Privacy and safety
Will this app steal my password? Why we never ask for your Instagram login
A public Instagram lookup needs a username, not a password, so this site has no login form at all. Here is the mechanism, exactly what our server does log (IP address, pages, usernames searched) and for how long, and how to check every claim yourself in about a minute.
This page is not yet available in your language, so we are showing the English version.
Original artifact: A row-by-row inventory of every data type this site handles - the password we never collect, IP address, pages viewed, username searched, watchlist, recent searches and cached public media - with where each one lives, how long it is kept and who can see it, compiled line by line from our published privacy policy and methodology page on 2026-09-27. (dataset, 27 set 2026)
How this was made: Drafted with AI assistance by reading this site's own privacy policy and methodology page and reproducing what they say; every row of the data table was checked against those two pages on 2026-09-27, and nothing here goes beyond them.
On this page
Quick answer
We never ask for your Instagram password because a lookup of public content does not need one: our servers fetch public data keyed on a username, so there is nothing for a password to unlock. That is also why there is no Instagram login on this site. What we do collect is your IP address, the pages you open and the usernames you search, kept for 90 days. Both halves matter, and the rest of this page is how to check them without believing us.
The only field on the page is a username
No password, no sign-in, no download. Type a public username and see what the tool actually asks for.
Why does this site not ask me to log in?
Because of where the request is made from. You send a public username to our servers; they ask commercial data providers, and for some public data Instagram's own public endpoints, for that account's public profile, stories, highlights and posts, then send the result back. Your browser talks only to us, so Instagram sees a request from our infrastructure rather than your device - which is also why no viewer lands in the story's viewer list. It is written up on our methodology page.
Read that from the credentials angle: the only key the fetch needs is a public username. A password identifies you, and nothing in that chain involves you as an Instagram user, so a password field would have no function. It is the same reason no credential would make a private account visible: private means Instagram serves it only to approved followers.
Will the app steal my password? What a login form actually buys a site
We cannot audit anyone else's servers and will not call a named site a thief, but the pattern is worth understanding. A site that gets you to type your Instagram username and password into its own page gains, in one step:
- The ability to act as you. That session can post, delete, follow, read and send direct messages, and change the email and phone used to recover the account. If the page also asks for the six-digit code from your authenticator or SMS, two-factor authentication stops being a barrier.
- A credential to try elsewhere. People reuse passwords, so the pair that opens Instagram is worth testing against email, storage and banking - the standard payoff of credential phishing as the US Federal Trade Commission describes it: one form, many downstream attempts.
- A borrowed account to fetch with. Public-content services get throttled upstream, and a pool of real logged-in accounts is operationally useful. The account carrying the risk of restriction is yours: Instagram's Terms of Use (Opens in a new window) put what happens with your login on your account.
What do you collect, then?
This is the part that "we respect your privacy" pages leave out. Instagram does not see you here. We do.
Every row below comes from our privacy policy and methodology page, and the same list is published at /llms.txt, so the three can be compared. Where this article and the policy could disagree, the policy is the authority.
| Data | Where it lives | How long | Who can see it |
|---|---|---|---|
| Your Instagram password | Nowhere. There is no Instagram login on the site and no field that would accept one | Not applicable | Nobody, us included |
| Your IP address | Our server, with each lookup record and with analytics | Full for 30 days, then shortened to /24 (IPv4) or /48 (IPv6); the record is deleted at 90 days, leaving daily aggregates | The operator; authorities where the law compels disclosure |
| The username you searched | Our server, in a lookup record used for rate limits and upstream cost caps; kept even if you decline analytics cookies | 90 days | The operator; not the account owner, not advertisers |
| Pages you open, clicks, time on page, scroll depth | Our server, first-party analytics with a random visitor cookie; in the EEA, UK and Switzerland only after you accept | 90 days raw, then aggregates only | The operator |
| Your watchlist | Your browser only (IndexedDB peekghost-watchlist, localStorage fallback) | Until you clear site data | Only you; it is not uploaded |
| Your recent searches | Your browser only (localStorage: the username and a small thumbnail) | Until you clear site data | Only you |
| Cached public content | Our server: resized public images in a size-capped, least-recently-used disk cache (128 MB on this site as of the date above); text metadata minutes to hours; videos and original-size files streamed, not stored | Metadata deleted a week after its cache window; images vary with traffic | Anyone looking up that same public account |
Two footnotes rather than fine print. The lookup record is not optional: declining analytics cookies switches off the analytics half, not the security and cost-control half, and the policy says so and says how to object. And if paid plans are ever offered and you switch on watchlist sync, we would hold an encrypted copy of your list we cannot read - the only case where anything in the browser-only column leaves your device.
We do not sell this data and we do not tell account owners who looked them up. We do disclose it where the law requires, which is a limit on us, not a promise.
