Privacy Policy
A factual explanation of the information involved when you browse the site, resolve an Instagram link, download media, or contact us.
This Privacy Policy applies to the InDownloader website and the API used by its download tools. References to “InDownloader,” “we,” or “us” mean the maintainers publishing the service under the InDownloader name. The site does not currently publish a separate legal-entity name or postal address. You can read more on the About page and contact us using the details below.
The service has no user accounts and does not require an Instagram login from you. That reduces the information involved, but it does not mean that no data is processed. The categories and limits are described here without making a “zero-log” or absolute anonymity claim.
Information we process
Instagram links and media identifiers
When you use a downloader, your browser sends the Instagram URL you entered—or a profile URL created from the username you entered—to our API. The API validates that address and may process public metadata associated with it, such as a shortcode, username, caption, post time, media type, dimensions, and expiring Meta CDN locations. A later download request includes opaque media identifiers and may include the original or canonical Instagram address so the API can resolve the file again after a cache miss.
Network and device information
Like other internet services, our infrastructure and network provider receives technical request information needed to route, secure, and troubleshoot traffic. This can include an IP address, request time, method, API path and query parameters, browser headers, response status, approximate network location, and performance or security signals. The application can use an IP-derived key for short-window rate limiting when that optional control is enabled. It does not use that key as an InDownloader account or advertising identifier.
Downloaded media
When you choose a download, the API requests the selected file from an allow-listed Meta media host and streams the response to your browser. It also processes normal download headers, including byte-range requests used by video players and download managers. Downloadable CDN addresses are kept on the server side; the browser normally receives an InDownloader download URL instead.
Information you send by email
The contact form does not submit information to an InDownloader form database. It opens your email application with the name, email address, subject, and message you entered. If you choose to send that email, we and the email providers involved will process its contents and delivery metadata so the message can be delivered and answered.
Browser storage and clipboard access
The site stores a theme value in your browser's local storage so it
can remember light, dark, or system appearance. This value is not sent to the
downloader API. If you press a paste button, the site asks the browser for
clipboard access and uses the returned text to fill the relevant field; browser
permissions control whether that access is allowed.
How we use this information
- to validate a submitted Instagram address and find supported media;
- to prepare and stream the file or preview you selected;
- to reduce repeated upstream requests through brief metadata caching;
- to prevent excessive automated use when abuse controls are enabled;
- to diagnose failures, protect the API, and maintain service reliability;
- to respond to support, privacy, correction, or rights-related messages; and
- to comply with a valid legal obligation or protect users and the service.
We do not sell submitted links or contact messages, use them to build advertising profiles, or use them for cross-context behavioral advertising.
Caching, logs, and retention
Resolved metadata
Successful resolution results may be stored in our provider's edge cache for about 10 minutes. This cache can contain the resolved post metadata needed to display results and locate downloads, including signed media locations. It exists to avoid requesting the same public information from Instagram for every visitor. It is a short-lived technical cache, not a permanent download history.
Media files
The service does not intentionally save a copy of the photo or video you download. Upstream media requests and download responses are configured not to use the API's media cache, and the response body is passed through as a stream. Our infrastructure and network providers still necessarily process those bytes while transmitting them.
Operational logs
The API emits structured diagnostic messages for unexpected failures and for problems with optional cache or abuse-control services. The application code does not intentionally add the pasted Instagram link or client IP address to those messages. However, our provider's platform-level request and observability systems may process request metadata, including API paths and query parameters, under the applicable platform configuration and retention rules. We therefore do not promise that every request is “zero log” or deleted instantly.
Other retention
- The theme preference stays in your browser until you change it, clear site storage, or remove it using browser controls.
- Rate-limit counters, when enabled, are used for short abuse-control windows; our provider may separately retain infrastructure security information.
- Emails remain in the mailboxes and systems used to send and receive them until they are deleted under the relevant mailbox and provider settings or retained for a legitimate support, security, or legal need.
