No accounts, no credentials, nothing sold. What our server logs actually contain (including searched usernames tied to hashed identifiers), what stays in your browser, and how to reach us at hello@tracygram.com.
Tracygram is a small independent web project with no connection to Instagram or Meta.
Tracygram is a free web toolkit for viewing and downloading public Instagram content: profile, story, highlights, reels and tagged viewers, downloaders, a comments viewer, a fake-follower estimator, an engagement calculator, trending audio, and AI caption, bio, and hashtag generators. It has been running since around April 2026.
We are a small independent team. We are not affiliated with, endorsed by, or sponsored by Instagram or Meta Platforms, Inc. in any way. "Instagram" is a trademark of Meta Platforms, Inc., and we use the word only to describe what our tools work with.
One design decision shapes everything in this policy: there are no accounts here. You cannot sign up, log in, or set a password, and we will never ask for your Instagram credentials. A site cannot lose, sell, or leak account data it never collects.
Anything in this policy unclear? Email hello@tracygram.com or use the form on our contact page. We read everything.
No selling, no ads, no fingerprinting, no credentials, no private accounts. Ever.
Before the details, the commitments. Each of these is checkable:
Everything else on this page describes the small amount of data a free tool site genuinely needs to run.
A handful of server logs, standard analytics, and short-lived caches. Here is the full inventory in one table.
This table is the complete list. If a data stream is not here, we do not have it.
| What | Why we collect it | Where it lives | How long |
|---|---|---|---|
| Page-view log: timestamp, page path, traffic source, country and city (from a local GeoIP lookup), a truncated salted hash of your IP, mobile or desktop flag, search keywords passed along by referrers | So we can see which pages people use and where visitors come from | Our server | Identifiers deleted after 90 days at most; anonymous counts (date, page, country) kept for long-term trends |
| Tool-usage log: event type (story view, download, and so on), success or error, the public username that was searched, a hashed visitor identifier, the page | So we can see which tools work, catch failures, and understand demand | Our server | Searched usernames and identifiers deleted after 90 days at most; anonymous totals kept |
| JavaScript error log: error message, page, device type, browser family (no IP) | So we can fix bugs | Our server | Deleted after 90 days at most |
| Rate-limit counters keyed to your raw IP | Fairness and abuse control (per-IP daily budgets) | Server memory only, never written to our analytics logs | Short-lived; cleared on restart |
| Ordinary web-server logs kept by the hosting stack | Standard server operation on our virtual private server | Our server | Standard hosting-stack rotation |
| Google Analytics 4 events (anonymous event names and standard GA data; never a searched username) | So we can understand overall traffic | Google's infrastructure | Per Google's retention settings |
| Text you type into the AI caption, bio, and hashtag tools | Sent to Google's Gemini API to generate your result | Processed by Google; not stored by us beyond normal logs | Not kept beyond normal server logs |
| Cached copies of public Instagram data that was requested | So repeat requests are fast and we make fewer upstream calls | Our server (memory plus a disk snapshot) | About 12 hours, with a stale copy kept up to about 7 days |
| Recent searches, saved profiles, snapshots, preferences | Instant previews and change alerts, on your device only | Your own browser (localStorage and sessionStorage), never sent to our server | Until you wipe it or clear your browser |
One point worth repeating about IP addresses: your raw IP is not written to our analytics logs. We use it in memory for rate limiting and for a local country-and-city lookup, then store only a truncated, salted SHA-256 hash. The truncation means many different addresses share the same hash, so it cannot be turned back into yours.
Like any site with a search box, the username you search lands in our server logs, tied to a hashed identifier, and is deleted automatically after 90 days.
Many sites in this space claim they are "100% anonymous" and "store nothing." We would rather tell you exactly what happens. And to be clear about the company we keep: every website with a search function logs what is searched. Google does, analytics tools do, and so do we. There is nothing unusual here except that we say it plainly.
When you search a public username in one of our tools, that username is written to our tool-usage log, together with the event type, whether it succeeded, the page, and a hashed visitor identifier. The searched username is also forwarded to our upstream Instagram-data API providers, because that is how the public data gets fetched.
So when we say the viewers are anonymous, we mean something specific: the owner of the profile you look at is not notified, and your viewing is not linked to any Instagram account of yours. It does not mean your search vanishes. It sits in our logs, tied to a hash rather than to your name or raw IP, and it is deleted automatically after 90 days.
Because the identifier is hashed, we usually cannot work out which person made which search. That cuts both ways: it protects you, and it also limits what we can look up if you ask. More on that in Your choices and rights.
Logs rotate when they grow past a size cap, and one previous generation is kept. If you want log entries matching your searches deleted, email us.
Recent searches, saved profiles, and preferences live in your own browser, never on our server, and you can wipe them anytime from the homepage panel.
A lot of what makes Tracygram feel fast is stored in your own browser (localStorage and sessionStorage) and is never sent to our server:
You do not have to take our word for it. The homepage has a panel called "What does this device store?" that lists every category with its live size and a Wipe button for each. Open it, look, wipe whatever you like. We think every site should have one.
