InViewer Privacy Policy

Effective October 6, 2026 · Applies to the public-data release of InViewer 2.0 for iOS · Contact: support@inviewer.store

InViewer displays public Instagram content, saves content to a personal archive, and creates follower and engagement reports for a selected profile. This policy explains the data used by the app, our backend and its service providers.

The short version

What we process, and why

Installation identifier and App Attest public key and attestations

Where: Our backend; the device holds the App Attest private key

Why: Identifying an installation, applying limits and verifying requests

Search text, requested usernames and profile IDs, profile details and public content

Where: Our backend and HikerAPI; your phone; some responses are kept in shared backend caches

Why: Finding profiles and fetching the requested public data. Media is loaded from the returned content URLs, so the media host receives the network request

Selected profile, including username, ID and privacy status; history and favourites

Where: Your phone; requested profile identifiers are sent to our backend. Daily quota markers associate opened usernames and profile IDs with the installation

Why: Choosing an account for reports, reopening profiles and avoiding repeated quota charges for the same profile. Selection is not authentication or proof of ownership

Watch list and push notification token

Where: Our backend; Apple Push Notification service receives push requests

Why: Checking public profiles and sending background updates. The app registers for a push token on launch, independently of permission to show alerts. Visible notifications require that separate permission

Request counts, quota records and notification preferences per installation

Where: Our backend

Why: Applying usage limits, accounting for upstream requests and respecting your notification choices

Request route, status, duration and installation identifier; IP address for rate limiting

Where: Our backend and Cloudflare

Why: Diagnosing failures, monitoring service performance and limiting abusive requests

Subscription status, product, expiry and RevenueCat customer identifier

Where: Our backend, RevenueCat and Apple. Our backend links the purchase state to the installation

Why: Providing paid access, restoring purchases and measuring purchases and subscription performance. Apple handles payment; we do not receive your card details

Public follower/following lists, public likes and comments

Where: Requested through our backend and HikerAPI; collected snapshots and report calculations are stored on your phone

Why: Comparing follower snapshots and calculating activity reports from the available public data

Saved media and calculated reports

Where: Your phone, in the app's database and archive; exported copies go to the destination you choose

Why: Your personal archive and report history

Crash reports, diagnostic logs, app-instance identifiers and usage events, such as screen openings and purchase outcomes

Where: Firebase Crashlytics and Firebase Analytics (Google)

Why: Diagnosing failures and understanding feature use. We do not set a Firebase user ID. Advertising identifier collection and ad personalisation are disabled

Approximate geographic information, such as country or city

Where: Firebase Analytics (Google), derived from network information

Why: Understanding where the app is used. This does not use GPS or request access to iOS Location Services

How reports work

Follower reports compare complete snapshots collected for a public profile. The first check establishes a baseline, and a change date records when the app detected it. If data is incomplete or unavailable, it cannot establish a complete comparison.

These reports use the public connections of the selected profile. InViewer does not read the contacts in your phone's address book.

Secret readers are accounts with recorded public likes or comments that are absent from the latest complete follower snapshot. Rankings use the posts and activity the app could collect and may reflect only a sample. Instagram does not reveal profile visitors. We do not collect story viewer lists or infer unobserved visits. An absence of recorded activity does not prove that someone never viewed or engaged with a profile.

InViewer does not use an Instagram account to follow, like, comment, send messages or mark stories as seen. It does not change account privacy settings. You may choose to make your own account public for a check and restore its privacy afterwards; private content cannot be analyzed.

Service providers

These providers also process service, security or transaction information under their applicable policies. InViewer is independent of Instagram and Meta Platforms, Inc.

Optional information for Apple refund reviews

If your version offers this choice and you allow it, InViewer uses RevenueCat to send Apple information when Apple reviews a refund request. The response includes your consent, whether the purchase was delivered, whether feature information was provided before purchase and any applicable refund preference. Apple decides whether to issue a refund.

This choice is optional and separate from buying Pro. Refusing or withdrawing permission does not change your purchased access. Browsed profiles, media, reports and Instagram cookies are not included in this response.

We keep the choice, disclosure version and delivery status on your phone. Our backend stores the choice, version, revision and update time against your installation identifier. RevenueCat stores the corresponding customer attribute so the applicable refund rule can be selected.

You can review or withdraw permission in Settings. An internet connection is needed to confirm withdrawal on the server. Until it is confirmed, Settings shows a pending status and the previous permission may still apply; return online and retry. Deleting app data also requests withdrawal before the installation record is removed.

Withdrawal stops future responses once confirmed. It cannot recall data already sent to Apple. RevenueCat may retain the withdrawal attribute and purchase history under its retention policy. For data already held by Apple, use Apple’s privacy request process.

Apple privacy requests

Retention

Your choices

Children

InViewer is not intended for children under 13, or below the minimum applicable age in their country. We do not knowingly collect personal data from children below that age.

Changes and contact

Policy changes will be published here with an updated effective date. Contact support@inviewer.store with privacy questions, or visit Support.