Privacy

Privacy Policy

What we hold about you, why we hold it, who else sees it, how long we keep it, and how to make us delete it. This policy is about your data — if you want to know how the product works, that is the Terms.

Last updated 13 August 2026.

The short version. We hold your email, your name, your interests, your Instagram handle and the access token that lets us act on your account, and the conversations you have through Instdate. We do not sell it and we never have. If you accept analytics on this website, we also tell Meta whether its ad worked — that is the one thing we share for advertising, it is off until you say yes, and section 4 says exactly what goes. You can delete all of it yourself, from Settings, in one action.

1. Who is responsible for your data

Instdate is the data controller for the personal data described here — we decide what is collected and why. Contact us about any of it at the address below.

We apply the GDPR standard to everyone, wherever you live, rather than giving different people different protection depending on their address. If you are in the United States, the rights your own state gives you apply on top of that — see section 8.

Privacy questions, and requests about your data: hello@instdate.com.

2. What we hold about you

  • Your account. Email address, password (stored only as a cryptographic hash, never as text we can read), the name you give us, and the date you accepted these terms and which version you accepted.
  • What you are looking for. The interests, city and age range you choose. These drive who the app shows you and nothing else.
  • Your Instagram connection. Your handle, and an access token issued by our connection provider that lets the app act on your account. We do not store your Instagram password. The token is what you revoke when you disconnect.
  • Your conversations. The openers drafted for you, whether you sent them, the messages exchanged in threads you started through Instdate, and the timestamps. We hold these so the app can show you your own conversations.
  • Your subscription. Which plan you are on, whether it is active, and the billing records Stripe returns. We never receive your full card number.
  • Technical records. Server logs containing IP address, device and app version, and the time of a request. We use them to keep the service running and secure.
  • Website measurement — only if you accept it. One anonymous ID for your browser, the advertising parameters on the link you arrived by (including Meta's fbclid), the page you landed on, the host that referred you, and which steps of this website you reached. It is off until you accept the banner, it holds nothing you typed, and declining removes it. Section 4 says who else sees it and section 6 says how long we keep it.

We do not analyse photographs of you or of anyone else to infer appearance, attractiveness, ethnicity, or any other personal characteristic, and we do not use biometric data.

3. Why we hold it, and on what legal basis

  • To provide the service you signed up for — your account, preferences, Instagram connection and conversations. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To take payment and keep the records tax law requires. Legal basis: contract, and our legal obligation (Art. 6(1)(b) and (c)).
  • To keep the service secure and working — logs, abuse investigation, fraud prevention. Legal basis: our legitimate interest in running a service that is not abused (Art. 6(1)(f)).
  • To record that you accepted the terms. Legal basis: our legal obligation to be able to demonstrate it (Art. 7(1)).
  • Analytics on this website, and telling Meta whether its ad worked — only if you accept it. Both are off until you do, they are the same decision rather than two, and you can withdraw at any time in section 8. Legal basis: your consent (Art. 6(1)(a)).

We do not use your data to train models that profile people by appearance, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

4. Who else sees it

We share your data with the companies that make the service work, and with nobody else. Each acts on our instructions under a contract.

  • Our Instagram connection provider — holds the token and carries the messages between the app and Instagram.
  • Our hosting and database provider — stores your account and conversations.
  • Stripe — takes the payment and holds the card details we never see.
  • Instagram / Meta — receives the messages you send, because that is where they are going.
  • Meta, for advertising measurementonly if you accepted analytics on this website. We advertise on Facebook and Instagram, and this is how we find out whether an ad produced a signup rather than a click. It is sent from our server to Meta's Conversions API; no Meta script, pixel or third-party file loads on this site.

Exactly what goes to Meta, and only with your consent. Which of five events happened — you viewed a page, you finished the demo, you created an account, you opened checkout, you subscribed — with the subscription's amount and currency. Alongside it: your email address as an irreversible SHA-256 hash and never as text, your account id as a hash, the two browser identifiers Meta uses to match a conversion to a click (one derived from the fbclid on the link you arrived by, one we generate and hold on our own server rather than on your device), and — read from the request at the moment of sending and written to no log or database of ours — your IP address and browser user-agent string.

What never goes: your name, your interests, your Instagram handle, anything you typed, anything about the people you were shown, and your consent decision itself. Decline the banner and not one of these events is sent, including from our server.

We may also disclose data if the law requires it, or to protect someone's safety. We do not sell your personal data and never have. The measurement described above is a disclosure to Meta as a separate controller, and under California's definition it counts as sharing for cross-context behavioural advertising. It is the only such sharing we do, it happens only if you accepted it, and section 8 is how you stop it.

Some of these providers are outside the EEA. Where that is so, transfers rely on the European Commission's standard contractual clauses or on an adequacy decision.

5. The people you contact

Instdate surfaces people using information they have made public — open communities, public bios and captions. We never access anything behind a login or a private account.

This policy is about your data. If you are someone Instdate surfaced rather than someone who uses it, and you want to know what we hold or want it removed, email hello@instdate.com and we will handle it.

6. How long we keep it

  • While your account exists — your account, preferences and conversations.
  • Deleted when you delete your account — all of the above, together with your Instagram token, which we also revoke.
  • Kept after deletion: invoices and payment records, which tax and accounting law requires us to retain, and a minimal record that a deletion happened, which holds no personal data and exists so we can show we honoured your request.
  • Server logs are kept for a short operational period and then discarded.
  • Website measurement — deleted 90 days after your last visit. If you never answer the consent banner it is deleted after 7 days. If you decline, or withdraw later, it is deleted straight away. Deleting your account takes it too. What survives any of those is a daily counter of how many visits an ad produced, which holds a date, the ad's id and a number, and nothing that can single anybody out.

7. Deleting everything

Settings ▸ Erase all my data. One action, no email, no waiting on us. It deletes your account, your preferences, your conversations and your drafts, and revokes the Instagram token so the app can no longer act on your account. It is irreversible, and the app tells you so before you confirm.

Deleting your Instdate data does not delete messages already delivered to someone else's Instagram inbox. We cannot reach into their account, and neither can you.

8. Your rights

Under the GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw consent where we relied on it. You also have the right to complain to the data protection supervisory authority for the country you live in.

If you live in California, Colorado, Connecticut, Virginia or another US state with a consumer privacy law, you have rights to know what we hold, to have it deleted, to correct it, and to opt out of sale or of sharing for targeted advertising. We do not sell your data. We do share the website measurement in section 4 with Meta for advertising. To exercise any of these rights, including opting out of that sharing, email hello@instdate.com. We will not treat you differently for exercising any of them.

Most of the rest is faster to do yourself: your data is in the app, editable in Settings, and deletable in one action. For anything else, email hello@instdate.com and we will answer within 30 days.

9. Security, children, and changes

  • Data is encrypted in transit and at rest, passwords are stored only as hashes, and access to production data is limited to the people who need it. No system is perfectly secure, and we will tell you and the regulator without undue delay if a breach puts you at risk.
  • Instdate is for adults. We do not knowingly collect data from anyone under 18. If we discover we have, we delete it and close the account.
  • If we change this policy materially, we will tell account holders before it takes effect. The date at the top always reflects the current version.

Related: Terms of Service · Home