Privacy Policy

Last updated: 21 September 2026

Privacy at a glance

Statly is two products, and they are separate systems. The Chrome extension runs inside your own logged-in browser session on supported social platforms, reads publicly visible content, and does the analytics on your device. The web app at app.trystatly.com works differently: you tell it which public Instagram, TikTok and YouTube accounts to follow, and our servers collect their public short-form videos once a day and keep the results for you. No automated logins or third-party credentials are used. We are not affiliated with Meta, TikTok/ByteDance or Google.

The extension is identified by a licence key and the web app by your email address; buying one does not give you the other, and we do not link the two. The extension talks to our servers only to verify your licence key, enforce the free-scan limit and 7-day trial (via an anonymous installation identifier plus, briefly, your IP), record anonymous usage events used to improve the product and measure our own ads, and, for Pro users, provide cloud sync, viewer keys, the Statly API, and the AI-assistant connection. The web app needs an account, so it holds your email address, your settings, the accounts you track, and anything you save to your Library.

Because the web app scans on our servers, we also hold public data about the creators you choose to track, who are not our customers: their handle, follower count, profile picture and the public reels they posted, with the views, likes and comments on each. Section 4.17 says exactly what, and Section 11 says how a creator can ask us to stop.

If you turn on transcription in the extension, the audio of the videos you choose to transcribe goes directly from your browser to Groq or OpenAI, using your own API key. It does not pass through our servers.

We do not sell data, and we use no Google Analytics, tracking pixels, or third-party SDKs inside the extension. Payments run through Lemon Squeezy as Merchant of Record, so we never see your card. To exercise any GDPR right, including full deletion, email info@trystatly.com. Full detail is in the numbered sections below.

1. Definitions

"Personal data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of Regulation (EU) 2016/679 (GDPR).

"Processing" means any operation performed on personal data, whether or not by automated means, including collection, storage, use, transmission, or deletion.

"We", "us", "our" refers to Miltiadis Themelis, the Data Controller.

"Supported platforms" means Instagram, TikTok, X (Twitter), and Reddit, the four social networks on whose public web pages the extension operates.

"Installation Identifier" means a randomly generated universally unique identifier (UUID v4) created by the extension on first installation and stored locally in Chrome extension storage. It contains no personal information and is not linked to any real identity.

"Usage event" means an anonymous record of an action inside the extension (for example, opening a dashboard, running a scan on a specific dashboard, activating a licence, or uninstalling the extension), tagged with the Installation Identifier and a timestamp.

"Install source" means a short marker stored temporarily in your browser's local storage on trystatly.com, indicating whether you arrived via one of our advertising campaigns. It is used only in aggregate to measure ad effectiveness.

"Cloud sync" refers to the optional feature, available to active Pro users, that stores a copy of certain Statly content on our infrastructure so it can be accessed across the user's devices.

"Viewer key" refers to a randomly generated read-only access token that a Pro user can create in the extension to grant a teammate read-only access to that user's synced content, and can revoke at any time.

"Web app" means the Statly web application at app.trystatly.com, together with the servers that run its daily scans. It is a separate product from the extension, with a separate subscription.

"Account" means the record created when you sign in to the web app with your email address. It holds your settings, your plan, and what you track.

"Workspace" means a container inside an account holding niches, tracked accounts and a saved Library, which the account owner may invite other people into.

"Tracked account" means a public Instagram, TikTok or YouTube account a customer has asked the web app to follow.

"Creator data" means the publicly visible information the web app collects about tracked accounts: the handle and public numeric identifier, follower count, profile picture, and, for each public reel, its code, posting time, view, like and comment counts, duration, thumbnail, video link and sound metadata.

"Scan" means one automated read of a tracked account's public short-form videos, performed by our servers through our data provider, on a daily schedule rather than at the moment anybody looks.

"Transcription provider" means Groq, Inc. or OpenAI, L.L.C., whichever issued the API key you enter in the extension to enable transcription and video descriptions.

"AI-assistant connection" refers to the optional feature, available to active Pro users, that lets an AI assistant you authorise (for example Claude or ChatGPT) read your synced Statly content through our MCP server.

2. Identity and Contact Details of the Data Controller

Name: Miltiadis Themelis
Location: Greece
Email: info@trystatly.com

All data-protection enquiries, requests to exercise data-subject rights, and complaints should be directed to the email address above.

