Privacy Policy
Effective date: 22 August 2026 · Last updated: 26 August 2026
Mastros ("we", "us", or "our") operates the mastros.online website and provides browser-based tools, including the Instagram Scraper & Follower Export Chrome extension, that let you export data that your own logged-in Instagram session can already see.
This Privacy Policy explains what the extension reads, what stays on your device, and the small amount of information that reaches us. Contact: admin@mastros.online
1. The short version
- The extension runs inside your browser on
www.instagram.com. It reads what your own session already renders — it does not log in for you, and it cannot see anything your account cannot see. - The data you extract never reaches our servers. Followers, comments, likers, posts and media are assembled in the page and saved straight to your computer through Chrome's download mechanism.
- What we do receive is limited to what is needed to run a licence and to keep the tool working: an account identifier, your plan, usage counts, and anonymous product analytics.
- The message export is the one feature that reads private content. It is off until you agree on a consent screen, it reads only your own inbox, and the text goes into the file you save and nowhere else. Section 3 says exactly what it does.
2. What stays on your device
Everything you extract. Extracted rows are never transmitted to Mastros, and there is no endpoint on our side that would accept them.
They are kept after the run, not only during it. Each export is saved as a dataset in a browser database on your computer (IndexedDB, named igexport_db) so that a long run can be resumed where it stopped and a finished one can be downloaded again without re-reading Instagram. That database never leaves your device. You can delete any single dataset, or all of them at once, from the panel's Results tab, and removing the extension removes the lot.
Extension settings, the pacing counters, your plan and usage figures, the diagnostic log and your message-export consent flag are kept separately in Chrome's local extension storage (storage). Chrome's synced storage holds one thing and one thing only: a random install id, so a paid plan survives a reinstall.
The export file itself — CSV, XLSX or JSON — is written by your browser the same way any download link works. Photos and videos go through Chrome's download manager, which is the one thing the downloads permission is for.
3. Direct messages
The extension can export your Instagram inbox: the people in it ("DM contacts") and the messages in one conversation you have open ("Chat history"). This is the most sensitive thing it touches, so the rules around it are stricter than for anything else and they are enforced in code, not by policy alone.
- You are asked first, once, and you can withdraw it. Neither message surface will start until you have been shown what it is about to read — including that the other person never agreed to it — and said yes. The consent is stored per installation and can be withdrawn at any time under Settings → Direct messages, after which you are asked again the next time.
- Your own inbox, and only ever your own. Instagram publishes no web endpoint that returns anyone else's threads, and the extension does not have one either. There is no setting, plan or version that changes this.
- Message text stays on your device. It goes into the CSV, XLSX or JSON file you save, and nowhere else: not to our licence service, not to analytics, not into an error report. The analytics allow-list has no property that could carry a message, a handle or a thread, so the exclusion survives a future change to the code rather than depending on one.
- Opening a conversation marks it read — exactly as opening it yourself does, because it is your own session reading it. We will not suppress the read receipt: that would be building a stealth feature, and we would rather tell you the truth about what the export is visible as.
- The extension never sends, replies to, deletes or edits a message, and never reads your inbox in the background. It reads one open conversation, when you press the button.
As with every other export, the file is yours and the responsibility for it is yours — see section 7. A conversation contains another person's words as well as your own.
4. What we receive
Licence and billing
Our licence service at igexport-api.mastros.workers.dev (Cloudflare Workers) stores one row per user containing:
- An account identifier. If you are signed in to Chrome, this is the email address of your Chrome profile, read through Chrome's
identity.emailpermission. If you are not signed in, a randomly generated install ID is used instead and we never learn an email address. - A browser fingerprint (a canvas hash), used solely to stop one person claiming an unlimited number of free quotas. It is never used for analytics, profiling or advertising.
- Your plan and subscription status, and — if you subscribe — the Stripe customer and subscription identifiers and your billing cycle dates.
Usage counters (how many rows you have exported in the current cycle) are held separately in Cloudflare KV. They are counts, not content.
Product analytics
We use PostHog, hosted in the EU (eu.i.posthog.com), to see whether the tool works. Events are restricted by a strict allow-list in the extension itself: anything not on the list is dropped before the request is built, so a future change cannot leak content by accident.
What is sent: the event name, and only these kinds of properties —
- product, plan, extension version, interface locale;
- which surface was used (for example "followers" or "post comments"), how many rows were gathered, how long the run took, whether it was resumed, and why it stopped;
- failure and self-healing causes when something breaks.
What is never sent: usernames, handles, display names, bios, captions, comment text, email addresses, post or media identifiers, search queries, or any follower's details. Row counts and failure causes only.
5. Permissions, and why each one exists
www.instagram.com— the only site the extension runs on.storage— settings and resumable run state, kept locally.downloads— saving the photos and videos you ask for to your computer, in their original quality and straight from Instagram's own network. The CSV/XLSX/JSON file does not use it.identity/identity.email— identifying your licence across devices. Optional in practice: without it you fall back to an anonymous install ID.alarms— one five-minute timer that re-syncs your plan and quota with the licence service, so an upgrade or a cancellation takes effect without a restart. It is the extension's only alarm.igexport-api.mastros.workers.dev— the licence service.eu.i.posthog.com— the analytics described above.
6. Processors
- Cloudflare — hosting for this site and the licence service (Workers, D1, KV).
- Stripe — payments. Card details go to Stripe directly; we never see or store them.
- PostHog (EU region) — product analytics, as scoped above.
- SplitForms — the contact and uninstall-feedback forms on this website. It retains submissions in its own dashboard.
- Google — distribution through the Chrome Web Store and the Chrome identity API.
7. Data you extract about other people
This matters and we would rather be blunt about it. When you export followers, commenters or likers, you are collecting personal data about people who are not party to this policy. For that data you are the controller, not us — we never receive it and cannot act on it for you.
You are responsible for having a lawful basis to collect and use it, for honouring access and deletion requests from those people, and for complying with Instagram's own terms and with the data-protection law that applies to you. The extension does not make that judgement on your behalf.
8. Retention and your rights
The account record we hold is one row, and this is all of it: your email address or install ID, the browser fingerprint hash, your plan and subscription status, your Stripe customer and subscription identifiers if you have paid, and your billing cycle dates. Usage counters — how many rows you have exported this cycle — are held alongside it. There is no other record, because there is nothing else we receive.
The record is kept while your account exists. Usage counters are deleted with it. Billing records are kept for as long as tax and accounting law requires, which is the one thing a deletion request cannot reach. Analytics events are retained by PostHog under its own retention settings and cannot be tied back to you by name, because no name is ever sent.
If the GDPR or a comparable law applies to you, you may request access to, correction of, or deletion of the data we hold about you, and you may object to processing or ask for a portable copy. Write to admin@mastros.online and we will show you the record or delete it within 30 days, keeping only what a payment record obliges us to keep. Deleting your licence also removes the email address or install ID associated with it.
9. Children
The Service is not directed at children under 16, and we do not knowingly create accounts for them.
10. Changes
If what the extension collects changes, this page changes with it and the "last updated" date above moves. Material changes will be called out in the extension or on this site rather than made quietly.
Questions: admin@mastros.online