How can I verify this myself?
For everything that happens in your browser, you need not take our word.
- Look for the password field. Open the story viewer: one input, a username. View the page source (Ctrl+U, or Cmd+Option+U) and search for
type="password". No match. Two places on this domain do use a masked field and neither involves Instagram: the operator's own admin login, and - if paid plans are ever offered - the box for a license key. - Watch the network. Press F12, open the Network tab, run a lookup. Every request goes to this domain - page, API call, media proxy - and none carries credentials, because none were collected. If you accepted optional analytics or ads, those vendors appear too; the enabled list is at the bottom of /privacy.
- Check where your watchlist lives. In the same dev tools, open Application (or Storage): IndexedDB holds
peekghost-watchlist, Local Storage your recent searches. Clear site data and both are gone - nothing was mirrored server-side to come back. - Compare our three descriptions. /privacy, /methodology and /llms.txt describe the same logging. If they disagree with each other or with the table above, that is a bug, and we would rather hear it than have it found.
- Test the exit. Account owners can ask us to block lookups of their account on the removal page: block added, search records deleted, cached copies dropped, within 72 hours. A route out is checkable in a way a privacy paragraph is not.
What we cannot promise
- You are not anonymous towards us. Your IP address and searched usernames sit in our records for 90 days. Anonymous here means towards Instagram and the account owner.
- We cannot hide you from your own network. Your provider, employer or school can still see that you visited, and your browser history records what you opened.
- We cannot promise a record never leaves. Where the law compels disclosure, we comply.
- We cannot show private accounts or tell you who viewed anything. Both sit outside public data.
- You cannot see our servers. Beyond the browser side you have a published policy, three descriptions that have to stay consistent, a 72-hour removal route and a contactable operator. That is a basis for trust, not proof, and we would rather say so.
Frequently asked questions
Will the app steal my password?
It never receives one. There is no Instagram login anywhere on the site, and a public lookup is keyed on a username. Confirm it by searching the page source for type="password".
Do I need to log in to view a public story?
No. A public story, highlight, reel, post or profile picture can be fetched with a username alone. If a site demands an Instagram login before showing public content, that demand is not technical.
Is it safe to give these apps access to my Instagram account?
Granting access, by password or by authorising an app, hands over the ability to act as you: posting, messaging, reading direct messages, changing recovery details. Public-content viewing needs none of it, and we offer no authorise-with-Instagram button. Our 12-point safety checklist shows how to judge any site on this.
Do these apps collect data for hacking?
We can only answer for this one. What we hold is the table above: IP address, pages, searched usernames, 90 days, not sold, not shared with advertisers. A username plus an IP address is not a credential and cannot log into anything; a password is, which is the thing we never ask for. And no, we cannot see who viewed your story or open a private account.
Is it a scam?
Judge it on checkable things rather than our wording: one input field, no Instagram login, no forced survey or download before content, a policy that admits to logging, a stated retention period, an opt-out, a removal route. A site failing those is worth leaving, this one included.
How do I get my own account out of this tool?
Use the removal page: we aim to block lookups of that username, delete its search records and drop cached copies within 72 hours, and the block stays until you lift it. It changes nothing on Instagram itself - for that, set the account to private.
Bottom line
A password would give us nothing we need, which is why no field asks for one - and you can check that in seconds instead of trusting it. What we do take is duller than a credential, and we would rather print it plainly, IP address, pages, searched usernames, 90 days, than claim a privacy we do not provide. Not affiliated with Instagram or Meta.
Sources
- Peekghost privacy policy - What we collect (Opens in a new window) (accessed Sep 27, 2026)
- Peekghost privacy policy - How long we keep it (Opens in a new window) (accessed Sep 27, 2026)
- Peekghost methodology - What our servers log (Opens in a new window) (accessed Sep 27, 2026)
- Peekghost - Remove my profile (account-owner takedown route) (Opens in a new window) (accessed Sep 27, 2026)
- Instagram Help Center - Tips to keep your Instagram account secure (Opens in a new window) (accessed Sep 27, 2026)
- Instagram Terms of Use (Opens in a new window) (accessed Sep 27, 2026)
- US Federal Trade Commission - How to recognize and avoid phishing scams (Opens in a new window) (accessed Sep 27, 2026)
View a public account anonymously
Type a public username. No login, no account, nobody is notified.
Related guides
- Will a story viewer get your Instagram account banned?
Last tested 27 set 2026 · 9 min read
- Is an Instagram story viewer safe? A 12-point checklist
Last tested 24 set 2026 · 6 min read
- Instagram story privacy settings: who sees what
Last tested 24 set 2026 · 7 min read
- Does Instagram notify when you screenshot a story?
Last tested 24 set 2026 · 1 min read