1. The short version
- ·Your Instagram export file is read in your browser and is never uploaded to us. We receive only the links and basic details of the posts you chose to import.
- ·Your library is private to your account and enforced at the database level, not just in the app.
- ·We do not sell your data, show you ads, or use your content to train AI models.
- ·You can delete any item, or your whole account and everything in it, at any time from the Account page.
2. What we collect
Account data
- ·Your email address (used to sign in and to contact you about the service).
- ·Your plan, subscription status, transformation balance, and usage history.
- ·If you sign in with Google, the basic profile information Google returns — we never receive your Google password.
Content data
- ·The links to the posts you import, plus caption text, creator name/handle, hashtags, and the date you saved them, taken from your export.
- ·Information we retrieve about those posts: thumbnail, title, duration, and — where needed — a text transcript of the audio.
- ·What we derive from that: categories, tags, summaries, key points, search indexes, and the outputs you generate.
- ·Your collections and any organization you create.
Technical data
- ·Standard server and security logs, including IP address and timestamps, used to operate the service and prevent abuse.
- ·Processing telemetry — timings, failures, and provider costs — used for reliability and to understand what the service costs to run.
We do not collect payment card details. Those go directly to our payment processor; we only ever see the subscription status and the last four digits and card brand it reports back.
3. Your Instagram export file, specifically
When you upload your export ZIP, it is opened and read entirely inside your browser. The file itself is never transmitted to our servers and we never store it. What leaves your browser is only the list of posts you are importing and the details attached to them (link, caption, creator, hashtags, saved date).
Instagram exports can contain far more than saved posts — messages, photos, contacts, activity history. We do not read, transmit, or retain any of it. This is why we ask you to select only Saved when requesting your export: it is the smallest file that does the job.
4. Why we process it
- ·To provide the service — building your library, search, and outputs (performance of our contract with you).
- ·To operate reliably and securely — logging, abuse prevention, backups (our legitimate interests).
- ·To take payment and prevent fraud (contract, and legal obligation).
- ·To contact you about your account or material changes (contract, legitimate interests).
We do not use your content for advertising or profiling, and we do not make automated decisions with legal or similarly significant effects about you.
5. Who we share it with
We use a small number of processors, each handling only what it needs. They are bound by contract to protect your data and to use it only on our instructions.
- ·Supabase — database, authentication, and file storage (hosts your account and library).
- ·Vercel — hosting and delivery of the web application.
- ·Railway — runs the background processing service.
- ·Apify — retrieves public post metadata and thumbnails for the links you import.
- ·Supadata — produces transcripts for imported videos when the caption alone is not enough.
- ·OpenRouter and the AI model providers it routes to — generate categories, summaries, and the outputs you request. Content is sent for that generation only; we direct that it not be used for model training.
- ·Stripe — payment processing and subscription management. Stripe receives your billing details directly, under its own privacy policy.
- ·An email delivery provider — sends sign-in links and account notices.
We may also disclose data if legally required, to enforce our terms, to protect rights and safety, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.
These providers may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
6. How long we keep it
- ·Account and library data: kept while your account is open.
- ·Deleted items: removed from your library immediately and purged from backups on our normal backup rotation.
- ·Deleted accounts: your library, imports, outputs, and collections are deleted straight away.
- ·Billing records: retained as long as tax and accounting law requires, even after account deletion.
- ·Security and processing logs: retained for a limited period for reliability and abuse prevention.
We keep a shared cache of processed public post data so the same post is not re-fetched for every user. That cache holds information about public posts, not about you, and is not linked to your identity after your account is deleted.
7. Security
- ·Every query runs under row-level security tied to your authenticated identity, so one account cannot read another's data even if the application layer were bypassed.
- ·Provider API keys are held server-side only and are never exposed to the browser.
- ·Traffic is encrypted in transit; data is encrypted at rest by our infrastructure providers.
- ·Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any relevant regulator as required by law.
8. Your rights
Depending on where you live — including under the GDPR in the UK/EEA and the CCPA/CPRA in California — you may have the right to:
- ·Access the personal data we hold about you, and receive a copy in a portable form.
- ·Correct data that is inaccurate.
- ·Delete your data — available immediately and directly from your Account page.
- ·Restrict or object to certain processing.
- ·Withdraw consent where processing relies on it.
- ·Not be discriminated against for exercising any of these rights.
Much of this is self-service in the app. For anything else, contact privacy@bigbrainlearning.app and we will respond within the timeframe the law requires. You may also complain to your local data protection authority.
We do not sell or share personal information for cross-context behavioural advertising, as those terms are defined under California law.
9. Cookies and analytics
Beyond the session cookie that keeps you signed in, we use cookies to measure traffic and the effectiveness of our own advertising. Either way you can change your answer at any time from the link in the footer of every page, and we honour browser-level opt-out signals such as Global Privacy Control.
Where you are changes when we ask. In places whose law requires consent up front — the EEA and UK, and some US states including California — the statistics and marketing cookies below are blocked until you accept them, and nothing is set if you decline or ignore the banner. Everywhere else they start on, the banner tells you so, and declining switches them off. We do not maintain the list of regions ourselves: our consent provider applies the rule for the visitor's location, so it stays current as laws change.
Necessary
A session cookie and local storage that hold your sign-in token, and a cookie that remembers your consent choice itself. These are not optional — the service cannot sign you in without them — and are not covered by the banner.
Statistics
Google Analytics (GA4), to see which pages get used and how people navigate the app, so we can prioritize what to build. It sets cookies that identify your browser across visits to this site. We have not enabled Google Signals or any feature that would link this to a Google account or follow you across other companies' sites.
Marketing
The Meta (Facebook/Instagram) Pixel, to measure whether the ads we run on those platforms actually lead to signups, and to avoid re-showing you an ad for a plan you already have. Meta may use this data under its own privacy policy in addition to ours; see Meta's cookie policy for how it uses pixel data across the sites and apps that use it. Sharing data with an advertising platform this way counts as “selling” or “sharing” personal information under some US state laws — declining, or sending a Global Privacy Control signal, is how you opt out of it.
Consent is managed by Cookiebot, which enforces whichever rule applies to you and does not receive any data about your saved reels or your account. Declining or later withdrawing does not limit any feature of the service — it only stops those two cookies being set.
10. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@bigbrainlearning.app and we will delete it.
11. Changes
We may update this policy. If a change is material, we will notify you by email or in the app before it takes effect, and update the date at the top of this page.
12. Contact
Privacy questions or requests: privacy@bigbrainlearning.app
General support: support@bigbrainlearning.app