No. WhoUnfollowed's parser only ever opens a small, fixed set of files inside your Instagram export by name: your followers list, your following list, your pending follow requests, and your own recently-unfollowed log. Even if your ZIP also contains private messages, photos, comments, or your entire account archive, because you chose "all available information" instead of the narrower request, the code never opens those files to read them. This isn't a policy promise. It's how the parser is written, and the code is public, so it can be checked directly instead of taken on trust.
Which Files the Parser Actually Opens
WhoUnfollowed's open source parser looks inside your uploaded ZIP for a fixed set of file name patterns, matched by their exact path and name: followers_1.json (and its paginated siblings for larger accounts) or followers_1.html if you exported in HTML instead of JSON, following.json or following.html, pending_follow_requests.json, and recently_unfollowed_profiles.json. Those are the only files it reads the contents of, full stop, regardless of which export format you picked (JSON is the better choice for other reasons, but the file-scope guarantee holds either way). For a closer look at what each of those actually contains, what's inside your Instagram data download breaks it down file by file.
What Happens If Your Export Also Contains Messages or Photos
Before opening anything, the parser lists the file names inside your ZIP so it can figure out what kind of export it's looking at, connections-only, Threads, or a mix. Listing names is different from reading contents. A file's name shows up in that list; a file's contents only get read if its name matches one of the patterns above. A messages folder, a media folder, an ads_information folder, none of them match, so none of them ever get opened, parsed, or looked at, no matter how large your export is or what else you selected when you requested it.
Why This Matters More If You Chose the Full Archive
The narrow "Followers and following" request keeps your export small on purpose, and if that's what you have, there's nothing else in the ZIP to worry about in the first place. But if you requested "all available information" instead, your export can include your direct messages, your posts, your comment history, and more, running into gigabytes for an active account. That's exactly the scenario where this matters: WhoUnfollowed treats a full archive the same way it treats a narrow one, by looking for the same fixed set of file names and ignoring everything else in the ZIP.
How to Verify This Yourself
You don't have to take this description on faith. The parsing logic is published under the MPL-2.0 license on GitHub, and the file-matching logic described above is a few dozen lines you can read start to finish. This is the same standard covered in does WhoUnfollowed store or sell your Instagram data: what a tool never opens, it cannot store, sell, or leak, and you can check that for yourself instead of trusting a privacy policy's wording.
In Short
- WhoUnfollowed's parser only opens a fixed, small set of files inside your export by name: followers, following, pending requests, and your recent-unfollow log, in whichever format you exported.
- Messages, photos, comments, and every other file in a full "all available information" export are never opened or read, regardless of how large the ZIP is.
- This applies the same way whether you requested the narrow connections-only export or the full archive.
- The file-matching logic is open source under MPL-2.0, so the claim can be verified directly in the code rather than taken on trust.
If you're deciding whether a follower tracker is safe to use at all, or wondering why other trackers ask for your password in the first place, the file-scope question above is the kind of specific, checkable claim worth demanding from any tool, not just this one. Most trackers won't let you check. This one does.


