Skip to security information

Security & data

Your saves become knowledge.Your Instagram sign-in stays in your browser.

Media IQ lists the saved-post links and public creator feeds you choose to sync, then processes those links in your private library. It does not collect your Instagram password or replay your browser sign-in on its servers.

M0 safety controls · updated Sep 11, 2026

Read-only
No posting, liking, following or messaging
6 hours
Background checks only after you opt in
Immediate pause
An Instagram challenge stops the run — no background attempt after that

Three places, one narrow path

The browser sign-in is used to check your identity, list collections and enumerate saved-post references and posts from public creators you explicitly choose to track. Everything after that starts from the link, without sending your Instagram sign-in to Media IQ.

  1. 01 · Your browser

    Reads the catalogue and selected content

    Uses your existing Instagram login to read collection IDs and names, sizes counted directly by the companion when you find collections, check sizes or sync, saved-post references and the public creator feeds you chose. Counting can read entries in unselected collections without importing them. No login is automated.

  2. 02 · Link handoff

    Sends references and account information

    Sends the connected handle and public account ID, the IDs and names of every collection, sizes counted directly by the companion when you find collections, check sizes or sync, selected saved-post references, public creator identifiers and names, post counts, post codes, permalinks and available timestamps. Creators are added one at a time by you; private accounts are refused. Media IQ never discovers accounts on its own or reads your browsing history.

  3. 03 · Private library

    Resolves and analyzes the post

    Media IQ resolves the link separately — through Apify, which receives only the public link and runs on servers in the United States — then stores the content and analysis under your Media IQ account when the post is accessible. Apify is the same processor named in our Privacy Policy; it never receives your Instagram sign-in.

A post that cannot be resolved without your Instagram login may remain unavailable. Media IQ does not send your browser sign-in to its server to get around that limit.

An explicit, read-only scope

Media IQ can read

  • The full list of your collections (IDs and names), and the saved-post references of the ones you choose to sync
  • Public creator profiles and posts you explicitly choose to track
  • Collection names, platform identifiers and sizes counted directly by the companion when you find collections, check sizes or sync
  • Post permalinks, codes and available timestamps
  • Content available from a resolved post, including caption, author, media, public metrics and location when the source provides them
  • Text and meaning extracted from media: OCR, transcript, visual description, summaries, facets and search embeddings

Media IQ does not read or do

  • Your Instagram password
  • Your direct messages, drafts or general browser history
  • Import entries from unselected collections during a size check
  • Post, comment, like, follow, unfollow or send messages
  • Copy your Instagram sign-in cookies to Media IQ servers
Chrome permission

The Media IQ browser companion does not request Chrome's Cookies permission. Instagram still receives its own sign-in cookies when your browser makes an Instagram request; Media IQ does not read or copy them.

Opening the companion can check and store your Instagram identity and request tokens before you agree to import. The Media IQ website can read the connected handle through the linking feature. Your linking code authenticates requests to Media IQ for account and credit-balance checks. Request timing, action type, build identifier and errors support operation and security. Instagram request tokens are never sent to Media IQ. Other Instagram reads require import consent. Finding collections can send your identity and the full catalogue before you import any posts.

Collection lists and public creator reads may use an existing Instagram tab; size checks make requests directly from the companion. A permitted popup action, or your click on "I agree and connect" on the companion's own consent page, may open one tab in the background and leave it open. The website and background check cannot open one on their own and skip requests that need a tab when none is available.

Read our Privacy Policy and Limited Use commitment.

Off by default. Stoppable immediately.

A successful first import is not consent for ongoing background checks. The control is separate, visible and survives a browser restart.

Default · off

Scheduled checks require your approval

If consent is absent or switched off, scheduled wake-ups make no Instagram call — including after the browser companion restarts.

Opted in · every 6 h

A check, not a continuous connection

Every six hours while Chrome can run it, the free check refreshes selected creator counts and compares previously measured collection sizes with your library. It does not detect new saves in collections: check sizes manually. Automatic imports require a separate switch. Both options start off and can be turned off. Counting is free; imports use credits. The amount shown before import is a base amount; long carousels and videos over five minutes use more.

Stop · now

The active run is cancelled

Stop cancels an in-progress enumeration. Once stopped, no new Instagram request or link handoff begins from that run.

Instagram says stop. Media IQ stops.

If Instagram reports a checkpoint or challenge, the run is cancelled immediately. Media IQ does not try a second request path, and it makes no background attempt once Instagram asks for a verification: nothing runs while the popup is closed.

The pause is remembered across browser restarts. Recovery stays human: open Instagram normally and clear the request there. The check only runs again when you reopen the popup, or use the available retry control.

1

Instagram returns a challenge or checkpoint

2

Media IQ cancels and remains paused

3

You resolve it in Instagram and reopen the popup

What is kept, and where

In your browser

Connection and safety state

Your Media IQ linking code, Instagram handle and numeric ID, request tokens, selected sources, collection names and measured sizes, continuation positions, the saved-post identifiers used for counting, consent, credit balance, latest sync status and bounded diagnostics are stored locally in this Chrome profile. Chrome Sync is not used. Instagram request tokens go only to Instagram and are cleared when the signed-in account changes. Media files are not retained in this local storage.

In Media IQ

Your private knowledge base

Media IQ stores connected-account references, collections, post links and resolved post data, plus OCR, transcripts, descriptions, structured analyses, search chunks, usage records and private poster images.

Access controls

Scoped to your account

Database rows are owner-scoped with row-level access policies. Stored poster images live in a private bucket and are opened through temporary signed links. Media IQ stores a hash of server-side linking keys rather than the keys themselves.

Instagram's web interfaces are private and can change

To list private saved collections and public creator feeds, the browser companion uses Instagram web endpoints that Instagram does not document for third-party use. Instagram can change, rate-limit or block those endpoints without notice.

Read-only access, a six-hour interval and immediate challenge stops reduce unnecessary activity; they cannot guarantee that Instagram will never show a warning or restrict the account. Media IQ is not affiliated with or endorsed by Instagram or Meta.

Write to contact@ultra-scalability.com

Send data questions, deletion requests and refund requests to contact@ultra-scalability.com, from the address on your account. Include your Media IQ account email and the affected collection or date. Deletion is effective within 30 days. Do not send an Instagram password, cookie, one-time code or screenshot containing sign-in data.

Security & Data — Media IQ