Privacy policy

What personal data Peekghost processes, why, for how long, who receives it, and how to use your rights under the GDPR, UK GDPR, CCPA/CPRA, LGPD, India's DPDP Act and Israeli law.

By Peekghost teamPublished Updated

Policy version 2026-09-24. Last updated 2026-09-24. Changes are listed on the changelog.

Who is responsible (the controller)

The controller of the personal data described here is:

  • Name: [LEGAL_ENTITY_NAME not set]
  • Address: [LEGAL_ADDRESS not set]
  • Contact for all privacy requests: [SITE_CONTACT_EMAIL not set]
  • Data-protection contact: [DPO_EMAIL not set]
  • Representative in the EU (GDPR Art. 27): [LEGAL_EU_REPRESENTATIVE not set]
  • Representative in the UK (UK GDPR Art. 27): [LEGAL_UK_REPRESENTATIVE not set]

Peekghost is run by an independent operator based in Israel. It is not affiliated with Instagram or Meta Platforms, Inc.

What "anonymous" does and does not mean

  • Anonymous towards Instagram and the account owner. When you look up a public account, our servers and our data providers fetch the public content. Your browser talks only to us. Instagram therefore sees a request from a provider, not from your device or your Instagram account, and no logged-in viewer is recorded in a story's viewer list. This works only for public accounts.
  • Not anonymous towards us. We record your IP address and the usernames or links you search, together with time, outcome and cost, in our own analytics and security records (see "What we collect"). We use them to run the service, not to tell account owners who looked. We do not share searches with account owners or sell them, but we may have to disclose data when the law requires it.
  • Not anonymous towards your network or device. Your internet provider, employer, school or the device itself can still see that you visited this site, and your browser history records what you opened.

What we collect

  • The lookup you make. The username or link you submit, your IP address and standard request headers (user agent, language). To answer you, our servers ask a data provider for the account's public data. The provider receives the public username, not your IP address or cookies.
  • Security and cost-control records (always on). For every lookup we keep a record with the username searched, time, outcome, which provider answered, what the upstream request cost, and your IP address. We use these to rate-limit abuse, cap paid upstream requests per IP address and per day, and detect scraping. They are kept for the analytics retention period below. Unlike analytics they are not switched off by declining analytics cookies, but you may object (see "Your rights and how to use them").
  • First-party analytics. We run our own analytics on our own server; no third party receives it. It records: a random visitor identifier (cookie vid), IP address, approximate location (country, and region or city where available, derived from the IP address by an offline database on our server and from edge headers), the network you connect from, device, browser, operating system and language, referrer and campaign parameters, the pages you open, time on page, scroll depth, what you click or tap (including links that leave the site and downloads), and the usernames you search. Search bots are recognised and flagged. In the EEA, UK and Switzerland this runs only after you accept analytics; everywhere you can turn it off on the analytics choices page.
  • Server access logs. Our web server keeps standard request logs (IP address, time, path, status, user agent) for security and debugging for up to 14 days. Profile, story, lookup and embed URLs are not logged, and the Referer header is not kept, so a searched username is not written next to your IP address there. Application error logs may contain technical details and rotate by size.
  • Your cookie choices. When you make a choice in the cookie panel we store it in your browser and keep a record on our server: time, policy version, the vendor list, your choices and a coarse country. It contains no name, cookie value or IP address, so we cannot tell which visitor it belongs to; it exists to show that choices were honoured.
  • Telegram alerts (optional). If you connect alerts we store your Telegram chat identifier, your language, the usernames you follow and a delivery log, until you send /stop.
  • Requests you send us. Removal, copyright and privacy requests: username, reason, your message, an email address if you give one, and a salted hash of your IP address for rate limiting.
  • Browser storage. Your watchlist, recent searches, theme and player settings are stored in your browser only. See "Cookies and browser storage".
  • Optional third-party services. If the operator enables Google Analytics, Microsoft Clarity, Google AdSense or advertising pixels (Meta, TikTok, Pinterest, Reddit, X, Microsoft Advertising, LinkedIn, Snap), those companies receive data from your browser. The exact list that is enabled right now is at the bottom of this page. They load only after your consent where the law requires it.

We do not make automated decisions with legal effects about you. Bot detection and rate limits are automatic and can block requests that look like scraping.

Where the GDPR or UK GDPR applies, each purpose has one lawful basis. Where consent is the basis you can withdraw it at any time, as easily as you gave it, with "Privacy choices" in the footer.

