Unfollo

Legal

Privacy Policy

Last updated: July 2026.

The short version

  • We never ask for, receive, or store your Instagram or TikTok password.
  • Your uploaded export is parsed in your browser and is not uploaded to our servers by default.
  • If you save snapshots, we store normalized usernames and follow-relationship flags — not photos, messages, or other export contents.
  • You can delete everything, at any time, in one action.
  • We measure product usage with our own first-party analytics. No third-party analytics company receives anything, and no archive contents, relationship data or typed input ever reaches analytics.

“Processed” is not “stored”

These words mean different things in this policy, and the difference matters:

  • Processed temporarily in memory — a value is read from your export inside your browser tab, used to compute something, and then discarded when parsing finishes. It is never written to disk, never sent anywhere, and is gone when you close the tab.
  • Stored— a value is written to your browser’s local storage on your device and survives until you delete it.

Some sensitive values in a TikTok export are processed temporarily so we can count them, and are never stored. That is described precisely below.

Data we process

Export data (processed locally). Your archive ZIP or JSON file is read entirely in your browser, one file at a time. It is never uploaded. The file itself is discarded after processing; only the derived insights described below are kept.

Derived archive insights (local only).To power My Life, your device keeps sanitized summaries derived from your export: counts and monthly totals for posts, stories, likes, saves, and comments; profile-change history including previous values (emails masked); saved-collection names; recent search terms; and advertiser and interest lists. These stay in your browser’s local storage, are never synced to our servers, never appear in shared output, and are never sent to analytics. Media files inside the ZIP are skipped by their file names — photos and videos are never opened.

TikTok account-access records

A TikTok export includes a record of technical account-access events. Unfollo does open this category — earlier versions of this policy said it did not, which was wrong. Here is exactly what happens, all of it inside your browser:

  • Each access record is read in memory. From it we derive only: how many access events the export contains, the first and last dates they span, a count of distinct addresses, coarse device families(for example “iPhone”, “Samsung”, “Other device”), coarse operating-system eras, and network types.
  • The raw IP address is never retained. It is reduced to a non-reversible fingerprint purely so two identical addresses can be recognised as one, and both the address and that fingerprint are discarded when parsing ends. The address itself is never written to storage.
  • The raw device identifier or model string is never retained. It is mapped to a coarse family label at the moment it is read, and the original string is discarded.
  • Raw addresses and raw device identifiers are never persisted, never synced to our servers, never logged, never sent to analytics, and never included in any shared image or link. Only the sanitized counts above are stored locally, and only on your device.

These are technical events TikTok recorded, not necessarily manual sign-ins by you — Unfollo does not present them as logins.

What we never open at all

The following categories ship inside exports and are refused before any value is read. Unfollo reports that they were present and skipped, and nothing more:

  • Message contents, including group chats and TikTok’s Tako AI chat.
  • Autofill identity details — phone number, email, name, address.
  • Payment instruments and saved delivery addresses.
  • Wallet, coin-purchase and transaction records.
  • Device and advertising identifiers (IDFA, GAID and similar).
  • Synced contacts, exact locations, photos and videos.

Snapshots (stored only if you save them).A snapshot contains usernames, whether each account follows you / you follow them, platform-provided follow dates where present, and snapshot metadata. By default snapshots live in your browser’s local storage on your device. If optional account sync is enabled, only this normalized relationship data — never archive insights, search terms, or profile values — is stored server-side, associated with your account, to enable cross-device access.

Account data (optional). If you create an account: your email address, authentication tokens, and subscription status. Payments are processed by Stripe; we never see full card numbers.

First-party product analytics

We measure how the product is used with our own analytics, built into Unfollo and stored in Unfollo’s own database. There is no third-party analytics collector — no Google Analytics, no Plausible, no PostHog, no Mixpanel, no Amplitude. No analytics data is sent to any other company.

These analytics are first-party pseudonymous, not anonymous, and we will not call them anonymous: if you sign in, we link your visit to your account so questions like “did paying customers finish their import?” can be answered.