Audio extraction in your browser
For the audio tool, the selected video is fetched through the InDownloader download proxy into your browser. The bundled Mediabunny software then extracts or converts the audio on your device. The resulting MP3 or M4A is represented by a temporary browser object URL and is not uploaded to a separate conversion service. Temporary in-page data is released when it is replaced or when you leave the page, subject to normal browser memory management.
Cookies, analytics, and advertising
The theme preference uses your browser's local storage rather than a cookie, and
that value is not sent to the downloader API. A published ads.txt
record is a text file naming authorised sellers; it does not itself load ads, set
cookies, or transmit browser data.
This site may serve third-party advertising. Where it does, the advertising provider can set cookies or read similar identifiers in your browser, and can receive your IP address, browser headers, the address of the page you are viewing, and the time of the request, in order to select, deliver, and measure ads. A provider may use that information to personalise advertising based on your earlier visits to this or other sites, and may combine it with data it already holds.
Where personalised advertising is offered you can normally limit it in the provider's own settings, and browser settings or an extension can block advertising scripts entirely. Blocking them does not affect the downloader.
Third-party services described below can also receive ordinary request information when they provide infrastructure, media, or an external page. This section names no advertising or analytics provider yet. Before either is enabled, it should be named here together with a link to its own policy, and — for visitors in a region where consent is required before advertising cookies are set — the consent mechanism in use.
Third-party services
- Hosting and network infrastructure. The API, metadata cache, proxy, optional rate limiting, and operational observability run on a third-party infrastructure and network platform. That platform processes traffic as an infrastructure provider on our behalf, under its own security and retention rules, and does not receive an InDownloader account because none exists. Contact us if you need the current provider identified for a data request.
- Instagram and Meta. The API requests Instagram pages, metadata, and media needed to answer a lookup. Some result thumbnails may be loaded directly from a Meta CDN, which lets that CDN receive your IP address, browser headers, and request time even though the image uses a no-referrer policy. Following an Instagram link also takes you to Meta's services. See the Instagram Privacy Policy .
- Email providers. If you email us, the providers used by you and by InDownloader process the message according to their own terms and privacy policies.
- Other external links. A third-party website you choose to open is responsible for its own privacy practices; this policy does not control it.
Our infrastructure provider and Meta both operate globally, so requests may be processed in countries other than the one where you live, subject to their infrastructure and policies.
Service-side Instagram session
The API supports an operator-managed Instagram session for features that Instagram does not serve anonymously, such as some Story or Highlight lookups and higher-quality profile data. This optional credential belongs to the service; it is not your account credential and is not exposed to your browser. We never ask you to submit an Instagram password, session cookie, or authentication code. Features that depend on this configuration may be unavailable.
Security measures and limits
Measures in the current design include HTTPS, strict Instagram and Meta host allow-lists, request validation, server-side handling of downloadable CDN addresses, no-store download responses, file-size limits, and optional abuse controls. No internet service can guarantee perfect security, uninterrupted availability, or that a third-party platform will not change its behavior.
Your choices and privacy rights
- You can use the informational pages without submitting an Instagram link.
- You can type or paste a link manually instead of granting clipboard access.
- You can clear the theme preference through your browser's site-data controls.
- You can avoid direct Meta preview requests by blocking third-party images or requests in your browser, although previews may not appear.
- You can contact us to ask about, correct, or request deletion of information you believe we control.
Depending on where you live, privacy law may provide additional rights, such as access, correction, deletion, restriction, objection, or complaint to a local regulator. Because InDownloader has no user accounts and does not maintain a permanent lookup history, we may have little or no stored information that can be reliably linked back to you. We may need enough detail to understand and verify a request, but please do not send account credentials.
Children's privacy
InDownloader is not directed to children under 13, and we do not knowingly ask them for personal information. If you believe a child has sent personal information through a support email, contact us so the issue can be reviewed.
Changes to this policy
We may revise this policy when the product, providers, or data handling changes. The updated date at the top identifies the latest published version. Material changes should be described clearly rather than hidden behind an unchanged date.
Contact
For privacy questions or requests, use the contact page or email hello@indownloader.dev. Please describe the request and any relevant page or link, but do not send an Instagram password, session cookie, authentication code, or other sensitive account credential.