Privacy Policy
Last updated: 11 September 2026 · Publisher: Ultra Scalability · contact@ultra-scalability.com
1. Who we are
Media IQ is published by Ultra Scalability. For any question about your data: contact@ultra-scalability.com.
2. Data we process
- Account: your email address; if you sign in with Google, your Google name and avatar (we only request "email" and "profile", never access to your mailbox or your files); if you sign in with a password, the password you chose (stored hashed, never in clear).
- Imported content: the posts you choose to connect (links, captions, thumbnails, media, and their analysis: transcripts, on-screen text, structured records). They are private, attached to your account and isolated from other users.
- Usage and billing: questions asked, credits consumed, payment history (handled by Stripe — we do not store your card).
- Technical: sign-in and error logs required for security and correct operation.
- Instagram connection (browser companion). Opening the companion checks which Instagram account is signed in and stores its handle and numeric ID locally, together with request tokens returned by Instagram. This can happen before import consent. These tokens are sent only to Instagram, never to Media IQ. The companion does not read your Instagram password, sign-in cookies or private messages. Your browser still sends Instagram its own cookies when making a request to Instagram. The Media IQ website can receive your connected handle through the linking feature before import consent. Your Media IQ linking code is stored locally and authenticates requests to our backend, including account and credit-balance checks before import consent. Request timing, action type, build identifier and error diagnostics support operation and security; account state and credit balances are also cached locally.
- Collection and creator reads. After import consent, the companion reads the full collection catalogue. It sends your handle and numeric ID, every collection ID and name, and measured sizes to Media IQ, including when you find collections before importing posts. Size checks read entries even in unselected collections to count them; they keep counts and continuation positions, without importing those entries. Selected imports send post links, codes, types and available dates. For public creators you explicitly choose one by one, it sends their handle, numeric ID, display name, post count and public post references. Private creator accounts are refused. It does not collect general browsing history or send media files from your browser. Collection lists and public creator reads may use an existing Instagram tab; size checks make requests directly from the companion. A permitted popup action may open an Instagram tab and leave it open. The website and background check cannot open one; a request that needs a tab is skipped when none is available. No code runs on ordinary page loads.
- Checks and imports. The optional free check runs every six hours while Chrome can run it. It refreshes selected creator counts and compares previously measured collection sizes with your library. It does not detect new saves in collections: use a manual size check. Automatic imports require a separate switch; both options start off and can be turned off. Counting is free. Imports use credits: the button shows a base amount, and long carousels and videos over five minutes use more. Media IQ separately retrieves publicly accessible content for analysis; content requiring your Instagram login may remain unavailable. Data is transmitted over HTTPS. Chrome local storage holds connection and consent settings, identity, request tokens, collection names and measured sizes, credit balances, progress and bounded diagnostics. Chrome Sync is not used. Instagram tokens are cleared when the signed-in account changes; saved-post links and media files are not retained in this local storage.
- Creators referenced in your library. When you choose to track a public creator, Media IQ processes only public information about that account: its public profile (handle, numeric ID, display name, post count) and the public posts published by that account. Creators are added one at a time, by you, and private accounts are refused. Our legal basis for this processing is legitimate interest: letting our users organise and follow public content they have explicitly chosen. Anyone whose public content is referenced can ask for it to be removed by writing to contact@ultra-scalability.com; removal is effective within 30 days.
3. Why
To provide the service (import, analyse and query your saves), secure your account, bill you, and improve the reliability of these features. We do not use your content to train models and we do not sell it to anyone.
Chrome Web Store Limited Use
Media IQ's use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Data obtained through the browser companion is used only to provide and improve its purpose: bringing your selected Instagram saves and public creator content into your Media IQ library for search and questions, including operating and securing these features. It is not used for personalised advertising, sold to data brokers, or used to assess creditworthiness or for lending. Transfers are limited to those allowed by that policy. Human access is limited to your explicit consent for specific data, security needs, legal obligations, or aggregated and anonymised data for internal operations. See the Limited Use policy.
4. Processors
Hosting and database: Supabase (European Union, Paris) and Vercel. Content analysis: AI model providers (Anthropic, Google) which receive the content to analyse without retaining it for training. Transactional email: Resend. Payments: Stripe. Fetching the public content to analyse: Apify (receives only the public links of the posts). Some of these processors are located outside the European Union, or run their infrastructure there: Apify, which fetches the public content, operates its platform on servers in the United States. Where personal data leaves the European Union, we rely on the processor's data processing terms, which incorporate the European Commission's Standard Contractual Clauses.
5. How long we keep data
As long as your account exists. Your content and your account can be deleted on request at contact@ultra-scalability.com; deletion is effective within 30 days. Disconnecting a platform from the app stops all syncing; your existing library remains available until you request deletion. The same address and the same 30-day delay apply to a removal request from a creator whose public content is referenced (see section 2).
6. Your rights
Access, rectification, erasure, portability, objection: write to contact@ultra-scalability.com. You can also lodge a complaint with the CNIL, the French data protection authority.
7. Cookies
Only the cookies required to keep you signed in. No advertising cookies, no third-party trackers.