# Privacy Policy **Last updated: 24 July 2026** **Effective date: 24 July 2026** Ghostegro (the "App", "Service") is developed and operated by **BEİVORS BİLİŞİM YAZILIM TEKNOLOJİLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ** ("Beivors", "we", "us", "our"), a limited liability company incorporated in Türkiye. Beivors is the **data controller** for the personal data described in this Privacy Policy. If you have any question about this policy or wish to exercise your rights, you can reach us at **info@beivorstech.com**. This Privacy Policy explains what information Ghostegro collects, why we collect it, who we share it with, how long we keep it, and what control you have over it. By downloading or using Ghostegro, you confirm that you have read and understood this policy. --- ## 1. Important notice about Instagram **Ghostegro is an independent analytics tool. It is not affiliated with, associated with, authorised by, endorsed by, sponsored by, or in any way officially connected to Instagram, Meta Platforms, Inc., or any of their subsidiaries or affiliates.** "Instagram" and "Meta" are trademarks of Meta Platforms, Inc., used here for identification purposes only. Ghostegro does not give you access to any Instagram account other than your own, and does not provide any information that is not already visible to you through Instagram itself. --- ## 2. Summary — what we do and do not do | | | |---|---| | **We never ask for or store your Instagram password.** | Correct | | We do not sell your personal data | Correct | | We do not post, like, follow, unfollow, comment, or message on your behalf | Correct | | We do not give any third party access to your Instagram account | Correct | | We collect only the data needed to run the analysis you asked for, plus standard technical and purchase data | Correct | | You can delete your account and all associated data at any time, from inside the App | Correct | --- ## 3. Information we collect ### 3.1 Information you provide **a) Instagram username (public lookup).** When you enter an Instagram username in the App, we query publicly available profile information for that username — profile picture, display name, and the public post / follower / following counts. No login is required for this step, and only information that Instagram already makes publicly visible is retrieved. **b) Instagram account connection (optional, for detailed analysis).** To produce detailed reports — such as who unfollowed you, who does not follow you back, or which followers never interact with your content — the App needs to read your own follower and following lists. To do this, you may choose to connect your Instagram account. When you do: - We receive and store an **Instagram session token** issued to your device. We do **not** receive, request, or store your Instagram password. - The session token is stored in encrypted form (AES-256-GCM) on our servers and is used solely to read your own follower, following and profile data on your behalf. - You can disconnect your Instagram account at any time from the App's settings, which immediately invalidates and deletes the stored token. - Connecting your account is entirely optional. You can use the App's public lookup features without connecting. **c) Instagram content data.** When you connect your account, we retrieve and store: your username, user ID, display name, profile picture URL, biography, account privacy status, post/follower/following counts, and the usernames and user IDs of your followers and the accounts you follow. This data is stored so we can compare it against later snapshots and show you what changed. Sensitive fields are encrypted at rest. **d) Correspondence.** If you contact us by email, we keep your message, your email address, and our reply. ### 3.2 Information collected automatically - **Device and technical data:** device model, operating system and version, app version, device language, region and time zone, screen configuration, network type, IP address. - **Identifiers:** Apple Vendor Identifier (IDFV), a randomly generated Ghostegro user ID, push notification token (if you enable notifications), and — only if you give permission via Apple's App Tracking Transparency prompt — the Advertising Identifier (IDFA). - **Usage data:** which screens you open, which features you use, session length and frequency, onboarding and paywall interactions. - **Diagnostic data:** crash reports, error logs, performance metrics. - **Purchase data:** subscription status, product identifier, purchase and renewal dates, trial status, transaction identifiers, country of the App Store account. Payment is processed by Apple; **we never receive your card number or bank details.** ### 3.3 Information we do not collect - We do not collect your Instagram password. - We do not collect precise geolocation. We may infer an approximate country or region from your IP address for security, fraud prevention and pricing purposes. - We do not collect your device contacts, photo library, microphone or camera data. - We do not knowingly collect data from anyone under 16. --- ## 4. Why we use your information, and our legal basis | Purpose | Data used | Legal basis (GDPR Art. 6 / KVKK Art. 5) | |---|---|---| | Providing the core analysis features you request | Instagram username, session token, follower/following data | Performance of a contract | | Creating and maintaining your Ghostegro account | User ID, device identifiers | Performance of a contract | | Processing subscriptions, restoring purchases, preventing subscription fraud | Purchase data, user ID | Performance of a contract; legitimate interest | | Sending push notifications about your reports | Push token, user ID | Consent (you can withdraw it in iOS Settings at any time) | | Diagnosing crashes and improving stability | Diagnostic and device data | Legitimate interest | | Measuring feature usage and improving the App | Usage data | Legitimate interest (or consent where required) | | Measuring the performance of our advertising campaigns | Attribution data, IDFA (only with ATT permission) | Consent | | Protecting the Service against abuse, automated access and rate-limit violations | IP address, device data, usage data | Legitimate interest | | Complying with legal obligations (tax, accounting, lawful requests) | Purchase and account data | Legal obligation | Where we rely on legitimate interests, we have assessed that our interest in operating and securing the Service does not override your rights and freedoms. --- ## 5. Service providers we share data with We do not sell your personal data and we do not share it for third-party advertising in a way that identifies you. We use the following processors, each bound by a data processing agreement: | Provider | Purpose | Data shared | |---|---|---| | **Apple Inc.** | App distribution, in-app purchases, push notification delivery | Purchase and transaction data, device tokens | | **Adapty Tech Inc.** | Subscription management, paywall configuration, purchase validation | User ID, purchase data, device and app metadata | | **Adjust GmbH** | Marketing attribution and campaign measurement | Device and app data, IP address, IDFA (only with ATT permission) | | **Google LLC (Firebase)** | Crash reporting, analytics, remote configuration, push notifications | Device data, usage data, crash logs, push token | | **Meta Platforms, Inc.