Data Protection Officer (DPO): No DPO has been appointed. This is not required under Article 37 GDPR, as the processing activities carried out do not meet the thresholds that trigger a mandatory DPO appointment.

3. About Statly and How It Works

Statly is two products. They share a name, a company and this policy, and nothing else: separate systems, separate identities, separate subscriptions.

3.1 The Chrome extension

The extension runs on Instagram, TikTok, X (Twitter), and Reddit web pages. On each supported platform, it reads publicly visible content already rendered in your browser and performs analytics calculations locally on your device. All analysis takes place inside your own logged-in browser session. It is identified by a licence key, never by your name or email.

The extension does not:

  • transmit profile data, scan results, analytics outputs, or browsing activity to any server we control, except as part of the optional cloud sync feature for Pro users (Section 4.8), the optional Statly API (Section 4.10), the optional AI-assistant connection (Section 4.11), or a bug report you choose to send (Section 4.7);
  • access login credentials, private messages, direct messages, or authentication tokens for any social platform;
  • modify the backend systems of Instagram, TikTok or YouTube;
  • bypass any authentication mechanism.

3.2 The web app

The web app at app.trystatly.com works the other way round, and it is important that you understand the difference. You sign in with your email address and tell it which public Instagram, TikTok and YouTube accounts to follow. Our servers then read those accounts' public short-form videos roughly once a day, through the data provider named in Section 8, and store what they find so that your dashboards, trends and exports are ready when you open them. The reading happens on a schedule, whether or not you are looking, and it happens without signing in to any platform as you or as anybody else.

The web app does not:

  • use your Instagram account, your credentials or your session for anything;
  • read anything that is not publicly visible to a signed-out visitor;
  • collect private messages, followers lists, or any other non-public data;
  • post, comment, follow, or take any action on any platform on your behalf.

Because the web app collects on a schedule, it necessarily holds data about the creators our customers follow. Those creators are not our customers and have no relationship with us. Section 4.17 sets out exactly what is held, Section 6 the legal basis, and Section 11 how a creator can object.

Statly is not affiliated with, endorsed by, or in any way officially connected to Meta Platforms, Inc., TikTok Inc./ByteDance Ltd., X Corp., or Reddit, Inc. Instagram, TikTok, X, and Reddit are trademarks of their respective owners.

4. Personal Data We Process

4.1 Licence Key Transmission (Paid Users Only)

If you hold a paid subscription, the extension transmits your licence key to a licence-verification endpoint hosted on Cloudflare Worker infrastructure (at the domain core.trystatly.com). This transmission occurs over HTTPS and serves exclusively to confirm, via our payment provider Lemon Squeezy, that your licence is valid.

IP addresses are personal data under GDPR. In the course of processing the HTTPS request, your IP address and standard connection metadata are received and processed by Cloudflare as a data processor providing infrastructure services. For licence verification specifically, we do not deliberately persist your IP address beyond the transient handling of the request.

4.2 Installation Identifier, Scan Count, and IP-Based Rate Limiting (All Users)

To enforce the daily free-scan limit, to prevent abuse of that limit, and to prevent 7-day-trial resets through reinstallation, the extension transmits the anonymous Installation Identifier to a scan-counting endpoint hosted on Cloudflare Worker infrastructure (at the domain core.trystatly.com).

The Installation Identifier is a randomly generated UUID created on first use and stored locally. It is not linked to your name, email address, social-media account, or any other identifying information.

To prevent circumvention of these limits, the scan-counting service also processes your IP address and temporarily stores IP-derived data in Cloudflare's key-value storage. Specifically, it stores: a per-IP daily scan counter, and a binding between your IP address and the first Installation Identifier seen from that IP on a given day. This IP-derived data is associated with a calendar date and is automatically deleted within a few days.

The service additionally inspects the network provider (autonomous system number) associated with a request to apply stricter limits to traffic originating from commercial VPN or datacentre networks; this inspection is part of the rate-limiting logic and is not stored as a separate profile.

4.3 Anonymous Usage Analytics (All Users)

To improve the product and to measure the effectiveness of our own advertising, the extension records anonymous usage events tagged only with the Installation Identifier and a timestamp. The events recorded are:

  • when the extension is first installed and initialised;
  • when the extension dashboard is opened;
  • which features and dashboards are used (for example, that a scan was run on the Audit dashboard, or that Trend Finder was opened);
  • whether a licence has been activated;
  • when the extension is uninstalled.

