Privacy Policy
Last updated: March 7, 2026
1. Introduction
SpyReels ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our Service. By using SpyReels, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and authentication credentials through our OAuth provider. We do not store passwords directly.
2.2 Usage Data
We automatically collect information about how you use the Service, including:
- Features used and frequency of use (scrapes, transcriptions, script generations)
- Pages visited and time spent on the Service
- Device information (browser type, operating system)
- IP address and approximate location (country/region level)
2.3 Content You Create
We store scripts, notes, saved reels, and other content you create or save within the Service. This content is associated with your account and is necessary to provide the Service.
2.4 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number, CVV, or expiration date. We may store your Stripe customer ID and subscription status for billing management.
2.5 Third-Party Content
When you use our scraping and transcription features, we temporarily process publicly available Instagram content. This content belongs to the original creators and is processed solely to provide you with the requested analysis.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process payments and manage your subscription
- Send important service notifications (billing, security, feature updates)
- Enforce our Terms of Service and prevent abuse
- Analyze usage patterns to improve the product (aggregated, anonymized data)
- Respond to your support requests
We do not sell your personal data to third parties. We do not use your content to train AI models. We do not share your data with advertisers.
4. Data Storage and Security
Your data is stored on secure, encrypted servers. We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) and at rest
- Secure authentication via OAuth
- Regular security audits and monitoring
- Access controls limiting employee access to user data
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. You are responsible for maintaining the security of your account credentials.
5. Data Retention
We retain your account data and content for as long as your account is active. Upon account deletion:
- Your personal data will be deleted within 30 days
- Your scripts, saved reels, and other content will be permanently removed
- Anonymized, aggregated usage data may be retained for analytics purposes
- Billing records may be retained as required by law (typically 7 years)
6. Third-Party Services
We use the following third-party services that may process your data:
- Stripe — Payment processing. Subject to Stripe's Privacy Policy
- Manus OAuth — Authentication. Used for secure sign-in
- Analytics — Anonymous usage tracking to improve the Service
7. Cookies
We use essential cookies to maintain your session and authentication state. We do not use tracking cookies for advertising purposes. Our analytics service may use cookies to collect anonymized usage data.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your personal data and account
- Export — Export your data in a machine-readable format (available via CSV/Google Sheets export)
- Objection — Object to processing of your personal data for certain purposes
- Restriction — Request restriction of processing in certain circumstances
To exercise any of these rights, contact us through the in-app support channel. We will respond within 30 days.
9. Children's Privacy
The Service is not intended for users under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.
11. Chrome Extension
The SpyReels Chrome Extension operates on instagram.com to provide feed sorting, transcription, and content saving features. The extension:
- Reads public Instagram page content — to detect Reels, extract engagement metrics (views, likes, comments), and display sorting controls. No private or direct message content is accessed.
- Stores preferences locally — sort order, theme settings, and cached data are saved in your browser's local storage using the Chrome Storage API.
- Sends data to SpyReels servers — when you use Transcribe or AI Re-Create features, the Reel URL is sent to spyreels.ai for server-side processing. No personal data, browsing history, or Instagram credentials are transmitted.
- Does not execute remote code — the extension communicates with our API via JSON data responses only. No external JavaScript is loaded or executed.
- Does not track browsing activity — the extension only activates on instagram.com and does not monitor activity on other websites.
The extension requires the following permissions: activeTab (to read the current Instagram page), storage (to save preferences), sidePanel (to display the sorting panel), and host permissions for instagram.com (to inject overlay buttons and sorting controls).
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us through the in-app support channel. We aim to respond to all privacy-related inquiries within 30 days.