** | Advertising campaign measurement (conversion events) | Hashed identifiers and event data, only with ATT permission | | **Contabo GmbH** | Server hosting and infrastructure | All data processed by the Service, stored in the EU | We may also disclose information where we are legally required to do so — for example to comply with a court order, a lawful request from a competent authority, or applicable tax legislation — or where disclosure is necessary to investigate suspected fraud or abuse, to enforce our Terms of Use, or to protect the rights, property or safety of Beivors, our users, or the public. If Beivors is involved in a merger, acquisition, reorganisation or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a different privacy policy. --- ## 6. International transfers Our servers are located in the European Union. Some of our service providers are established outside Türkiye and the European Economic Area. Where personal data is transferred internationally, we rely on the European Commission's Standard Contractual Clauses, adequacy decisions where applicable, and — for transfers from Türkiye — the mechanisms permitted under Article 9 of the KVKK. --- ## 7. How long we keep your data | Data | Retention period | |---|---| | Instagram session token | Until you disconnect your account or delete your account, whichever is earlier | | Follower / following snapshots | While your account is active; deleted within 30 days of account deletion | | Account and profile data | While your account is active; deleted within 30 days of account deletion | | Diagnostic and crash data | Up to 90 days | | Usage and analytics data | Up to 14 months, in aggregated or pseudonymised form thereafter | | Purchase and billing records | 10 years, where required by Turkish tax and commercial legislation | | Support correspondence | 2 years from the last message | --- ## 8. Security We use commercially reasonable technical and organisational measures to protect your information, including TLS encryption in transit, AES-256-GCM encryption of sensitive fields at rest, access controls limiting production access to authorised personnel, rate limiting, and regular patching of our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected users without undue delay. --- ## 9. Deleting your account and your data You can delete your Ghostegro account and all data associated with it at any time: **In the App:** Settings → Account → **Delete Account**. Deletion removes your profile, your stored Instagram session token, and all follower and following snapshots from our systems. Backups are purged on a rolling basis within 30 days. Records we are legally required to keep — principally purchase and invoicing records — are retained for the statutory period and are not used for any other purpose. You can also request deletion by writing to **info@beivorstech.com** from the email address associated with your account. Deleting the App from your device stops all further collection but does not by itself delete data already stored on our servers. **Cancelling a subscription is separate from deleting your account.** Subscriptions are managed by Apple — see Section 7 of our Terms of Use. --- ## 10. Your rights Depending on where you live, you have some or all of the following rights: - **Access** — to be told whether we process your personal data and to receive a copy of it. - **Rectification** — to have inaccurate or incomplete data corrected. - **Erasure** — to have your data deleted. - **Restriction** — to have processing limited in certain circumstances. - **Objection** — to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing. - **Portability** — to receive your data in a structured, machine-readable format. - **Withdrawal of consent** — to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. - **Complaint** — to lodge a complaint with a supervisory authority. In Türkiye this is the Personal Data Protection Authority (KVKK / Kişisel Verileri Koruma Kurumu); in the EEA it is the authority in your country of residence. Under Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK), you additionally have the right to learn whether your data has been transferred abroad, to request notification of corrections to third parties, to object to results produced solely by automated analysis, and to claim compensation for damages arising from unlawful processing. If you are a California resident, you have the right to know what personal information we collect and how it is used and shared, the right to request deletion, and the right not to be discriminated against for exercising these rights. **We do not sell or share personal information as those terms are defined by the CCPA/CPRA.** To exercise any right, contact **info@beivorstech.com**. We will respond within 30 days. We may ask you for information to verify your identity before acting on a request. --- ## 11. Advertising and tracking choices Ghostegro does not display third-party advertisements inside the App. We do advertise Ghostegro on external platforms and measure how those campaigns perform. On iOS, the App will ask for your permission through Apple's **App Tracking Transparency** prompt before accessing the Advertising Identifier (IDFA) or sharing data with advertising partners for measurement. If you decline, we do not access the IDFA and we do not share identifiers with advertising partners; the App works exactly the same in every other respect. You can change this choice at any time in **iOS Settings → Privacy & Security → Tracking**. You can also disable personalised advertising at [optout.aboutads.info](https://optout.aboutads.info), [optout.networkadvertising.org](https://optout.networkadvertising.org), or via the AppChoices app at [youradchoices.com/appchoices](https://youradchoices.com/appchoices). --- ## 12. Cookies The App itself does not use cookies. Our website and any web pages opened from the App may use strictly necessary cookies and, where required, will ask for your consent before setting any non-essential cookie. Third-party libraries used by the App may use similar local storage technologies for their own operation. --- ## 13. Children's privacy Ghostegro is not directed at children. **You must be at least 16 years old to use the Service.** We do not knowingly collect personal data from anyone under 16. If we learn that we have collected such data, we will delete it and close the account without delay. If you are a parent or guardian and believe a child under 16 has provided us with personal data, please contact **info@beivorstech.com**. --- ## 14. Links to other services The App and our website may contain links to third-party websites or services, including Instagram. This Privacy Policy does not apply to those services, and we are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any third-party service before using it. --- ## 15. Changes to this Privacy Policy We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top of this page and post the revised policy at the same address. If the change is material — for example, a new purpose of processing or a new category of recipient — we will notify you in the App or by push notification before the change takes effect. Continued use of the Service after a change takes effect means you accept the updated policy. --- ## 16. Contact **BEİVORS BİLİŞİM YAZILIM TEKNOLOJİLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ** Email: **info@beivorstech.com**