What is not sent: the content of your scans, the profile handles or accounts you look up, the analytics numbers computed for those accounts, and any personally identifying data.

Events are sent over HTTPS to an endpoint on our own infrastructure (Cloudflare Workers, at the domain core.trystatly.com). We do not use Google Analytics, Segment, Mixpanel, Amplitude, PostHog, tracking pixels, advertising SDKs, or any other third-party analytics library inside the extension. We do not sell, rent, or share this data with any third party.

4.4 Install Source Attribution

When you visit our website (trystatly.com), if you arrived through one of our advertising campaigns (for example a Google Ads link), the website records this fact in your browser's local storage. Concretely, we store a short marker such as "google_ads" together with a campaign identifier. This marker does not leave your browser at that stage.

If you then install the extension, the marker is read once during first-run initialisation and sent, together with the anonymous Installation Identifier, to our own server (Cloudflare Workers). This lets us determine, in aggregate, how many installations came from each of our advertising campaigns (for example, "X installations came from Google Ads campaign Y last week").

We do not link this data to your name, email address, or social-media account. The marker is deleted from local storage after use.

4.5 Local Storage (All Users)

The extension stores the following data locally in Chrome's extension storage on your device:

  • Licence key (paid users only) and subscription status, tier, and last verification timestamp
  • Installation Identifier (anonymous UUID, no personal information)
  • Scan date and daily scan count (resets each local calendar day)
  • Scan results (the public analytics fetched during your scans across Instagram, TikTok, X, and Reddit)
  • Watchlist accounts you choose to track, together with the folders and tags you create to organise them
  • Trend Finder niches and their associated scan results
  • Saved-posts library (posts and short-form videos you have bookmarked, with their associated public analytics)
  • Recent-scan history
  • Your transcription API key, if you have entered one, and the transcripts and video descriptions produced with it (Section 4.12)
  • User-interface preferences and settings (for example dark mode)

All of this data remains on your device. Where you are a Pro user with cloud sync enabled (the default), a copy of the watchlist, Trend Finder, saved-posts library, transcripts, and transcription API key is additionally stored on our infrastructure as described in Section 4.8. Local data is automatically deleted when you remove the extension from your browser.

4.6 Payment Information

Payments for paid subscriptions are processed by Lemon Squeezy. Lemon Squeezy operates as Merchant of Record, meaning the legal transaction takes place directly between you and Lemon Squeezy, not between you and us. Lemon Squeezy is responsible for collecting and processing all payment data, including card details and billing information, which we do not receive, process, or store. See lemonsqueezy.com/privacy for their privacy policy.

As part of licence fulfilment, Lemon Squeezy transmits limited data to us, specifically a transaction identifier and subscription status, solely for the purpose of generating and activating a licence key. On our side, we store only the licence key and the associated Installation Identifier once activation occurs. We do not independently store customer transaction records.

4.7 Email Support Communications

If you contact us by email, we will process the information you provide, including your email address and the content of your message, for the purpose of responding to your enquiry. We do not use this information for any other purpose, and we do not share it with third parties. Email correspondence is retained for as long as reasonably necessary to resolve your enquiry.

In-extension bug reports. The extension includes a form for reporting problems. When you choose to send a report, the extension transmits to our endpoint at mcp.trystatly.com: your message, the reply email address you enter (optional), any files you attach (up to five files, 10 MB in total), the platform and extension version, and your browser's user-agent string. If you have a licence key, it is sent too, so that we can look up the email address and plan status associated with your purchase and reply to you; the key itself is not included in the email we receive. The report is delivered to our support inbox as an email via Resend (Section 8). To prevent abuse, the endpoint keeps a count of reports per licence key or, where there is no key, per IP address; these counters expire automatically within about a day.

