100% ON-DEVICE · NO CLOUD, NO TRACKING
Backup for Instagram — your archive, on your device

Privacy Policy

InstBackup · Backup for Instagram · Effective July 24, 2026

🔒 The short version: InstBackup stores your archive entirely on your device and sends nothing anywhere. No developer servers, no analytics, no telemetry, no accounts. The developer receives no data whatsoever — and has no way to see your archive.

1. Who we are

InstBackup ("the extension") is a browser extension for Google Chrome that backs up the Instagram data your own signed-in account can already see — your posts, reels, stories, saved and tagged posts, followers and following lists, comments on your posts, direct message conversations you can access, and your profile — into a local, searchable archive on your computer. This policy explains what information the extension does — and, more importantly, does not — handle.

2. What data we collect

None. The extension does not collect, transmit, store remotely, sell or share any personal information or browsing data. Specifically, we do not collect:

  • Your archive — the posts, media, messages and lists it backs up stay in your browser’s local storage on your computer; the developer never sees them
  • Your Instagram credentials — the extension never sees, asks for or stores your password, and never performs a login for you
  • Your browsing history or the addresses of pages you visit
  • Personal details such as your name, email address or identifiers
  • Usage analytics, telemetry or crash reports

The extension has no server. There is nowhere for your data to be sent.

3. What is stored on your device

  • Your archive — the content you chose to back up (posts, reels, stories, saved and tagged items, followers/following, comments, messages and media files), stored in your browser’s IndexedDB on this computer only.
  • Your settings — theme, backup preferences, schedules and similar options, kept in Chrome’s extension storage.
  • Session identifiers, read in place — to work inside your existing instagram.com session, the extension reads page-accessible cookies on instagram.com (your numeric user ID, your username and the CSRF token, which Instagram requires as a request header). It never reads your login (sessionid) cookie, and none of these values ever leave instagram.com.

Removing data is instant: Settings → Remove demo data or Reset archive, or simply uninstall the extension.

4. Why the extension requests its permissions

PermissionWhy it is needed
Access to instagram.com
(host permission)
Required to detect your session and fetch your own content — including media files from Instagram’s content servers — so it can be archived locally. The extension runs only on instagram.com; it reads nothing anywhere else.
storage / unlimitedStorageKeeps your archive and settings on your device; personal media libraries routinely exceed the default quota.
downloadsSaves the exports you request (ZIP / CSV / JSON) through Chrome’s normal download manager.
alarmsRuns the optional backup schedule you configure.
notificationsShows a "backup finished" notification. Can be turned off in Settings.
scriptingReconnects to an instagram.com tab that was already open before the extension was installed, so you don’t have to reload the page.

5. Network activity and third parties

The extension uses no third-party services, analytics providers, advertising networks or remote APIs. The only network requests it makes are to instagram.com and Instagram’s own media servers (cdninstagram.com, fbcdn.net) — the same hosts your browser already talks to when you use Instagram — on your behalf, to fetch the content being archived. Media files are fetched without cookies.

6. Your rights and controls

  • Export — take your entire archive, or any single category (followers, following, comments, messages, content, profile), out as ZIP / CSV / JSON at any time.
  • Delete — remove the demo data, one account’s archive, or everything, instantly, from Settings.
  • Inspect — the Privacy dashboard inside the app shows exactly what is stored locally.

7. Scope and your responsibility

InstBackup archives only what your own signed-in account can already access. It does not bypass authentication, private-account restrictions or any other access control. Please use your archive in ways that respect the rights of the people whose content appears in it, Instagram’s terms of service, and the law of your jurisdiction.

8. Children’s privacy

Because the extension collects no data from anyone, it collects no data from children.

9. Changes to this policy

If a future version of the extension ever changes how data is handled, this policy will be updated and the "Effective" date above revised before that version is released. Material changes will be noted in the extension’s store listing changelog.

10. Contact

Questions about this policy or the extension? Contact the developer at dev1tools@proton.me.

© 2026 GrabFlow · InstBackup is not affiliated with, endorsed by, or sponsored by Instagram or Meta Platforms, Inc. · Everything happens on your device.