Our documents

Legal center

Privacy Policy

On this page

Last updated: September 19, 2026 — version 1.0

This policy describes how INSYDER IO LLC ("Insyder", "we"), 5830 E 2nd St, Ste 7000 #37750, Casper, WY 82609, USA, processes personal data in connection with the Insyder service (insyder.io, app.insyder.io, the desktop application, API and integrations — the "Service").

Contact for questions or to exercise your rights: support@insyder.io (subject: "Personal data").

1. Two categories of data subjects

  1. Customers and their teams — people who create an account, use the Service, or are invited into a workspace.
  2. Customers' audiences ("Audience Data") — holders of third-party Instagram accounts who interact with a Customer's analyzed Instagram account (followers, likers, commenters, story viewers). This data is processed on behalf of the relevant Customer, who decides to connect their account and analyze their audience: for such processing the Customer acts as data controller and Insyder primarily as processor (see Section 8 and the Data Processing Annex).

2. Data we process

2.1 Customer data

  • Account & onboarding: email, designated Instagram handle, onboarding questionnaire answers (business type, team size, goals, tools).
  • Billing: handled by our payment provider Whop (identity, payment method, transaction history, VAT ID where applicable). Insyder does not access full card numbers.
  • Instagram connection: when you connect your account in the app, Instagram session tokens/cookies are used and stored securely to provide certain features. We never store your Instagram password.
  • Usage & support: technical logs, IP addresses, app usage data, support conversations.
  • Integrations: data from tools you connect (e.g., iClosed: bookings, call outcomes, amounts; Zapier; Meta APIs where you consent).

2.2 Audience Data (third parties)

On the Customer's behalf, the Service collects and stores over time, from publicly accessible sources and accesses authorized by the Customer:

  • handle (@), profile picture, follower count, public/private status, verification badge;
  • time-stamped interactions with the Customer's account: follows, likes, comments (including text), story views and reactions, clicks and replies where available;
  • computed indicators: engagement and reply-probability scores, segments, estimated value;
  • where the Customer connects business tools, matching with the Customer's commercial data (bookings, purchases).

We do not knowingly collect special categories of data or data about minors; the Service is not directed at persons under 18.

ProcessingPurposeLegal basis (GDPR, where applicable)
Account, subscription, supportProvide the ServiceContract (art. 6.1.b)
Audience DataAnalysis of the Customer's audience, scoring, historyProcessing on the Customer's behalf (art. 28); for the Customer: legitimate interest in analyzing their own commercial audience
Service emails and follow-ups on an initiated signupOrder follow-up, securityLegitimate interest (art. 6.1.f)
Commercial prospecting by emailInformation about Insyder offersLegitimate interest (business prospects) or consent, with an opt-out at any time
Service improvement, statisticsReliability and product improvementLegitimate interest; aggregated/anonymized wherever possible
Billing, accounting, anti-fraudLegal obligations and protection of the ServiceLegal obligation (art. 6.1.c) and legitimate interest

4. Recipients and subprocessors

Data is accessible only to authorized Insyder staff and to our providers, strictly as needed: Amazon Web Services (application and database hosting; support mailbox via AWS WorkMail), Whop Inc. (payments, subscriptions, tax collection, affiliate program), Instagram data providers (collection of public data — third-party API providers — internal APIs), proxy providers (technical routing of authorized requests), Framer (marketing website), Zapier, iClosed, Meta and other integrations only if the Customer connects them, plus emailing/analytics/support providers as the case may be.

Insyder does not sell personal data.

Customer exports: Customers may export their Audience Data (CSV/Excel/API) and use it in advertising tools (e.g., Meta Ads custom audiences). Such uses are the Customer's responsibility as data controller.

5. International transfers

Insyder is established in the United States and some providers are located outside the EEA. Where data of EEA individuals is transferred outside the EEA, we rely on recognized mechanisms (EU Standard Contractual Clauses, adequacy decisions, or equivalent safeguards from providers).

6. Retention

  • Customer account data: for the duration of the contract, then limited archiving for legal evidentiary and accounting purposes.
  • Audience Data: for the duration of the relevant Customer's subscription (long-term history is a core feature). Upon account closure, deleted or anonymized within 90 days of the effective termination date, absent a legal obligation to retain.
  • Instagram session tokens/cookies: deleted upon account disconnection or closure.
  • Technical logs: up to 12 months.

7. Your rights

Subject to applicable law (including GDPR where applicable), you have rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent.

  • Customers: write to support@insyder.io from your account email.
  • Individuals appearing in Audience Data (third-party Instagram account holders): contact support@insyder.io with your Instagram handle; we will forward the request to the relevant Customer(s) acting as controller(s) and apply erasure or objection in our systems where that duty falls on us.

You may also lodge a complaint with your supervisory authority (in France: CNIL, cnil.fr).

8. Roles (summary)

  • For Customer data: Insyder is the controller.
  • For Audience Data: the Customer is the controller (they choose to analyze their audience and use exports); Insyder acts as processor to provide the Service, and as controller only for processing strictly necessary for security, billing, and Service improvement (aggregated statistics).
  • The annex below sets out Insyder's processor commitments (GDPR art. 28).

9. Security

We implement appropriate technical and organizational measures: encryption in transit, environment segregation, role-based access, logging, secure storage of session tokens, and least-privilege access for providers. No system is infallible; we will notify you within legal deadlines of any data breach likely to result in a high risk to your rights.

10. Changes

Material changes to this policy will be notified by email or in-app. The last-updated date appears at the top.


Annex — Data Processing Commitments (GDPR art. 28)

Where Insyder processes Audience Data on the Customer's behalf:

  1. Instructions. Insyder processes Audience Data only to provide the Service per the Terms and the Customer's documented instructions (settings, connections, exports).
  2. Confidentiality. Persons authorized to process the data are bound by confidentiality obligations.
  3. Security. Section 9 measures apply.
  4. Sub-processors. The Customer generally authorizes the sub-processors listed in Section 4. Insyder will give notice of significant changes; the Customer may raise reasonable objections.
  5. Assistance. Insyder reasonably assists the Customer with data-subject requests and with security and notification obligations.
  6. End of contract. Insyder deletes or returns Audience Data as per Section 6.
  7. Audit. Insyder makes available the information reasonably necessary to demonstrate compliance, at most once a year and under NDA.
  8. Transfers. Section 5 applies.