4.8 Cloud Sync for Pro Users (Optional)

If you hold an active Pro subscription, the extension offers cross-device synchronisation of certain content. When cloud sync is enabled (this is the default for Pro users, and can be turned off at any time from the Settings tab), the extension transmits the following content to a sync endpoint hosted on Cloudflare Worker infrastructure (at the domain sync.trystatly.com):

  • Your watchlist (the Instagram, TikTok, X, and Reddit accounts you have chosen to track; the folders and tags you have created; and the public analytics that have been fetched for those accounts)
  • Your Trend Finder data (the niches you have created, the accounts assigned to each niche, and the public analytics fetched for those accounts)
  • Your saved-posts library (the posts and short-form videos you have bookmarked, with their associated public analytics)
  • Transcripts and video descriptions you have generated (Section 4.12), and your transcription API key, so that transcription works on your other devices without entering the key again. Your API key is never delivered to viewer keys (Section 4.9)
  • Scan-related settings, such as scan windows and speed preferences

This content is stored on our infrastructure in Cloudflare's key-value storage, keyed by your licence key. It is used solely to provide the sync feature, so that activating the same licence key on another device retrieves the same content. We do not analyse, profile, or commercially exploit this content.

Before allowing sync operations, our sync service verifies with Lemon Squeezy that the supplied licence key is currently active. As with all Cloudflare-handled requests, your IP address and standard connection metadata are processed by Cloudflare as part of delivering the request.

You can disable cloud sync at any time in the Settings tab. Disabling sync stops new uploads from your device. Data already stored on our infrastructure is retained until you request deletion (Section 11) or until your licence has been inactive for an extended period, after which it may be removed.

4.9 Team Viewer Seats for Pro Users (Optional)

As a Pro user, you may optionally create one or more viewer keys that grant read-only access to your synced content (your watchlist, Trend Finder niches, and saved-posts library) to teammates you choose to invite. Viewer keys are randomly generated by the extension and are stored, alongside the licence key that issued them, on our infrastructure at sync.trystatly.com.

A teammate presenting a valid viewer key can retrieve your synced content in read-only mode. Viewer keys cannot modify, delete, or add anything, and they cannot access the underlying licence key, your transcription API key, or trigger scans on your behalf.

You can revoke any viewer key at any time from the extension's Settings tab; revoked keys stop working immediately. If your Pro subscription ends, viewer keys stop working automatically.

4.10 Statly API (Optional)

Statly includes an optional API that lets Pro users request profile scans and retrieve public analytics for Instagram, TikTok, X, and Reddit programmatically. When you submit a request, our endpoint at api.trystatly.com queues it as a job; the scan itself is carried out by your own Statly extension, in your own browser, which picks up the job and sends the results back to the endpoint so they can be returned to you. To route jobs to the right browser, the extension sends a periodic signal that it is online.

To operate the API, we store: your API key and the licence key it belongs to; a monthly request counter; the job records you create, including the requested profile and the returned public analytics, which expire automatically within 72 hours; and short-lived "online" signals, which expire within a day. Use of the API is entirely at your initiative; if you do not use it, no such requests are made.

4.11 AI-Assistant Connection (MCP) for Pro Users (Optional)

As a Pro user, you may connect an AI assistant of your choice (for example Claude or ChatGPT) to your Statly data through our MCP server at mcp.trystatly.com. To connect, you enter your licence key or a viewer key on a Statly sign-in page; the assistant then receives an access token that works only for reading your data and can be revoked.

The MCP server does not store your analytics. Each request is forwarded to our sync service (Section 4.8), which re-checks your licence, and the result is passed to your assistant. The MCP server stores only: registered assistant clients (90 days), one-time sign-in codes (10 minutes), access tokens (30 days), refresh tokens (1 year), short-lived links to post images (1 hour), and, where you ask your assistant to transcribe a post, a temporary job record that your extension picks up (1 hour).

Content your assistant retrieves is then processed by the provider of that assistant under its own terms and privacy policy. We do not control how that provider handles it.

4.12 Transcription and Video Descriptions (Optional)

Statly can transcribe the speech in a video and describe what the video shows, on Instagram, TikTok, X, and Reddit. This feature is off until you enter your own API key from a transcription provider (Groq or OpenAI).

When you transcribe a video, the extension downloads its audio in your browser and sends it directly from your browser to the transcription provider, authenticated with your API key. For video descriptions, a small number of still frames from the video are sent in the same way. This data does not pass through our servers. The provider processes it under its own terms and privacy policy, as an independent service you have chosen to use: see groq.com/privacy-policy and openai.com/policies/privacy-policy.

Your API key and the resulting transcripts and descriptions are stored locally (Section 4.5) and, if you are a Pro user with cloud sync enabled, in your synced content (Section 4.8). You can remove your API key at any time from the extension's Settings.

