Privacy Policy Last updated: 15 August 2025

Who we are & scope

Hintstagram (“we”, “us”, “our”) operates the website hintstagram.app and related pages (the “Service”). This policy explains how we handle your information under the UK GDPR, the EU GDPR, and applicable privacy laws. For questions, contact info@hintstagram.app.

What we collect (data minimisation)

  • Email & sign-up details (if you choose to provide them) — used to create or manage your Hintstagram account, send essential communications, and respond to support requests.
  • In-session usage data (ephemeral) — basic, temporary state in your browser (e.g., session storage) so the site functions while you’re on the page. We do not persist your stats or content after you leave.
  • Automatic technical events — standard server logs (e.g., IP address, timestamp, user agent) necessary for security and to deliver the Service. We do not use third-party tracking/advertising cookies.

We do not see or store any other user or private information. We do not sell your data.

Instagram / Facebook (Meta) integrations

If you choose to connect with Instagram or Facebook, we only request the minimum permissions required to provide the feature you use. We do not store your Meta access tokens on our servers; processing is performed in your browser and any tokens kept in session storage are cleared when your session ends or you close the browser tab. We never post on your behalf without your explicit action.

You can revoke access at any time via your Meta account settings. Data received from Meta is handled in accordance with this policy and Meta’s platform terms.

How we use your information

  • Provide, operate, and secure the Service.
  • Communicate with you about your account or requests.
  • Comply with legal obligations and prevent abuse.

We do not use your information for targeted advertising.

Cookies, local storage & “what disappears”

Strictly necessary session cookies / storage. We may use a short-lived, essential cookie and/or session storage to keep you signed in and make the site work. These expire when you close your browser (or shortly thereafter).

No analytics or advertising cookies by default. If we embed third-party content (e.g., Instagram), those services may set their own cookies — see their policies for details.

Ephemeral by design: while you’re on the site, you can view your own stats and content. When you leave, that in-session data is cleared and is not retained by us.

Sharing & processors

We do not sell your data. We may share limited information with trusted service providers (e.g., hosting, email, form handling) who act under our instructions as data processors and are bound by confidentiality and data protection terms.

We may disclose information if required by law, to protect our rights, or to prevent abuse.

Legal bases (UK/EU GDPR)

  • Consent — for email sign-ups and optional features you choose to use.
  • Performance of a contract — to provide the Service you request.
  • Legitimate interests — to keep our Service secure and running (balanced against your rights).

Retention

  • Email & sign-up details — kept until you unsubscribe or request deletion, or until your account is closed.
  • Session data — cleared when you end your session/close your browser tab.
  • Security logs — kept for a short, proportionate period for fraud and abuse prevention.

International transfers

If we use processors outside the UK/EU, we rely on lawful transfer mechanisms (e.g., UK/EU Standard Contractual Clauses) and supplementary safeguards as needed.

Your rights

Under the UK GDPR/EU GDPR, you may have the right to access, rectify, erase, restrict processing, object, and data portability. You also have the right to withdraw consent at any time (this does not affect processing before withdrawal) and to lodge a complaint with your local authority (e.g., the UK ICO).

To exercise your rights, contact info@hintstagram.app. We may need to verify your identity before fulfilling requests.

Data deletion instructions

If you created an account or shared your email with us, you can request deletion by emailing info@hintstagram.app with the subject “Data Deletion Request”. We will remove your email and associated records (if any) and confirm once completed.

In-session data (your stats/content visible while using the site) is not retained by us and is cleared when you leave.

Children’s privacy

The Service is not intended for children under 13, and we do not knowingly collect personal data from them. In certain EU countries, additional age thresholds may apply. If you believe a child has provided personal data, contact us so we can delete it.

Security

We use reasonable technical and organisational measures to protect information. No method of transmission or storage is 100% secure, but we design Hintstagram to minimise data collection and retention.

Changes to this policy

We may update this policy to reflect changes to the Service or law. We will post the updated date at the top. Material changes will be highlighted where appropriate.