No. WhoUnfollowed never receives your Instagram data export in the first place, so there is nothing on our end to store or sell. The ZIP file you upload is read entirely by your own browser using client-side JavaScript, and its contents, your followers, your following, your usernames, never reach our servers during analysis.
What Actually Happens to the File You Upload
When you drop your Instagram export into WhoUnfollowed, the parsing happens locally, inside the browser tab you are already looking at. No part of that file is transmitted anywhere as a step in producing your results. This is not a setting you have to enable. It is the only way the free tier works, described in full in our privacy policy.
What About the Snapshots You Save for Later?
If you save a snapshot on the free tier so you can compare it against a later export, that snapshot stays in your browser's own local storage (IndexedDB) on your device. We have no copy of it and no way to read it, because it never leaves your browser to begin with.
What Does the Paid Pro Tier Store, and Why?
Pro adds optional cloud snapshot history so your export record survives a cleared browser or a new device. To provide that, we store an email address, an argon2id-hashed password, an encrypted snapshot blob, and a Stripe billing reference marking when your access expires. That is the complete list. Full card numbers never reach us; Stripe handles that directly. Nothing beyond what running the feature requires gets collected, and the exact handling is spelled out in the privacy policy, not just summarized here.
Does WhoUnfollowed Sell Data?
No. There is no advertising network built into the product, no data broker relationship, and no business model anywhere that depends on monetizing what a user uploads. The reason the free tier cannot leak your Instagram data to a third party is the same reason it cannot sell it: the data never arrives at a server we control to begin with.
How to Verify This Instead of Taking Our Word for It
A privacy claim on a landing page is easy to write and hard to check. The parsing code that reads your export, the exact logic that decides what happens to your data, is open source under the MPL-2.0 license and published on GitHub. You do not have to trust a sentence on this page. You can read the code that runs when you upload a file, the same way you would check a claim from any other follower tracker that says it is safe.
In Short
- WhoUnfollowed's free tier never transmits your Instagram export to a server; parsing happens entirely inside your browser.
- Free-tier snapshots are stored only in your browser's own local storage (IndexedDB), which we cannot access.
- The paid Pro tier stores the minimum needed for cloud history: an email, a hashed password, an encrypted snapshot, and a billing reference, nothing more.
- There is no data-selling business model in the product, and the parsing code is open source so the claim can be checked directly rather than taken on trust.
If you are comparing this against a tool that asks for your Instagram password instead, or wondering whether unfollow apps in general actually deliver what they promise, the structural difference is the same one covered here: what a tool never receives, it cannot store, sell, or leak.

