Privacy Policy

Last updated: 2026-07-08

GhostList is built around one rule: your Instagram data export is parsed entirely in your browser. The raw ZIP file is never uploaded to our servers — only the derived list of usernames is sent to our API to save your snapshot.

GhostList is operated from Switzerland. We serve users worldwide, so both the Swiss Federal Act on Data Protection (FADP) and, for users in the EU/EEA, the GDPR apply to how we handle your data — this policy is written to satisfy both.

What we collect

We never ask for or store your Instagram password.

Legal basis

We process your account and snapshot data to provide the service you've signed up for (contract performance / fulfilling our obligations under the FADP). Reminder emails are sent only if you explicitly opt in (consent) — see below.

Who we share data with

Some of these providers may process data outside Switzerland or the EU/EEA (e.g. in the United States); where that applies, they do so under their own standard contractual safeguards.

We do not sell your data, and nothing you upload — your export, the accounts in it — is ever sent to Instagram or Meta. If you accept cookies, Meta's advertising pixel is told which pages of this site you opened and whether you signed up or subscribed, and nothing more.

Cookies

One strictly-necessary cookie, set by Supabase, keeps you signed in — it needs no consent because the site can't work without it. For analytics we use PostHog (EU-hosted). By default it runs without cookies: nothing is written to or read from your device, and every visit counts as a new anonymous one. Accepting cookies changes two things — PostHog can then recognise return visits, and we load Meta's advertising pixel, which measures which of our ads led to a signup or a subscription. Neither happens before you accept, and you can switch both off again at any time in Settings.

Location for pricing

To show prices in your local currency, we read an approximate country from your IP address at the moment of the request. This isn't logged or stored — it's used only to pick a currency for that page load.

Children's privacy

The service isn't directed at children under 13, and we don't knowingly collect data from them. If we learn a child has created an account, we'll delete the data and disable the account.

Security

We use encryption in transit (HTTPS) and at rest, and the app connects to its database with a least-privilege role that can't perform destructive operations. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security — but we design for it.

Marketing emails

The "email me reminders" checkbox is unchecked by default — we only send re-engagement emails if you actively opt in. You can withdraw consent at any time from Settings, and every email includes an unsubscribe link.

Your rights (GDPR & Swiss FADP)

You can, at any time:

To exercise any of these, contact us at support@ghostlist.app.

Retention

Snapshot and account data is kept until you delete your account. Deleting your account permanently removes all associated data — except billing records Stripe retains under its own legal/accounting obligations, which are outside our control.

Changes to this policy

We may update this policy as the product evolves. If a change is material, we'll give at least 30 days' notice by email or an in-app notice before it takes effect.