Privacy policy
Data controller
Federico Bernacca. For any privacy request write to dev@federicobernacca.com.
In short
FollowGuard never asks for your Instagram username and password and doesn’t require an account.
ZIP import: the file is read on your phone and the data stays there. Username search: the username you look up goes through our server and external data providers, and the result is deleted from the server after 7 days.
ZIP import
When you upload the file exported from Instagram, the app analyses it locally. Followers, following and history are stored only on your device and are not sent to our servers.
You can delete them at any time from the app menu, with “Delete my data”, or by uninstalling the app.
Username search
When you use username search (the free search or the PRO subscription), the username you enter is sent to our server together with your device identifier (see below). The server passes it to external data providers, reached through the RapidAPI platform, which retrieve the profile’s public information: followers and following, with their usernames, names and profile pictures.
Search works only with public profiles and shows only information already publicly visible on Instagram. The providers receive only the searched username: they don’t know who searched it.
The result stays on our server for at most 7 days after completion, so it can reach the app even if it was closed at the time, and is then deleted. On your phone it stays until you delete it.
Device identifier
The app sends the server your device’s Android identifier (Android ID). We use it to deliver the results of your searches, to allow one free search per device and to enforce the subscription limits. We don’t use it for advertising or link it to a name, email or account.
Push notifications
To tell you when a search result is ready we use Google’s Firebase Cloud Messaging. The device’s notification token and the app language are stored on our server, so the notification reaches you in your language. You can turn notifications off in Android settings.
Subscription
The PRO subscription is handled by Google Play: payment data is processed by Google under its own policy and we never see it. To verify the subscription the app sends us the purchase token, which we check with Google Play.
We keep only a fingerprint of the token (SHA-256 hash), together with the product name and the time of the last successful search: they enforce the limit of one search every 24 hours.
Security and stability
Firebase App Check (with Google’s Play Integrity) verifies that requests to the server come from the genuine app and not from automated scripts.
Firebase Crashlytics sends us a report when the app crashes: the error trace, the device model, the Android and app versions and an installation identifier. It is used only to fix crashes.
For each request the server logs its type, the address called, the outcome and the duration, without the searched username. The IP address is used to limit excessive requests.
What we don’t do
We don’t sell data, show ads, use analytics or profiling tools, or take any action on your Instagram account.
Who receives data
Google (Firebase and Google Play), as provider of the services above; the data providers reached through RapidAPI, which receive only the searched username; OVHcloud (OVH SAS), which hosts our server in France.
Our server and the data it keeps stay in the European Union. Google and some data providers may instead process data outside the EU, in particular in the United States. In those cases the transfer relies on the safeguards provided by the GDPR, such as the European Commission’s standard contractual clauses or the EU-US Data Privacy Framework.
Legal basis
We process data to provide the service you request, i.e. the search, the subscription and the notifications about results (Art. 6.1.b GDPR), and for our legitimate interest in protecting the service from abuse and fixing malfunctions: App Check, one free search per device, request limits, crash reports (Art. 6.1.f GDPR).
How long we keep data
- ZIP import data: only on your phone, until you delete it.
- Search results: on the server for at most 7 days after completion.
- Device identifier, notification token and language: deleted after 12 months in which the app doesn’t contact the server, or immediately with “Delete my data”.
- Purchase token fingerprint: up to 12 months after the last successful search.
- Free search already used: after “Delete my data” we keep only the fact that the device has used it, so as not to grant another one, and this too for at most 12 months.
Your rights
From the app menu, “Delete my data” deletes the data on your phone and what the server holds about your device, in one step.
You also have the right to access, rectify, erase, restrict, object to and port your data: write to dev@federicobernacca.com. You can also lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
If you are the person searched
Whoever uses search sees the followers and following of a public profile, which includes your username, name and picture if you appear in those lists. On our server this data stays for at most 7 days. To exercise your rights write to dev@federicobernacca.com.
Children
FollowGuard is not intended for people under 14.
Changes
Any changes to this policy will be posted on this page with a new update date.