IG Unfollower Tracker Privacy Policy

Effective date: October 7, 2026

1. Scope and Contact

This policy covers IG Unfollower Tracker, including the browser extension named “Unfollowers Tracker - Who Doesn't Follow Back,” this website, and its associated sign-in, membership and subscription services. These services are operated under the name Unfollowers Tracker. For privacy questions, support or account deletion, email [email protected].

2. Information We Access and Collect

The extension reads your signed-in Instagram account ID and username, following and follower lists, and relationship information. Profile information may include account IDs, usernames, display names, avatar URLs and cached images, private-account and verified status, and whether someone follows you back.

It uses your current Instagram session and CSRF token to make authenticated requests. It does not ask you to enter your Instagram password into the extension. Google sign-in uses Chrome Identity and the openid, email and profile scopes. The Google OAuth token is sent to the membership API for sign-in verification. We store your email to identify your account and paid membership, rather than storing your Google name or avatar. Membership authentication tokens, membership level, subscription status, expiration and quotas are also processed to provide account access and entitlements.

Local records include whitelists, candidate accounts, scan checkpoints, synchronization times, task state, settings, unfollow counters and trial records. Upgrading sends your plan ID, email and membership token to the subscription website. Stripe directly collects payment information at checkout; we do not store your card details. Account and order records are separate from card details.

If you email us, we receive your email address, message and any attachments you choose to send to respond to your request. Do not send passwords or authentication tokens. Our website uses Microsoft Clarity for website analysis. Clarity processes interaction and device/browser data and can use cookies and session recordings, as described in Microsoft's documentation. The analysis page also requests the JSZip library from cdnjs.cloudflare.com. Website and API requests reach the infrastructure serving those services; server logs and backups are retained for one month.

Data categorySourcePurposeStorage locationRecipients
Instagram profiles, relationships and avatarsInstagram pages, interfaces and avatar hostsRelationship results, scans, whitelist and requested unfollowsBrowser IndexedDBYour browser; Instagram and image hosts for feature requests
Instagram session and CSRF tokenYour existing login sessionAuthenticate Instagram requestsBrowser session and request processingInstagram
Google OAuth tokenGoogle through Chrome IdentityVerify membership sign-inAuthentication processingGoogle and membership API
Email, membership token and entitlementsSign-in and membership serviceIdentify paid users and manage accessExtension storage.local and membership serviceMembership API; email and membership token also reach the subscription site
Settings, whitelist, scan and task recordsYour choices and extension operationsResume tasks and remember preferencesIndexedDB and extension storage.localYour browser
Plan, order and payment informationUpgrade flow and Stripe checkoutSubscriptions and payment processingAccount/order service; payment details with StripeSubscription website and Stripe
Support messagesYour email and attachmentsAnswer support and deletion requestsSupport mailboxSupport staff and email service
Website interactions and requestsWebsite visitsWebsite analysis and deliveryClarity and service infrastructureMicrosoft, website hosting infrastructure; cdnjs for library requests

3. How We Use Information

We use relationship data to display results, identify accounts that do not follow you back, maintain whitelists, resume scans and perform unfollows you request. Authentication and membership data verifies sign-in and manages access, quotas and subscriptions. Payment-related information supports checkout and subscription management. Support messages are used to respond to you, and Clarity is used to understand website usage. We do not sell user data, use it for advertising or provide it to data brokers.

4. Local Processing and Storage

Instagram profiles, relationship data, avatars, whitelists and scan state are saved in browser IndexedDB, in a database named ig_unfollower_tracker opened by the Instagram content script. Extension storage.local separately stores membership email and token, membership state, settings, counters and trial records. It is not Chrome Sync storage. XOR/Base64 obfuscation of membership records is not secure encryption.

Our website's separate file-analysis tool uses localStorage for analysis history, local Pro status and upload-limit records. Website storage, extension storage and server accounts are distinct. Local processing does not mean no external communication: the extension communicates with Instagram, image hosts, Google, the membership API and the subscription website. Membership and order records are handled by the associated server services, and Stripe handles payment details.

5. Data Transmission and Sharing

  • Instagram and image hosts: receive authenticated feature requests, requested unfollow actions and avatar requests.
  • Google: handles Google sign-in through Chrome Identity.
  • Membership service: https://api.savemydayapp.com receives the Google OAuth token to verify sign-in and your email, membership token and product channel identifier for membership checks. The extension's relationship scanning and unfollow flows process lists locally rather than uploading follower or following lists to this membership API.
  • Subscription service: https://www.savemydayapp.com/social/subscribe/redirect.html receives the plan ID, email and membership token when you upgrade. These are associated membership and subscription services covered by this policy.
  • Stripe: receives checkout information to process payments and subscriptions. See Stripe's Privacy Policy for its own processing.
  • Website and support services: Microsoft receives Clarity analytics data; website infrastructure and cdnjs receive requests needed to deliver their resources. Support messages reach our support mailbox.

We do not provide Instagram relationship lists to advertisers or data brokers. Communication with Instagram to provide the extension's features is separate from membership and billing communication.

6. Retention

Local caches have no unified automatic expiration period. They remain between sessions until updated or deleted through the relevant feature or browser storage clearing. Removing a whitelist entry removes that entry, not all profile data. Local membership records are updated when saved; invalid membership credentials can trigger removal of the local membership record. Other preferences and task records are separate.

Server account and order records have no automatic expiration and are retained until a deletion request is carried out. Server logs and backups are retained for one month; copies in backups may therefore remain until that retention period ends. Stripe maintains its own records under its privacy policy, including records it must retain independently. Clarity analytics and support correspondence are separate from our one-month server-log and backup rule; contact us for questions about those records or deletion.

7. User Choices and Deletion

You can stop using or disable the extension in Chrome's extension manager. You can remove entries using the whitelist controls. Disabling the extension does not delete existing data or cancel billing.

To remove extension-managed local storage, remove the extension through Chrome's extension manager. Do not rely on uninstalling to remove every website-origin database. Use Chrome's site-data settings to clear Instagram site data for content-script data and unfollowers-tracker.com site data for the website's analysis records. Clearing Instagram site data may sign you out and remove other Instagram data. For targeted database removal, contact us for help identifying ig_unfollower_tracker in your browser; storage locations can differ between browsers.

Local clearing and signing out do not delete your server account. Email [email protected] to request account-data deletion. When we carry out account deletion, we delete the account data and cancel the associated Stripe subscription to stop further recurring charges. You will no longer be able to sign in to that account. Backup copies follow the one-month retention rule. This does not promise deletion of records independently retained by Stripe or a refund of earlier payments. You can also cancel a subscription within the app without requesting account deletion.

8. Security

The configured Instagram, membership and subscription endpoints use HTTPS. The current authentication and upgrade flows include tokens in URL parameters, so those URLs should be treated as sensitive and not shared. Local membership obfuscation is not strong encryption. No system is absolutely secure; we do not promise end-to-end encryption or that all stored data is encrypted.

9. Permissions

  • storage: saves settings, membership state and feature records.
  • tabs: locates and manages relevant tabs and coordinates Instagram and subscription flows.
  • identity: supports Google sign-in.
  • Instagram host access: reads relevant Instagram pages and communicates with Instagram for relationship and unfollow features.

10. Changes and Contact

We publish updates at this URL and revise the effective date shown above. For questions, support or account deletion, contact [email protected].