Skip to content

Privacy policy

The short version: there are no accounts here, so there is almost nothing about you to hold. The rest of this page explains exactly what that means in practice.

Last updated 30 July 2026

What we collect

There is no sign-up anywhere on this site, which removes most of what a privacy policy normally has to account for. We never see your name, your email address, or your Instagram credentials, because nothing here ever asks for them.

  • The link you paste. It is used to look up the media for that post and is not written to any database. When the request finishes it is gone.
  • Ordinary server logs. Like every web server, ours records requests — IP address, timestamp, path, user agent — to keep the service running and to spot abuse. They rotate automatically and are not used to build a profile of anybody.
  • Aggregate usage counts. Which tool pages get used and how often lookups succeed, as totals rather than per person, so we know what to fix first.

What we deliberately do not collect

  • Instagram passwords or login tokens. The tool does not use them and there is no field to enter them into.
  • A history of what you downloaded. There is no account for one to attach to.
  • Copies of the media itself. Files stream through to your browser and nothing remains on our side afterwards.
  • Anything sold or rented to data brokers. We have no data product and no intention of building one.

Cookies

The site works without any tracking cookies. If advertising or privacy-respecting analytics is added later, this section will name the provider and describe what it sets before it goes live, and you will get a consent choice wherever the law requires one.

Third parties in the request path

Three are unavoidable given how the tool works, and you should know about all of them.

  • Instagram and its content delivery network. Retrieving public media means asking their servers for it, so they see that a request happened.
  • A media lookup provider, which turns a post link into direct file addresses. It receives the post identifier and nothing that identifies you.
  • Our hosting provider, which runs the servers and holds the standard access logs described above.

How long anything survives

Pasted links live only for the duration of the request. Server logs rotate on a short cycle, typically inside thirty days. Aggregate counts contain no personal data at all and may be kept indefinitely, because there is nothing in them to identify anyone with.

Children

This site is not directed at children under 13 and we do not knowingly collect information from them. With no accounts and no profile building, there is very little to collect from anyone of any age.

Your rights

Depending on where you live — the GDPR in Europe and the UK, the CCPA in California, and comparable laws elsewhere — you have rights to access, correct, delete, or object to the processing of your personal data.

Exercising them here is unusually simple, because without an account there is no personal record to produce or erase beyond transient log entries. If you would like those checked or removed, email hello@ilovenowatermark.com with the approximate date and time and, if you know it, the IP address involved, and we will action it.

Security

All traffic runs over HTTPS. The API credentials used for media lookups live in server-side environment variables and are never exposed to the browser. Because we store so little by design, a breach of our systems would not reveal anyone's download history — there is not one to reveal.

Changes to this policy

If this policy changes materially — a new analytics provider, an advertising partner, anything that alters what is collected — the date at the top will change and the new terms will be described in plain language rather than buried in a clause.