Legal

Privacy Policy

Effective date: April 14, 2026  ·  Developer: Yatinder Sharma

This Privacy Policy describes how InstaBrain ("we", "our", or "us") collects, uses, and protects your personal information when you use our mobile app and website. By using InstaBrain you agree to this policy.

1. Information We Collect

We collect the following categories of information:

Account Information

  • Mobile phone number (used for OTP-based authentication)
  • Account creation timestamp and session tokens

Content You Provide

  • URLs of Instagram Reels you submit for analysis
  • Transcripts and AI-generated analysis results (summaries, tags, notes, quiz questions) derived from those reels
  • Personal notes and annotations you save to your library
  • Custom tags and categories you create
  • Reminder preferences and scheduled times

Usage Data

  • Quiz attempts, scores, and daily streaks
  • Feature usage events (e.g., which sections you visit, share card generation)
  • App version, device operating system, and device type (iOS / Android)
  • Crash reports and error logs (no personally identifiable information in logs)

Payment Information

  • Subscription status and tier (Free / Pro)
  • Transaction IDs from Apple App Store, Google Play, or Razorpay
  • We do not store full payment card details — these are handled entirely by Apple, Google, or Razorpay

2. How We Use Your Information

  • To authenticate you via phone number OTP and maintain your session
  • To run AI analysis on the Instagram Reel URLs you submit
  • To store and display your analysis history, library, notes, and quizzes
  • To enforce Free tier quotas and manage Pro subscription access
  • To send push notifications you explicitly opt in to (quiz reminders, recall alerts)
  • To calculate and display your quiz streaks and learning progress
  • To improve our AI models and app features using aggregated, anonymised usage patterns
  • To comply with legal obligations and prevent fraud or abuse

3. Third-Party Services

We share or send data to the following third-party providers to operate the service. Each provider has its own privacy policy.

Google Gemini AI

Purpose: AI analysis of reel content (transcription, summarisation, quiz generation)

Data shared: Reel transcript text and metadata

Firebase (Google)

Purpose: Push notifications delivery (iOS and Android)

Data shared: Device push notification token

2factor.in

Purpose: SMS OTP delivery for authentication

Data shared: Phone number

Adapty

Purpose: iOS in-app subscription management

Data shared: Subscription status, purchase receipts (iOS)

RevenueCat

Purpose: Cross-platform subscription management

Data shared: Subscription status, purchase receipts

Razorpay

Purpose: Payment processing for Indian users

Data shared: Transaction ID and amount (no card details stored by us)

Vercel

Purpose: Web hosting and serverless functions

Data shared: Server access logs (IP address, request metadata)

We do not sell your personal data to any third party. We do not use your data for advertising.

4. Data Storage and Security

  • Your data is stored on secured PostgreSQL servers. All connections use TLS encryption in transit.
  • Session tokens are stored in HTTP-only, secure cookies and never exposed to JavaScript.
  • We retain your account data for as long as your account is active, or as required by law.
  • Analysis results, notes, quiz history, and reminders are retained until you delete them or request account deletion.
  • Reel transcript data is stored to power your Library and recall features — it is not used to train AI models without anonymisation.

5. Your Rights

You have the following rights regarding your personal data:

  • Access — request a copy of all data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your account and all associated data
  • Portability — request your data in a machine-readable format
  • Objection — object to processing of your data for non-essential purposes

To exercise any right, email support@instabrain.app. We will respond within 30 days. For account deletion, include the subject line "Delete Account" — deletion is completed within 7 business days and confirmed by email.

6. Children's Privacy

InstaBrain is not directed at children under 13 years of age (or under 16 in the European Economic Area). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us immediately at support@instabrain.app and we will delete it promptly.

7. Push Notifications

We send push notifications only if you grant permission. You can withdraw consent at any time through your device settings (iOS: Settings → Notifications → InstaBrain; Android: Settings → Apps → InstaBrain → Notifications). Disabling notifications does not affect your ability to use the app.

8. Cookies and Local Storage

Our website uses HTTP-only session cookies for authentication. The mobile app uses secure local storage only for caching analysis results to enable offline access. We do not use advertising cookies or third-party tracking pixels.

9. International Users

InstaBrain is operated from India. If you access the app from outside India, your data may be transferred to and processed in India and in the countries where our third-party providers operate. By using the app, you consent to this transfer.

For users in the European Economic Area (EEA) or United Kingdom, our lawful basis for processing is: (a) contract performance for core app features; (b) legitimate interest for product analytics; and (c) consent for push notifications.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page and, where appropriate, via an in-app notice. Continued use of InstaBrain after changes constitutes your acceptance of the updated policy.

11. Contact Us

For privacy questions, data requests, or concerns, contact us at:

InstaBrain — Yatinder Sharma

Email: support@instabrain.app

Response time: within 30 days of receipt