Instagram credentials (never asked for, never accepted), no download history, no cross-site tracking, no advertising profile, no fingerprinting.

Third parties

Media files are fetched from Instagram's content servers on your behalf. Instagram sees a request from this server, not from you; your IP is not passed on.

If analytics is enabled on this installation, it is configured with IP anonymisation and no cross-site identifiers. Nothing is shared or sold, because there is nothing to share.

Retention

Cached lookups: 15 minutes. Rate-limit counters: 60 seconds. Contact messages: kept until the matter is resolved, then deleted. Media files: never stored.

Your rights

Under GDPR and similar regimes you can request access to, correction of, or deletion of personal data held about you. In practice the only category that exists is a contact message you sent yourself. Write to the address on the contact page and it will be removed.