InstaStudio collects zero personal data. No accounts, no analytics, no remote servers. All downloads happen directly between your browser and Instagram's CDN servers. Your settings (Ghost Privacy toggles) are stored only in your local
chrome.storage.local and never uploaded anywhere.
1WHAT INFORMATION WE COLLECT ↑ Top
InstaStudio collects no personal information whatsoever. We do not ask you to create an account, provide an email address, or sign in with any service.
The extension interacts with Instagram's web interface in your browser. During normal operation, the following data is temporarily handled locally within your browser session only:
- Instagram Session Cookies (Read-Only): The extension reads your existing Instagram CSRF token and session cookies already present in your browser. These are used exclusively to authenticate download requests to Instagram's own CDN servers on your behalf. We never transmit, store, or log these values to any external server.
- Media URLs (Transient): When you click a download button, the extension intercepts or fetches the direct CDN URL for the media (video, audio, image). This URL is used only for the immediate download and is never stored or recorded.
- Ghost Privacy Settings (Local Only): If you enable Ghost Story View or Ghost DM, your preference is saved to
chrome.storage.localon your device only. This data never leaves your browser.
2HOW WE USE YOUR INFORMATION ↑ Top
Because we collect no personal information, there is nothing to "use." The extension's logic runs entirely inside your browser. Here is what the extension does on your behalf:
- Download Media: Fetches Instagram CDN URLs (video .mp4, audio .mp3, photos .jpg) directly from Instagram's servers to your device's Downloads folder via Chrome's native
downloadsAPI. - Extract Audio: Decodes the video stream locally in your browser using the Web Audio API and encodes it to MP3 using the bundled
lamejslibrary. No audio data is sent to any server. - Ghost Privacy: Intercepts network requests to Instagram's "seen" endpoints using Chrome's
declarativeNetRequestAPI to prevent read receipts from being sent, without collecting or logging any of that data. - Comment Export: Scrapes comments visible in your browser's DOM and converts them to a local CSV file saved directly to your Downloads folder. No comment data is transmitted to any server.
- Bulk Download / ZIP: Bundles multiple media files using the bundled
JSZiplibrary, entirely in-browser. The resulting ZIP is saved directly to your Downloads folder.
3DATA STORAGE AND RETENTION ↑ Top
InstaStudio stores only one type of data, and only locally on your device:
| Data Item | Storage Location | Purpose |
|---|---|---|
| instastudio_privacy | chrome.storage.local | Remembers your Ghost Story and Ghost DM toggle states across browser sessions. Cleared when you uninstall the extension. |
| Downloaded Files | Your device's Downloads folder | Videos, photos, audio, CSVs, and ZIPs you explicitly download. These are your files, we have no access to them. |
All storage is entirely on your local device. Uninstalling the extension permanently removes all stored data.
4THIRD-PARTY SERVICES ↑ Top
InstaStudio does not use any third-party analytics, advertising, crash reporting, or telemetry services such as Google Analytics, Firebase, Sentry, or Mixpanel.
The extension communicates only with:
- Instagram / Facebook CDN Servers (
*.instagram.com,*.cdninstagram.com,*.fbcdn.net): To fetch and download media you explicitly request. This is no different from your browser normally loading Instagram media. - Google Fonts (on the Guide and Landing pages bundled inside the extension): For typography only. No user data is sent.
No user data is shared with, sold to, or transmitted to any third party under any circumstances.
5CHROME PERMISSIONS EXPLAINED ↑ Top
In accordance with Google Chrome Web Store Least Privilege guidelines, each permission in manifest.json is strictly limited to a specific user-facing feature:
| Permission | Justification and Specific Use |
|---|---|
| downloads | Saves videos (.mp4), photos (.jpg), audio (.mp3), ZIPs, and CSV comment exports directly to your device's Downloads folder when you click a download button. |
| storage | Persists only your Ghost Privacy toggle preferences (Ghost Story, Ghost DM) locally in chrome.storage.local. No personal data is stored. |
| cookies | Reads your existing Instagram CSRF token cookie (csrftoken) already present in your browser, required to authenticate media info API requests to Instagram's own servers. The cookie is never modified or transmitted to any third party. |
| webRequest | Intercepts Instagram CDN media stream URLs (video/audio .mp4 requests) to auto-detect the highest-quality stream for download. No request content is stored or logged. |
| declarativeNetRequest | Blocks specific Instagram "seen receipt" API calls (/stories/reel/seen, /direct_v2/threads/*/seen) when Ghost Privacy is enabled by you. No network traffic is recorded or logged. |
| host_permissions | Required to inject download buttons into Instagram pages, read Instagram CDN media URLs, and make authenticated API calls to Instagram on your behalf for media resolution. Scoped only to instagram.com, cdninstagram.com, and fbcdn.net. |
6GHOST PRIVACY FEATURE ↑ Top
The Ghost Privacy feature allows you to view Instagram Stories and read Direct Messages anonymously, without sending read receipts to the content creator or sender.
