Privacy Policy
Last updated: 2026-07-08
GhostList is built around one rule: your Instagram data export is parsed entirely in your browser. The raw ZIP file is never uploaded to our servers — only the derived list of usernames is sent to our API to save your snapshot.
GhostList is operated from Switzerland. We serve users worldwide, so both the Swiss Federal Act on Data Protection (FADP) and, for users in the EU/EEA, the GDPR apply to how we handle your data — this policy is written to satisfy both.
What we collect
- Your email address (for login and, if you opt in, reminder emails)
- Instagram usernames from your followers/following lists, and counts derived from them (not following back, fans, etc.)
- Actions you take in the app — batches opened, profiles marked unfollowed
- For paid plans: billing details handled entirely by our payment processor, Stripe — we never see or store your card number
We never ask for or store your Instagram password.
Legal basis
We process your account and snapshot data to provide the service you've signed up for (contract performance / fulfilling our obligations under the FADP). Reminder emails are sent only if you explicitly opt in (consent) — see below.
Who we share data with
- Supabase — authentication and database hosting (your account, snapshot, and subscription data)
- Vercel — runs the application; does not separately store your data
- Stripe — payment processing for paid plans
- Upstash — briefly processes your IP address only, to prevent abuse of login and upload endpoints
Some of these providers may process data outside Switzerland or the EU/EEA (e.g. in the United States); where that applies, they do so under their own standard contractual safeguards.
We do not sell your data, and we never send it to Instagram or Meta.
Cookies
We use one strictly-necessary cookie, set by Supabase, to keep you signed in. We don't use tracking, analytics, or advertising cookies.
Location for pricing
To show prices in your local currency, we read an approximate country from your IP address at the moment of the request. This isn't logged or stored — it's used only to pick a currency for that page load.
Children's privacy
The service isn't directed at children under 13, and we don't knowingly collect data from them. If we learn a child has created an account, we'll delete the data and disable the account.
Security
We use encryption in transit (HTTPS) and at rest, and the app connects to its database with a least-privilege role that can't perform destructive operations. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security — but we design for it.
Marketing emails
The "email me reminders" checkbox is unchecked by default — we only send re-engagement emails if you actively opt in. You can withdraw consent at any time from Settings, and every email includes an unsubscribe link.
Your rights (GDPR & Swiss FADP)
You can, at any time:
- Request a copy of the data we hold about you
- Request correction of inaccurate data
- Delete your account, which cascades to delete all snapshots and logs
- Withdraw marketing consent
To exercise any of these, contact us at support@ghostlist.app.
Retention
Snapshot and account data is kept until you delete your account. Deleting your account permanently removes all associated data — except billing records Stripe retains under its own legal/accounting obligations, which are outside our control.
Changes to this policy
We may update this policy as the product evolves. If a change is material, we'll give at least 30 days' notice by email or an in-app notice before it takes effect.