4.13 Your Account in the Web App

The web app requires an account, so unlike the extension it knows who you are. Signing in is by email link: you enter your address, we email you a single-use link, and following it creates a session. We hold:

  • Your email address, stored in lowercase. It is the account's identity and the address we send sign-in links and service notices to.
  • Sign-in links, of which we store only a one-way SHA-256 hash of the link's token, its expiry, and a one-way hash of the IP address that requested it. The link itself is never stored, and a used or expired link cannot be reused.
  • Sessions: an identifier, the times it was created and expires, the browser's user-agent string, and a one-way hash of the IP address. Keeping session records server-side is what lets a session be revoked.
  • Rate-limit counters on the sign-in endpoint, so a single address cannot be used to send unlimited email.

We do not store your IP address in readable form anywhere in the web app. Cloudflare, as our infrastructure provider, necessarily receives it in order to deliver the request (Section 8).

4.14 What You Create in the Web App

  • The accounts you track, the niches you sort them into, and the names and colours you give those niches.
  • Your Library: the reels you save, the folders you file them in, and the tags you write on them.
  • Your settings: the scan window, the hour your data is ready, and your workspace's timezone.
  • Your workspaces, their names, and who is in them.

4.15 Teams and Invitations

An account owner can invite other people into a workspace as a viewer, an editor or a full member. To do that we store the email address invited, the role offered, who sent the invitation, and when it was created, accepted or revoked; once accepted, the member's account identifier, role and email address are held against that workspace.

What this means in practice, said plainly: the owner of a workspace can see the email addresses of the people in it, and everything the workspace tracks and saves. If you join somebody else's workspace, you are working inside their account and they can see that work. Your own account, your own workspaces and your own plan remain yours alone.

4.16 Subscription Data in the Web App

When you subscribe, Lemon Squeezy remains the Merchant of Record and we still never see your card (Section 4.6). What we store against your account is limited to the identifiers and state we need in order to know what you are entitled to: a customer identifier, a subscription identifier, which plan variant you bought, the status of the subscription, the end of any trial, and the renewal or end date. We also keep a one-way hash of your email address in a separate record used for one purpose only: to prevent the same address taking a second free trial.

4.17 Creator Data Collected by the Web App

This section concerns people who are not our customers. When a customer asks the web app to track a public Instagram, TikTok or YouTube account, our servers read that account's public short-form videos roughly once a day and store:

  • the account's handle and its public numeric identifier;
  • its follower count and profile picture;
  • for each public reel: the reel's code, when it was posted, its view, like and comment counts, its duration, its thumbnail and video links, and the sound it used;
  • a history of those counts, so a reel's growth can be shown. We keep the most recent readings of each reel and thin the rest.

All of this is content Instagram shows publicly to anyone, signed in or not. We collect no private information, nothing from a private account, no followers list, no comments text, and nothing at all about the people who watch or like a reel. We do not attempt to identify anyone, build profiles of individuals beyond the public performance of their public posts, or make any decision about anybody.

We stop collecting as soon as no customer tracks the account, and what we hold is then deleted as described in Section 9. A creator who wants us to stop sooner can write to us: see Section 11.

5. What We Do Not Collect

For the avoidance of doubt, we do not collect, process, or store any of the following:

  • Login credentials, passwords, private messages, direct messages, or authentication tokens for any social platform
  • Browsing history, or any activity of yours outside the scans and dashboard actions you explicitly perform
  • Behavioural profiles of any individual user
  • Data via Google Analytics, tracking pixels, advertising SDKs, or third-party analytics libraries inside the extension
  • Cookies used for tracking or profiling
  • Your social-media passwords, your Instagram session, or any access to your own social accounts. The web app never asks you to connect an Instagram account and could not act as you if it wanted to
  • Any information that identifies you personally beyond what is described in Section 4

Google Ads is used only on our public website (trystatly.com), and only to measure the effectiveness of our advertising campaigns in aggregate. Google Ads is never embedded in the Chrome extension.

In the extension, the public analytics you generate are processed on your device. Where you have enabled cloud sync as a Pro user, a copy of that content is stored on our infrastructure solely to provide the sync feature, as described in Section 4.8. Where you use transcription, video audio and frames are sent to the transcription provider you chose, as described in Section 4.12.