- Ghost Story View: Uses Chrome's
declarativeNetRequestto block outgoing network requests toinstagram.com/stories/reel/seenand related endpoints. Instagram's "you've seen this story" signal is never sent. No story content is stored by the extension. - Ghost DM: Blocks outgoing requests to
instagram.com/api/v1/direct_v2/threads/*/seenso messages appear unread to the sender. The messages you read are not stored by the extension. - Your toggle preference (on/off) is saved only in
chrome.storage.localon your device.
7DOWNLOADED CONTENT AND COPYRIGHT ↑ Top
InstaStudio is a technical tool that allows you to save publicly accessible Instagram media to your device. We do not endorse, encourage, or facilitate copyright infringement.
- All downloaded content belongs to its original creators and is subject to their copyright.
- You are responsible for ensuring your use of downloaded content complies with Instagram's Terms of Service and applicable copyright law.
- Downloaded content should only be used for personal, non-commercial purposes unless you have explicit permission from the original creator.
- InstaStudio does not store, host, or transmit any downloaded content. All files go directly to your device's Downloads folder.
8CHILDREN'S PRIVACY ↑ Top
InstaStudio is not directed at or intended for children under the age of 13 (or 16 in the European Economic Area). Since Instagram itself requires users to be at least 13 years old, this extension is designed for adults and older teenagers using Instagram.
We do not knowingly collect any information from children. If you believe a child has used this extension and you have concerns, please contact us at the email below.
9SECURITY ↑ Top
Our security posture is strong because we collect nothing. There is no database of user data to breach. Specific technical safeguards include:
- Zero Remote Servers: The extension has no backend. Downloads go directly from Instagram's CDN to your device. InstaStudio is never in the middle of the data flow.
- Zero eval() Execution: We do not use
eval(),new Function(), or any obfuscated dynamic code. The full source code is readable in the extension bundle. - Bundled Libraries Only: Audio encoding (lamejs) and ZIP generation (JSZip) are fully bundled inside the extension package. No external CDN script loading at runtime.
- Manifest V3 Compliance: Built on Chrome's modern Manifest V3 standard with strict Content Security Policies and declarative network request handling.
- CSRF Read-Only: The extension only reads your existing CSRF token to sign API requests. It never sets, modifies, or exposes your Instagram cookies.
10YOUR RIGHTS (GDPR AND CCPA) ↑ Top
Depending on your location (European Economic Area, United Kingdom, or California), you may have rights regarding personal information. Because InstaStudio collects no personal data, most of these rights are automatically satisfied. However:
- Right to Access: The only data we store is your Ghost Privacy toggle preference in
chrome.storage.local. You can inspect this at any time viachrome://extensions→ InstaStudio → Storage. - Right to Erasure: Uninstalling the extension immediately and permanently deletes all stored data (
chrome.storage.localis wiped on uninstall). - Right to Portability: Your settings are accessible locally and can be viewed via Chrome's developer tools at any time.
- Right to Object: You can disable any individual feature (Ghost Privacy, downloads, etc.) independently within the extension.
To exercise any right, simply uninstall the extension or contact us at the email below.
11DO-NOT-TRACK ↑ Top
Because InstaStudio does not track users across websites, collect behavioral data, or use advertising networks, it inherently complies with Do-Not-Track (DNT) browser signals. We do not alter the extension's behavior based on whether DNT is enabled or disabled. We simply never track.
12CHANGES TO THIS POLICY ↑ Top
We may update this Privacy Policy from time to time to reflect changes in the extension's features or legal requirements. When we do:
- The "Last Updated" date at the top of this page will be revised.
- Material changes will be noted in the extension's Chrome Web Store update notes.
- Continued use of the extension after an update constitutes acceptance of the revised policy.
We encourage you to review this page periodically. Since we collect no personal data, updates will typically be minor clarifications.
13CONTACT US ↑ Top
If you have questions, concerns, or feedback about this Privacy Policy or InstaStudio's data practices, please reach out:
For privacy inquiries, data requests, feature feedback, or bug reports:
support.instastudio@gmail.comWe aim to respond to all inquiries within 48 hours.