One caveat worth knowing: wiping affects only your device. It does not touch our server logs, because the two are separate systems. For server-side deletion requests, see Your choices and rights.
GA4 runs on the site and sets Google's own cookies, but we deliberately never send it any username or Instagram handle.
We use Google Analytics 4 to understand overall traffic: how many people visit, which pages they land on, roughly where they are. GA4 runs in your browser and Google sets its own cookies and identifiers, governed by Google's privacy policy.
Here is the design choice we are proud of: we never send searched usernames, or any Instagram handle at all, to Google Analytics. When you use a tool, GA4 receives only an anonymous event name (for example, "xray_open") plus standard GA data. What you searched stays out of Google's analytics entirely.
If you would rather not be measured by GA4 anywhere, Google publishes a browser opt-out add-on, and most content blockers handle it too. The site works fine either way.
What you type into the caption, bio, and hashtag generators is sent to Google's Gemini API to produce the result.
Our AI caption, bio, and hashtag generators do not run on our own hardware. The topic or text you type is sent to Google's Gemini API, which generates the output and sends it back. Google processes that input under its own API terms.
We do not store what you type beyond our normal server logs, and we do not build any profile from it. Practical advice: treat the input box like any third-party service and do not paste anything private or sensitive into it.
The output is machine-generated. Read it and edit it before you post it anywhere; what you publish is your responsibility.
Public profile data we fetch is cached on our server for about 12 hours so repeat requests are fast. This is public data, not data about you.
When someone requests a public profile, story, or post, we cache what came back, in memory plus a disk snapshot, for up to about 12 hours. A stale copy can be retained for up to about 7 days to keep things working when the upstream source is slow. This is data that is already public on Instagram, not data about our visitors.
Two practical consequences worth knowing:
The complete list, each with one job. Nobody else.
We do not hand data to "trusted partners" in the vague sense. Here is the complete list of outside services involved, and exactly why:
That is everyone. If this list ever changes, this page changes with it.
After 90 days, log entries lose everything identifying. Anonymous daily totals stay so we can see long-term trends.
The real retention numbers, including the awkward one:
We only show what is already public, and you can have your profile excluded from our tools by emailing us.
This policy is mostly about our visitors, but there is a second group with rights here: people whose public profiles get searched.
What we process about you is the public Instagram data anyone can see while logged out: your public profile, posts, stories, and counts. We add no access beyond that, we cannot see private accounts, and profile owners are not notified of views. Fetched data sits in our cache for up to about 12 hours (stale up to about 7 days).
If you would rather not appear in these tools at all, email hello@tracygram.com from a channel that lets us verify you control the account. We will purge your data from the cache and exclude your profile from the tools going forward. Details are on our copyright and removal page.
Email us to ask about or delete data. One caveat: our hashed logs often cannot be linked to a specific person, which protects you but limits lookups.
Wherever you live, you can email hello@tracygram.com to ask what we hold, request deletion of log entries, object to processing, or just ask how something works. We extend the same treatment to everyone; we do not gate rights by region.
Now the caveat. Our logs are keyed to truncated hashes, not names or raw IPs, so we usually cannot tell which log lines belong to which person. That is a privacy feature, and it is also a limitation: we often cannot answer "show me everything you have on me" with certainty. If you give us enough detail (the approximate time, the username you searched, your country), we will run a good-faith search and delete matching entries. What we will not do is start collecting extra data about visitors just to make future lookups possible.
If you are in a region with data-protection laws such as the EU or UK GDPR, California's CCPA, or India's DPDP Act, here is how the usual concepts map to us:
We do not claim any certification, and we will not pretend to be "GDPR certified" (no such certificate exists). We describe what we do, and we answer our email.
Our server processes requests where it is hosted, Google processes its parts on global infrastructure, and everyone gets the same treatment.
Tracygram runs on a virtual private server. Visitors come from everywhere, so depending on where you live, our server logs may be stored outside your region.
Google (Analytics and the Gemini API) processes its parts of the data on its own global infrastructure, under Google's own data-processing terms. Given what our log entries contain (hashed identifiers, no names, no raw IPs), we think the practical exposure of cross-border storage is small, but you deserve to know how the data is handled, and we answer questions about it by email.
Tracygram is a general-audience service, not directed at children under 13, and we collect no age data.
Tracygram is a general-audience service. It is not directed at children under 13, and since there are no accounts, we collect no age data and no profile of any visitor, child or adult. If you believe a child has submitted personal information through our contact form, email hello@tracygram.com and we will delete it.
When this page changes, the date at the top changes, and meaningful changes get a one-line note.
When we change how the site handles data, we update this page first, refresh the effective date at the top, and add a one-line note saying what changed. Since there are no accounts, we cannot email you about updates; this page is the record. If you rely on this policy, check the date now and then.
This July 2026 version is a full rewrite, effective July 16, 2026, and it replaces all earlier versions. We wrote it to describe exactly how the system works today, in plain language and full detail, and we intend to keep it that way.
One inbox for everything: hello@tracygram.com.
Questions about this policy, requests about your data, removal of your profile from the tools, or anything else: email hello@tracygram.com or use the form on our contact page. We are a small team, so replies can take a few days, but a real person reads and answers every message.