In the web app, the collection is the point of the product and it does happen on our servers, as Sections 3.2 and 4.17 describe. Even so, it is limited to publicly visible content about the accounts a customer has chosen to track. We do not collect anything from a private account, the text of comments, the identity of the people who watch, like or comment on a reel, or anything at all about a creator that Instagram does not show a signed-out visitor.

We do not sell, rent, or share any data with third parties for advertising, marketing, or profiling purposes.

6. Legal Basis for Processing

We process personal data only to the extent described in Section 4. The applicable legal bases under Article 6 GDPR are as follows:

Contractual necessity (Article 6(1)(b) GDPR). Transmission of the licence key, provision of cloud sync (where enabled), viewer-seat functionality, the Statly API, the AI-assistant connection, and transcription at your request are necessary to provide the features you have chosen to use. In the web app, the same basis covers your account and sign-in (Section 4.13), the niches, tracked accounts and Library you create in it (Section 4.14), workspace membership (Section 4.15), and the subscription record that says what you are entitled to (Section 4.16). Without them there is no service to give you.

Legitimate interests (Article 6(1)(f) GDPR). The following processing is based on our legitimate interests, balanced against your rights and freedoms:

  • Transmission of the anonymous Installation Identifier and the temporary processing and storage of IP-derived data for scan counting and abuse prevention (Section 4.2): operating a commercially sustainable free tier and preventing 7-day-trial resets. In the web app, the same interest covers the hashed IP addresses and rate-limit counters on sign-in (Section 4.13), which exist to stop our email being used to send mail somebody did not ask for.
  • Anonymous usage analytics (Section 4.3): improving the product and measuring advertising effectiveness in aggregate. Only an anonymous Installation Identifier is used; no real-world identity is linked to these events.
  • Install source attribution (Section 4.4): measuring, in aggregate, which advertising campaigns drive installations. Data is not linked to any real-world identity.
  • Processing of email correspondence and bug reports (Section 4.7), including rate-limiting of bug reports: responding to user communications, fixing problems, and preventing abuse of the report form.
  • Collection of creator data by the web app (Section 4.17): providing the competitive-analytics service our customers have asked for, over content its authors chose to publish to the world. The processing is limited to what is publicly visible; we take nothing private, draw no conclusion about the person behind an account beyond the public performance of their public posts, make no automated decision about them, stop as soon as no customer tracks them, and honour objections as described in Section 11.
  • Keeping a one-way hash of an email address after an account is deleted (Section 4.16), and the cost ledgers described in Section 9: ensuring one address cannot take repeated free trials, and keeping an accurate record of what our own data provider was asked to fetch.

You have the right to object to processing based on legitimate interests at any time. To do so, please contact us at info@trystatly.com.

7. Automated Decision-Making

We do not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects you, within the meaning of Article 22 GDPR. Licence verification, scan counting, rate limiting, anonymous usage analytics, install source attribution, cloud sync, viewer-seat access, the Statly API, the AI-assistant connection, and transcription are technical operations and do not involve any assessment of your personal characteristics or circumstances.

8. Third-Party Services and Data Processors

We rely on the following third-party services:

Cloudflare, Inc. Provides the network infrastructure that hosts our Worker endpoints (core.trystatly.com, sync.trystatly.com, api.trystatly.com, mcp.trystatly.com), the whole of the web app at app.trystatly.com together with the databases behind it, and delivers our website. In the course of delivering any request, Cloudflare processes standard connection metadata, including IP addresses. Cloudflare acts as a data processor on our behalf. Privacy policy: cloudflare.com/privacypolicy.

Lemon Squeezy. Provides payment processing and acts as Merchant of Record for all paid subscriptions. Lemon Squeezy is the seller of record and processes all payment-related personal data (card details, billing information) as an independent controller for that purpose. Privacy policy: lemonsqueezy.com/privacy.

Google Ads (Google LLC). Used exclusively on our public website (trystatly.com) to measure the effectiveness of our advertising campaigns. Google Ads is not embedded in the Chrome extension. Privacy policy: policies.google.com/privacy.

Resend. Delivers our email: the bug reports you send from the extension to our support inbox, and, for the web app, your sign-in links, your team invitations and service notices about your account. To send them, Resend processes your email address and the content of the message on our behalf, as a data processor. Privacy policy: resend.com/legal/privacy-policy.