PurposeDataLawful basisNotes
Delivering the lookup you asked forThe username or link you submit; your IP address and request headers to answer the requestContractNecessary to provide the free service you requested (Art. 6(1)(b)).
Security, abuse prevention and cost control (rate limits, per-IP upstream budgets, anomaly detection, server logs, and a record of each lookup with the username, IP address and outcome)IP address, user agent, time, path, the username looked up, upstream request costLegitimate interestsArt. 6(1)(f): protecting a free service against scraping and running up paid upstream calls. Runs even if you decline analytics; you can object (see Your rights).
First-party analytics (visits, pages, clicks, scroll depth, approximate location, device, referrer, usernames searched)Random visitor ID cookie, IP address, approximate location, device and browser, pages, clicks, searchesConsentIn the EEA, UK and Switzerland only after you accept analytics (Art. 6(1)(a) and the ePrivacy rules). Elsewhere: legitimate interests, with an opt-out.
Third-party analytics (Google Analytics, Microsoft Clarity), only if enabledPage paths with usernames removed, approximate location, device, interactionsConsentLoaded only after you accept analytics where consent is required.
Advertising and ad measurement (AdSense, Meta, TikTok and other pixels), only if enabledCookie and device identifiers, page views and coarse events, IP addressConsentLoaded only after you accept advertising where consent is required. Google ads in the EEA, UK and Switzerland are not served at all unless a Google-certified consent platform is in place.
Recording your cookie choicesTime, policy version, vendor fingerprint, your choices, coarse country; no name, cookie value or IP addressLegal obligationTo demonstrate consent or refusal (Art. 7(1), Art. 6(1)(c) and (f)).
Telegram alerts you requestTelegram chat identifier, language, the usernames you follow, delivery logContractOnly after you link a chat; stop any time with /stop.
Removal, copyright and privacy requestsUsername, reason, message, contact address if given, salted hash of your IP addressLegal obligationArt. 6(1)(c) and (f): handling your request and keeping a block in place.
Showing public Instagram content that account owners made publicPublic profile data, stories, highlights and posts of the account you look upLegitimate interestsArt. 6(1)(f). The account owner can ask us to block lookups on the removal page.

Cookies and browser storage

We do not need cookies to show stories. The table lists everything this site itself stores in your browser. Third-party services that you allow set their own cookies; they are described in the vendor list at the bottom of this page and in each vendor's own policy.

NameTypeCategoryWhat it is forHow long
cmCookieStrictly necessaryRemembers your cookie choices, the policy version and the vendor list you saw. Mirrored in localStorage under the same name.365 days
cmlocalStorageStrictly necessaryCopy of the choices cookie, used if cookies are blocked.Until you clear site data
analyticsCookieStrictly necessarySet to "off" when you turn analytics off on the analytics choices page.365 days
vidCookieAnalyticsRandom visitor identifier for our own analytics (HttpOnly). In the EEA, UK and Switzerland it is only set after you accept analytics. Not set for search bots.365 days
themeCookiePreferenceYour light or dark theme, so the page renders in the right theme on first paint. Mirrored in localStorage.365 days
themelocalStoragePreferenceYour theme choice.Until you clear site data
NEXT_LOCALECookiePreferenceRemembers the language you chose when it differs from your browser language (set by the language routing library).Browser session
alCookieStrictly necessarySigned pointer to your Telegram alert subscription. Only set if you connect alerts, at your request.365 days
sv.recent-searcheslocalStoragePreferenceYour recent searches (usernames and a 72 px avatar thumbnail), kept on your device only.Until you clear it or site data
ig:watchlist:v1:*localStoragePreferenceYour watchlist, kept on your device only (fallback when IndexedDB is unavailable), plus a badge counter and last-refresh time.Until you clear it or site data
peekghost-watchlistIndexedDBPreferenceYour watchlist and archive, kept on your device only. Never uploaded.Until you clear it or site data
sv.a11ylocalStoragePreferenceYour accessibility options (text size, contrast, grayscale, link highlighting, readable font, text spacing, paused animation, large cursor), kept on your device only.Until you reset it or clear site data
player:mutedlocalStoragePreferenceWhether the story player is muted.Until you clear site data
sv.stories-viewlocalStoragePreferenceGrid or list view of stories.Until you clear site data
ig.pubcfg.v1sessionStorageStrictly necessaryCaches which third-party services are enabled, for 10 minutes, so the consent layer can decide what may load.Browser session
ig:pwa:viewssessionStoragePreferenceCounts pages viewed in this session to time the "install app" suggestion.Browser session
ig-static-v2, ig-pages-v2Cache StoragePreferenceService-worker copies of the app shell, static files and public pages for offline use. Profile pages, the API, embeds and anything carrying signed media links are never cached.Until the next site version or you clear site data

You can change or withdraw your choices at any time with "Privacy choices" in the footer, or by clearing this site's data in your browser. If your browser sends a Global Privacy Control signal we treat it as an opt-out of advertising.