What is recorded:

  • Random identifiers.A random visitor identifier and a random session identifier, generated on your device with your browser’s cryptographic random-number generator. They are stored in local storage and in two first-party cookies (unfollo_vid, unfollo_sid). They contain no email, no social username, nothing derived from your archive, and nothing derived from your IP address, and they never appear in a URL. We do not fingerprint your browser.
  • Account linking. Once you sign in, the visit is associated with your account. Your email address is not copied into analytics events — it stays in the account record and is joined only when the owner views the private dashboard.
  • What you did. Pages viewed, scroll depth, time actively engaged, which buttons were clicked (by a fixed identifier we author in the code — never the text on screen), demo sections opened, import steps reached, and checkout steps reached.
  • How you arrived. Referring domain, and only these URL parameters: utm_source, utm_medium, utm_campaign, utm_content, utm_term, and the advertising click identifiers gclid, fbclid, ttclid, twclid. Every other query parameter is discarded — which is how sign-in links, one-time codes and checkout identifiers stay out of analytics. Referrer URLs are reduced to a domain; their paths and query strings are dropped.
  • Your device, coarsely. Device type, browser family and major version, operating system, screen and window size rounded to the nearest 10 pixels, language, time zone, light/dark preference, reduced-motion preference, whether you installed the app, and a rough connection speed category.
  • Coarse location. A two-letter country code, and a region only where our network provider states one. This comes from the network edge; we never store your IP address.
  • Import outcomes, in bands. The platform, whether the file was a ZIP or JSON, its size as a band(for example “10–50 MB”), how long parsing took as a band, and whether it succeeded or failed with one of seven fixed failure categories.
  • Performance and errors. Core Web Vitals, and error reports whose message and stack trace are stripped of quoted text, emails, handles, long tokens, query strings and file paths before they leave your browser.
  • Click and scroll heatmaps. Where on a page people click and how far they scroll, as coordinates relative to the page.

What analytics never receive:

  • Any contents of your archive, in any form.
  • Any social relationship data — no usernames, no follower lists, no who-unfollowed-whom.
  • Anything you type. No input values, no keystrokes, no search terms, no clipboard contents, no text you select.
  • The name of any file you upload.
  • Raw parser error messages.
  • Session replay. We do not record or reconstruct your screen, and we have not built the capability.

This is enforced by the code rather than by policy: an analytics event may only carry properties from a fixed list, and each one may only hold a value from a fixed set (a platform name, a size band, a number). There is no free-text field for an archive value to travel in, and the server rejects anything else.

Your choices

  • Global Privacy Control and Do Not Track. If your browser sends either signal, analytics are switched off entirely — including in regions where the law does not require it.
  • Consent.In the EEA, the UK and Switzerland nothing is collected until you opt in. Elsewhere, these disclosed first-party analytics run with a one-tap opt-out in You → Privacy Center. Nothing is collected before that state is resolved, and events raised while it resolves are discarded rather than replayed if the answer is no.
  • Opt out.Turning analytics off in You → Privacy Center also deletes your analytics identifiers and every analytics record keyed to them.
  • Delete the identifier only.“Delete my analytics identifier” erases the identifiers and their records while leaving analytics on.
  • Delete All My Data removes your analytics records along with everything else.

How long analytics are kept

  • Individual events: 13 months.
  • Sessions: 24 months.
  • Heatmap points: 13 months.
  • Sanitized error reports: 90 days.
  • Daily totals: kept indefinitely. These are counts only — a date, a dimension and a number — and contain no identifier.
  • Archive contents: never stored, so there is nothing to retain.

What we never do

  • Sell or share your relationship data with third parties.
  • Log into, scrape, or automate your social accounts.
  • Build cross-user databases of other people’s accounts.
  • Show other users anything about your social graph.

Retention & deletion

Raw uploads: not retained. Raw IP addresses and raw device identifiers from a TikTok export: not retained — discarded the moment parsing finishes. Local snapshots and derived archive insights: until you delete them or clear your browser storage (You → Privacy Center deletes them in one action). Synced data (if enabled): deleted immediately when you use Delete All My Data or delete your account, including backups on their scheduled rotation. See Data Deletion.

Contact

[email protected] — we answer privacy mail first.