ScrapeCreators. The data provider the web app uses to read public content from the Instagram, TikTok and YouTube accounts our customers track (Sections 3.2 and 4.17). We send it the handle or public account identifier to read, and nothing else: not your email address, not your Statly account identifier, not your IP address. It returns public short-form videos and their public counts. Nothing about you reaches it, and it plays no part in the Chrome extension.

Groq, Inc. and OpenAI, L.L.C. Transcription providers you may choose to use (Section 4.12). The extension sends video audio and frames to them directly from your browser under your own API key and your own account with that provider; they are not our processors, and they process that data under their own terms. Privacy policies: groq.com/privacy-policy, openai.com/policies/privacy-policy.

We do not use any other third-party analytics service, advertising SDK, or tracking library inside the extension or the web app.

9. Data Retention

  • Local data on your device (licence key, subscription status, Installation Identifier, watchlist, folders, tags, Trend Finder niches, saved-posts library, recent scans, settings): retained on your device for as long as the extension is installed, and automatically deleted on uninstall. We do not hold copies of locally-stored data on our own servers, except for the cloud-sync copy described below.
  • IP-derived scan-counting data (Section 4.2): automatically deleted within a few days.
  • Anonymous usage events (Section 4.3): retained in aggregated form for as long as they remain useful for product improvement and campaign measurement. Individual events are keyed only by Installation Identifier and are not linked to any real-world identity. You may request deletion of events associated with your Installation Identifier by contacting us.
  • Install source markers (Section 4.4): deleted from local storage on the website once sent, together with the Installation Identifier, to our server. The aggregate campaign-attribution record on our server is retained for the life of the associated campaign.
  • Cloud-synced content (Section 4.8) and viewer keys (Section 4.9): retained on our infrastructure for as long as the associated licence remains active and the user continues to use the sync feature. Users may request deletion at any time by emailing info@trystatly.com. Content associated with licences that have been inactive for an extended period may be removed at our discretion.
  • Email correspondence and bug reports (Section 4.7): retained for as long as reasonably necessary to address your enquiry or fix the reported problem, after which they are deleted. Bug-report rate-limit counters expire automatically within about a day.
  • Statly API data (Section 4.10): job records expire within 72 hours; the monthly request counter within about 35 days; your API key for as long as it remains in use, up to one year after it was last issued.
  • AI-assistant connection data (Section 4.11): sign-in codes 10 minutes, image links and transcription job records 1 hour, access tokens 30 days, registered clients 90 days, refresh tokens 1 year.
  • Transcription data (Section 4.12): we do not receive the audio or frames you send to your transcription provider. Transcripts, descriptions, and your API key are kept on your device and, where cloud sync is enabled, with your synced content.
  • Payment records: Lemon Squeezy retains transaction data in accordance with its own legal and regulatory obligations and privacy policy.

9.1 The Web App

  • Sign-in links (Section 4.13): the stored hash expires within minutes and is removed once used or expired. Sessions expire on their own and are deleted when you sign out or delete your account.
  • Your account and everything in it (Sections 4.14 to 4.16): kept for as long as your account exists.
  • After you cancel a subscription: your account, your niches and your Library are kept for 60 days, so that resubscribing picks up where you left off. After that we may delete the workspace's contents. You can delete everything immediately yourself at any time, without waiting.
  • When you delete your account: your tracked accounts, niches, Library, folders, tags, workspaces, team memberships, invitations, settings and plan record are deleted at once, and your sign-in is deleted with them. Two things deliberately survive, and we would rather say so than claim otherwise: a one-way hash of your email address, so the same address cannot take a second free trial, and our internal cost ledgers, which record how many requests were made to our data provider against an account identifier that no longer belongs to anyone. Neither contains your email address, your name, or anything you created.
  • Creator data (Section 4.17): kept for as long as at least one customer tracks that account. Once nobody does, the account's reels, reading history, profile row and scan record are deleted automatically by a nightly clean-up. A reel that a customer has saved to their Library is kept until they unsave it or delete their account.
  • Reading history: we keep only the most recent readings of each reel, about a week's worth, and thin the rest nightly.