Who receives your data

WhoRoleWhat they receiveWhere
Hosting provider and network (server, backups)ProcessorEverything stored on the server, including the analytics database and access logsSee the international transfers section
Data providers that supply public Instagram data (for example RocketAPI, HikerAPI, RapidAPI)Processors / independent providersThe public username or user id we look up. Your IP address and cookies are not sent to them.Vendors are not location-controlled by us; treated as transfers
Instagram / Meta PlatformsIndependent controllerRequests made by our providers for public content. Instagram sees our providers, not you. If you open an Instagram link yourself, Instagram's own policy applies.Various
Telegram MessengerIndependent controllerAlert messages you asked for, and your chat identifier when you talk to the botVarious
MaxMind GeoLite2 (offline database)Not a recipientA file on our server used to guess a country and city from an IP address. Nothing is sent to MaxMind at lookup time.On our server

We do not sell personal data. We do not let anyone use it for their own purposes, except the optional advertising and analytics vendors you may accept (see the vendor list). We may disclose data to authorities when the law requires it, or to protect the service, our users or others from abuse.

International transfers

The controller is in Israel and the servers are hosted by [LEGAL_HOSTING_PROVIDER not set]. Visitors come from all over the world, so personal data is processed outside your country.

  • Israel. The European Commission and the UK recognise Israel as providing an adequate level of protection, so personal data of EU and UK visitors can be handled by the operator in Israel without further safeguards.
  • Other countries. Providers in the United States and elsewhere receive data as described above. Where required we rely on the EU-US Data Privacy Framework (and its UK extension) for certified providers, or on the European Commission's standard contractual clauses and the UK International Data Transfer Addendum. You can ask us for a copy of the safeguards.
  • Brazil and India. Transfers are made to providers and countries that give a level of protection compatible with the LGPD (Art. 33) and, for India, to countries not restricted by the government under the DPDP Act.

How long we keep it

DataHow longBasis / setting
First-party analytics: visits, sessions, pages, clicks, searches (with IP address, visitor identifier, searched username), upstream-request records90 days, then deleted; only aggregate daily totals remainConfigured retention (ANALYTICS_RETENTION_DAYS); runs every 6 hours
IP addresses inside those analytics recordsFull address for 30 days, then shortened to /24 (IPv4) or /48 (IPv6)ANALYTICS_IP_RETENTION_DAYS
Server access logs (reverse proxy)Up to 14 days (rolling files); lookup and profile URLs are not loggedCaddy log roll settings
Application container logs (errors and warnings)Size-capped rotation (about 50 MB total), not time-based; normally daysDocker log rotation
Consent records (time, version, your choices; no name, no IP address)3 years, then deletedTo demonstrate that consent was given or refused
Analytics opt-out cookie, consent cookie, visitor cookieUp to 1 year in your browserSee the cookie table
Telegram alert subscription (chat identifier, followed usernames, delivery log)Until you send /stop or delete it; then removedOnly if you connect alerts
Backups of the main database (cache, Telegram subscriptions, admin audit log); the analytics database is not part of themThe last 48 hourly snapshots are kept (about two days), then overwrittenBACKUP_KEEP; deletions reach backups when they roll off
Removal and copyright requests (username, reason, contact address if given, salted IP hash)Kept while the block or dispute is in force, then reviewed at least yearlyNeeded to keep a block in place and to answer disputes
Cached public Instagram profile and story metadata (names, bios, counts, media links)Fresh for minutes to hours (profiles 6 hours, stories 10 minutes, posts 30 minutes, not-found and private answers 15-60 minutes); expired rows are deleted 7 days after their stale window endsEngine cache; cleaned every 6 hours
Resized copies of public images (profile pictures, story and post images)Kept in a size-capped disk cache (200 MB by default); the least recently used files are deleted first, so the time varies with trafficPerformance cache; see the methodology page
Videos and original-size filesStreamed through us and not storedSee the methodology page

Your rights and how to use them

Depending on where you live you may have the right to: know what we hold about you and get a copy; correct it; delete it; restrict or object to processing (including our legitimate-interest analytics and security records); receive your data in a portable format; withdraw consent; not be discriminated against for using your rights; and complain to a regulator.

How to ask. Write to [DPO_EMAIL not set] (or use the removal page for account-related requests). You can also help yourself right now:

  • This browser: open the analytics choices page to turn analytics off or to delete the analytics data linked to this browser. Use "Privacy choices" in the footer to change cookie choices.
  • Your Instagram account: if searches of your public account concern you, ask on the removal page or by email; we can delete the search records for that username and block further lookups.

