Privacy Policy
Last updated: June 11, 2026
This Privacy Policy explains how Reports+ ("we", "us", "our", or "the App") handles your information. We are committed to protecting your privacy and being transparent about our practices.
Our Privacy Commitment
The App keeps your Instagram content on your device while being transparent about the limited data that does leave it:
- Your Instagram content stays local: your followers, following, engagement and other analytics are stored only on your device, not on our servers.
- Limited data leaves your device: your account and device identifiers, subscription history, and the data needed for blocker detection and — with your permission — ad measurement, as detailed below.
- Tracking is opt-in: advertising tracking happens only if you allow it through Apple's App Tracking Transparency prompt.
Information We Collect
The following data is created on or sent from your device so the App can authenticate, manage your subscription, and measure our advertising. It is linked to you; we do not describe it as anonymous.
- Device identifier. When you first open the App, our server issues a random device ID (UUID), which we register together with a device fingerprint to authenticate your requests. This same device ID is used as your account ID in RevenueCat so your subscription stays in sync across reinstalls and devices, and — only after you grant tracking permission (see "Advertising & Tracking") — a hashed form of it is shared with TikTok as an ad match key.
- Your Instagram user ID. After you log in, the numeric user ID of your Instagram account leaves your device: the raw ID is sent to our server and stored as the lookup key for blocker detection, and a one-way SHA-256 hash of it is sent to Firebase Analytics as the analytics user identifier (so your analytics events are linked to that hashed ID). Your Instagram username, profile, followers, following and engagement data are not part of this.
- Blocker relationship data. To power blocker detection, our server stores the Instagram IDs of accounts that have blocked you and the time each block was detected, keyed to your Instagram user ID. This is fetched from an upstream blocker provider and cached on our server for up to 24 hours.
- Push token. If you enable notifications, Firebase Cloud Messaging issues a push token for your device, which we store on our server to send you notifications.
- Purchase history. When you start a trial or subscribe, RevenueCat records the product, price, currency and transaction ID to manage your subscription; these events are also shared with TikTok as described under "Advertising & Tracking." Payment itself is processed by Apple through the App Store; we never receive your card or payment details.
- Advertising identifier (IDFA). Collected only if you grant tracking permission through Apple's App Tracking Transparency prompt, and used only for ad measurement (see below).
- Crash, performance and usage analytics. We collect crash reports, performance diagnostics and usage events (such as which screens you view and when a paywall is shown) through Firebase and Microsoft Clarity. Firebase Analytics is keyed to the hashed Instagram user ID above; Microsoft Clarity is initialized with no user identifier and derives only a coarse, IP-based approximate location.
Information Stored on Your Device
The following stays on your device, is never uploaded to our servers, and is removed when you uninstall the App or clear its data in device settings:
- Your Instagram username, profile information and cached avatar images
- Your followers and following lists
- Engagement metrics, including Secret Admirers likes, comments and view counters
- Stories, story-viewer data, and Reels analytics
- Historical tracking snapshots and follower changes over time
- Your Instagram session cookies and login credentials, kept in the device Keychain and used only to talk to Instagram directly
What leaves your device is limited to the items listed under "Information We Collect" above.
Advertising & Tracking
We share certain data with TikTok for ad attribution and conversion measurement, including SKAdNetwork and value optimization. This requires your opt-in:
- App Tracking Transparency. Your IDFA is collected only after you tap "Allow" on Apple's tracking prompt. We present this prompt ourselves and show it after launch, not at startup; the TikTok SDK is configured not to show its own. Until you grant permission, no IDFA is collected and TikTok's automatic install and launch events carry no advertising identifier.
- What is shared with TikTok. When you start a trial or subscribe, we send the event (with product, value and currency) to TikTok, both through the in-app TikTok Business SDK and server-side through TikTok's Events API. These events include a SHA-256 hashed version of your account ID and — only if you allowed tracking — your IDFA, which TikTok uses to match the conversion to an ad.
- RevenueCat's role. RevenueCat collects your IDFA (after you allow tracking) and your account ID and relays your subscription conversions to TikTok for the measurement above.
- Opting out. Decline the tracking prompt, or turn off tracking for Reports+ in iOS Settings > Privacy & Security > Tracking. With tracking off, no IDFA is shared and ad measurement relies on your hashed account ID and Apple's SKAdNetwork only.
Third-Party Services
The App relies on the following providers, each acting under its own privacy policy:
- Our backend (Cloudflare): Our own server, which registers your device, authenticates requests, stores your Instagram user ID and blocker relationship IDs to detect blockers, stores your push token, passes your Instagram user ID to an upstream blocker provider as the lookup key, and relays subscription events to TikTok.
- TikTok: For advertising and conversion measurement. Receives your trial and subscribe events, purchase value, a hashed account ID, and — only if you allow tracking — your IDFA. See the TikTok Privacy Policy.
- RevenueCat: For subscription management and ad attribution. Receives your account ID, purchase history, and IDFA (if you allow tracking). See the RevenueCat Privacy Policy.
- Firebase (Google): Firebase Analytics (keyed to a hashed version of your Instagram user ID, not anonymized), Crashlytics (crash and performance data), Cloud Messaging (push tokens), and Remote Config (feature flags, no personal data). See the Firebase Privacy Policy.
- Microsoft Clarity: For anonymized behavior analytics and performance monitoring, set up with no custom identifier or tags and deriving only a coarse, IP-based location. See the Microsoft Clarity Privacy Policy.
Data Security
Your locally stored data is protected by your device's built-in security features, including encryption, and your Instagram credentials are kept in the device Keychain. The Instagram user ID, blocker data and push token held on our server are transmitted over encrypted connections and protected by authenticated, HMAC-signed requests.
Data Retention and Deletion
Your follower, following, engagement, stories and Reels data is stored only on your device, so uninstalling the App removes it and you can clear it at any time in device settings.
The data we hold on our server — your device record, Instagram user ID, blocker relationship IDs and push token — does not disappear automatically when you uninstall; blocker data is cached for up to 24 hours and refreshed from the upstream provider. To have your server-side data deleted, email us at analyzer@appwide.co.
Your Rights
You have the right to:
- Delete your on-device data by uninstalling the App or clearing its data in device settings
- Disconnect your Instagram account at any time
- Decline or revoke ad tracking, as described under "Advertising & Tracking"
- Request access to, or deletion of, the data we hold on our server — your device record, Instagram user ID, blocker relationship IDs and push token — by emailing analyzer@appwide.co
Children's Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date and, where appropriate, through in-app notifications.
If you have any questions about this Privacy Policy, please contact us at:
analyzer@appwide.co