10. International Data Transfers

The licence-verification, scan-counting, usage-analytics, install-attribution, API, and cloud-sync endpoints, and the whole of the web app including its databases, are delivered through Cloudflare's global network. Because Cloudflare operates data centres across multiple jurisdictions, including outside the European Economic Area (EEA), routing a request through Cloudflare's infrastructure may constitute a transfer of personal data (specifically, connection metadata, the short-lived IP-derived rate-limiting data described in Section 4.2, the anonymous usage events described in Section 4.3, and the cloud-synced content described in Section 4.8) to third countries within the meaning of Chapter V GDPR.

Cloudflare relies on appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) adopted pursuant to Article 46 GDPR. Details are available at cloudflare.com/privacypolicy.

Bug reports are delivered by Resend, which may process them outside the EEA, under the transfer safeguards described in its own privacy policy. If you use transcription, the audio and frames you send go to the provider you chose (Groq or OpenAI), both based in the United States, under your own agreement with that provider.

Payments are processed by Lemon Squeezy, which may also operate infrastructure outside the EEA. Its own privacy policy describes the applicable transfer safeguards.

Google Ads, used only on our public website, may transfer aggregated advertising-measurement data outside the EEA. Google's own privacy policy describes the applicable safeguards.

11. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to object (Article 21), including objection to processing based on legitimate interests: the anonymous usage analytics and install source attribution described above, and, for creators, the collection described in Section 4.17
  • Right to data portability (Article 20)
  • Right to withdraw consent, where processing is based on consent
  • Right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at dpa.gr

To exercise any of the above rights, contact info@trystatly.com. We will respond within one month as required by Article 12 GDPR.

11.1 If you use the extension

Most data resides on your device; the most effective way to delete locally-stored data is to uninstall the extension. To delete cloud-synced content, viewer keys, API data, or AI-assistant access, please email us with the licence key for which deletion is requested. To delete anonymous usage events, please email us with the Installation Identifier for which deletion is requested. You can find the Installation Identifier in the extension's Settings tab.

11.2 If you use the web app

You do not have to write to us for the two that matter most. Settings → Danger zone lets you delete your account and everything in it yourself, at any time, and every table in the app has an Export button that writes what you see to a CSV file, which is portability under Article 20. For anything else, including access to what we hold or correction of it, email us.

11.3 If you are a creator we hold data about

You may be reading this because you found Statly holding public data about your Instagram, TikTok or YouTube account, without ever having been our customer. You have the same rights as anybody else, and you do not need an account with us to use them.

Write to info@trystatly.com from an address connected to the account, or tell us how else to verify it, and say what you want:

  • To see what we hold about your account: we will send it.
  • To object to the processing (Article 21) or to have it erased (Article 17): we will delete the reels, readings, profile row and scan record we hold for your account, and add it to a list our scanners will not read again, so that no customer can re-add it. That list holds nothing but the handle.

We will do this without arguing the point, and we will not tell you which of our customers was tracking you, because that would trade your privacy for theirs. We will respond within one month, as Article 12 requires.

12. Children's Privacy

Statly is not directed at, and is not intended for use by, individuals under the age of 16. We do not knowingly process personal data relating to children under 16.

13. Security Measures

We apply the following technical measures:

  • All transmissions between the extension and our endpoints are protected by HTTPS (TLS) encryption in transit
  • The extension is designed on a data-minimisation principle
  • The Installation Identifier is a randomly generated UUID with no link to any personal identifier
  • In the web app, sign-in links are stored only as a one-way SHA-256 hash and are single-use; IP addresses are stored only as a one-way hash; sessions are recorded server-side so that they can be revoked; and the session cookie is HttpOnly and signed
  • Every request in the web app is checked against the account it claims, and against the workspace it names, before any data is returned
  • IP-derived rate-limiting data is short-lived and automatically deleted
  • Cloud-synced content is keyed to the user's licence key and is only accessible by requests presenting that key or a valid viewer key associated with that licence
  • Viewer keys grant read-only access and can be revoked at any time
  • Local storage uses Chrome's sandboxed extension storage, inaccessible to other extensions or websites
  • No third-party analytics or advertising SDKs are embedded in the extension

No method of transmission or storage over the internet can be guaranteed to be completely secure. Statly's architecture is designed to minimise the volume and sensitivity of data processed, reducing risk proportionately.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be reflected by an updated effective date at the top of this document. Where the changes are material, we will seek to notify users via the Chrome Web Store listing or another appropriate channel.

Questions about anything above? Email info@trystatly.com.