What we need from you. Our analytics does not know your name, so we find your data through identifiers that you hold: the value of the vid cookie (visible in your browser's developer tools), your IP address, or the username of the account you own. We may ask you to show that you control the identifier. For a username we may ask you to post a short code in the account's bio. For an IP address we do not release data to anyone who cannot show that they controlled that address; we can still delete on request.

How fast. We confirm your request and answer within one month (30 days) of receiving it. If we need more time or more information we tell you within that period, and we may extend once where the law allows. For requests under Brazilian law we send a simplified answer immediately where possible and a full answer within 15 days. There is no fee unless a request is clearly unfounded or excessive.

Complaints. You may complain to your data-protection authority: in the EU/EEA the authority of your country of residence, work or the alleged breach; in the UK the Information Commissioner's Office; in Switzerland the FDPIC; in Brazil the ANPD; in Israel the Privacy Protection Authority; in California the Attorney General or the California Privacy Protection Agency. We would appreciate the chance to fix things first.

California residents (CCPA/CPRA) and other US states

  • Categories collected in the last 12 months: identifiers (IP address, cookie identifiers); internet activity (pages, clicks, searches); approximate geolocation; device and browser data. We do not collect sensitive personal information to infer characteristics about you.
  • Sources and purposes: from you and your browser, for the purposes in the table above. Recipients are the service providers above and, if enabled, the advertising and analytics vendors listed below.
  • We do not sell personal information. If advertising services are enabled, those vendors may receive identifiers and browsing data for advertising and measurement, which US state laws call "sharing" or "sale" of personal information. When that is the case the footer shows a Do Not Sell or Share My Personal Information link that opens the same panel; Reject all is the one-click opt-out. We also treat a Global Privacy Control signal from your browser as that opt-out. Whether advertising services are enabled right now is shown in the vendor list at the bottom of this page.
  • Your rights: know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information (not applicable), and non-discrimination. An authorised agent may submit a request with your written permission. We answer within 45 days.
  • We have no actual knowledge that we sell or share the personal information of anyone under 16.

Brazil (LGPD)

Our legal bases are those in the table above, expressed in LGPD terms: performance of the service you asked for, legitimate interest (security, cost control, public content) with the safeguards described here, consent for optional analytics and advertising, and compliance with legal obligations. You have the rights of Art. 18 (confirmation, access, correction, anonymisation or deletion, portability, information about sharing, withdrawal of consent and review of decisions). The data-protection contact (encarregado) is [DPO_EMAIL not set].

India (DPDP Act, 2023)

For visitors in India we process personal data on the basis of your consent (optional analytics and advertising) and for the "legitimate uses" the Act allows (providing the service you request, security and legal compliance). You have the right to information, correction and erasure, grievance redressal, and to nominate another person to exercise your rights. Grievance contact: [DPDP_GRIEVANCE_EMAIL not set]. We do not track or target advertising at children (in India, anyone under 18) and we do not knowingly process their data.

Israel

We process personal data in line with the Protection of Privacy Law, 5741-1981. You may ask to see and to correct data we hold about you, and you may complain to the Privacy Protection Authority.

People whose public accounts are looked up

The tool displays public content that account owners chose to make public on Instagram, obtained from commercial data providers and, for some public data, Instagram's public endpoints. This includes public profile details (name, username, biography, counts, profile picture), stories, highlights and posts. We cache this metadata for a limited time so repeat lookups are fast (see the retention table) and keep resized copies of public images in a size-capped cache. We do not build profiles of the people looked up and we do not display private accounts. If you own or represent an account (or are a parent of a minor who owns it) you can ask for lookups of that account to be blocked on the removal page, and you can exercise the rights above against data we hold about your account, including searches for your username.

Children

The service is intended for people aged 16 and over (13 and over in countries where that is the lowest age at which a child can consent to online services). It is not directed at children, and we do not knowingly collect personal data from children under 13, or under the local age of digital consent for consent-based processing. If you are younger, do not accept optional cookies and ask a parent or guardian to help you. If you believe a child has given us data, or that a minor's account is being looked up, contact us or use the removal page and we will act promptly.

Security

Analytics and logs are stored on our own server. Access to the admin area requires a strong password and can be limited by IP address, admin actions are logged, and deletion requests are logged by a hash of the subject, never the subject itself. No system is perfectly secure; if a breach affects you we will notify you and the authorities as the law requires.

Changes to this policy

When we change this policy in a material way we change the version number above, add an entry to the changelog, and ask you to confirm your cookie choices again where consent is required.

This is a template for informational purposes. Consult with a qualified attorney for legal advice specific to your situation.

Third-party tags on this site

This site does not currently load any third-party analytics, session-recording or advertising tags.