Skip to content

Privacy Policy — Browser Extension

Effective date: 21 August 2026  ·  Katch the Ick (KLUPT)

This policy explains what the Katch the Ick browser extension (the "Extension", "we", "us") accesses, stores, and shares. It applies only to the browser extension, not to any other KLUPT product.

In short: the Extension shows you an Instagram profile's followers and following in order, using your own logged-in Instagram session in your browser. We do not collect, store, or transmit that Instagram data — or the accounts you look up — to our servers. The only data that reaches us is what's needed to process a one-time purchase, unlock the Extension, and a small amount of anonymous usage statistics (never tied to your identity or to any Instagram account) that help us keep the Extension working and improve it.

Instagram data the Extension reads

When you open a profile and use the Extension, it calls Instagram's own web API from your browser, authenticated by your existing Instagram session cookies (the same session you're already logged into). It reads the follower / following lists — username, display name, profile picture, and public verified/private flags — and displays them to you in the popup.

  • This data is fetched on your device and shown only to you.
  • It is never sent to KLUPT's servers, never stored by the Extension, and never shared or sold.
  • The Extension can only see what your own Instagram account is permitted to see.
  • We never receive or store your Instagram password or session cookies.

Stored on your device

The Extension keeps a small amount of data in your browser's local extension storage to make purchases and unlocking work:

  • A randomly generated device ID (not linked to your identity).
  • Your unlock/entitlement status and an access token for it.
  • The email address associated with your purchase, if you restore a purchase.
  • A temporary checkout session reference during payment.

This data stays in your browser. Uninstalling the Extension removes it.

Sent to our servers (purchase & unlock)

To sell the one-time unlock and restore it across devices, the Extension sends the following to the KLUPT API:

  • Your device ID, to create a checkout session and to check/grant your unlock.
  • Your email address, only if you use "Restore purchase" (so we can email you a secure link).

We use this solely to process payment and manage your access. We do not use it for advertising and we do not sell it.

Anonymous usage analytics

So we can tell whether the Extension is actually working for people and fix it when it isn't, it sends us a small number of anonymous product events. Each event is tagged only with your random device ID and the Extension version — never your name, email, or any Instagram account. We collect:

  • When the Extension is installed, updated, or opened — and, if it can't load, a coarse reason code (for example "not on Instagram").
  • When you start or stop tracking a profile, and when a sync begins, finishes, or fails — including how many new follows it found and how completely the list loaded. No usernames or list contents are included, only counts.
  • Whether a follower/following list loaded successfully, how many rows it returned, and — if it failed — a coarse reason code (for example "rate-limited" or "not logged in"). No usernames or list contents are included.
  • When the unlock paywall is shown, when checkout starts, and when an unlock completes.
  • When the in-app "rate us" prompt is shown, clicked, or dismissed.

These events are aggregated and used only to monitor reliability and improve the Extension. They are never sold or shared with third parties, and they never contain the Instagram accounts you view or their follower data — that information stays on your device, as described above.

Uninstalling the Extension stops all event collection. Because these events carry no identifying information, they cannot be tied back to you individually.

Third-party services

  • Stripe — payment processing. When you buy the unlock, Stripe handles your card details and billing email under Stripe's privacy policy. KLUPT never receives your full card number.
  • Instagram / Meta — the source of follower data, accessed through your own logged-in session, under Instagram's terms.

Permissions we request & why

  • Access to instagram.com — to read follower/following lists via your session.
  • Access to Instagram's image CDNs — to display profile pictures.
  • Access to our API / klupt.io — for purchase and unlock.
  • Storage — to remember your device ID and unlock status.
  • Alarms — to check for your unlock shortly after payment.
  • Notifications — to tell you when your purchase has unlocked.
  • Tabs / activeTab / scripting — to detect Instagram profile pages and open the checkout tab.

What we don't do

  • No selling or renting of your data.
  • No advertising or ad tracking.
  • No collection of browsing history outside of detecting Instagram profile pages.
  • No storage of your Instagram followers/following on our servers.

Data retention & your choices

Local data is retained until you uninstall the Extension or clear its storage. Purchase records (device ID, email, transaction) are retained on our side as needed to honor your access and meet legal/accounting obligations. To request deletion of your purchase data, contact us below.

Children

The Extension is not directed to children under 13 and we do not knowingly collect their data.

Changes

We may update this policy; material changes will be reflected by a new effective date on this page.

Contact

Questions or data requests: privacy@klupt.io

© 2026 KLUPT. This policy covers the Katch the Ick browser extension.