Last updated: 2026-07-28
Creator Scout is local-first: your workspace lives in your own browser, and discovery and messaging run through your own Instagram session. We never receive your Instagram password or session cookies. There are two exceptions, both set out below: the AI features, which send specific text to our server and on to our AI provider, and the optional cross-device contact sync, which is off unless you switch it on.
Everything you create — discovered profiles, outreach settings, contact history, notes, deal values and daily send counts — is stored in your browser's local storage on your own device. We hold no copy and no account database. Clearing your browser data, or using "Clear local workspace", permanently removes it. Exporting a workspace writes a file to your machine only.
When you use an AI feature, the relevant text is sent to our function and forwarded to our AI provider (OpenAI) to generate a response. It is not used to train models, is not sold, and we do not retain it beyond producing the answer. Specifically:
If you never use an AI feature, none of the above leaves your browser.
If you turn on Share contacted creators across my devices (Settings → Workspace), the app keeps a shared list so the same creator isn't messaged twice from different browser profiles or machines. This is the only setting that causes anything about creators to leave your browser.
What is sent: a one-way fingerprint of each contacted creator's handle — a truncated SHA-256 hash — together with the name you gave the workspace that contacted them. Usernames are not sent. Deduplication only needs to ask "have we contacted this person", never to read the name back, so the hash is enough and we store nothing readable. The workspace name is sent as-is, because it is your own label and without it the duplicate warning cannot tell you which client was involved.
What we can see: a list of hashes and your workspace names, associated with the email on your license. We cannot read the creator handles from the hashes. We want to be straight about the limit of that protection: Instagram handles are short and predictable, so someone with the hashes could test guesses against them. Hashing removes casual and incidental exposure — it is not protection against a determined attacker.
Turning it off stops any further sending immediately. To delete what has already been stored, email us and we will remove the record for your license.
Our AI and support-chat functions record your IP address in short-lived rate-limit counters, to stop abuse from exhausting shared capacity. These counters hold a per-IP request count and a date. They are not linked to your workspace, are not used for analytics or advertising, and expire automatically.
If you buy a licence, our payment processor (Stripe) handles the transaction and we receive the billing email in order to issue and email your key. We never see your card details.
The companion extension uses browser permissions to open and read public web pages (Google search results, public Instagram profiles and hashtag pages) and to prepare and send messages from the Instagram account you are already logged into. Reading profile and inbox data uses the same requests Instagram's own website makes, authenticated by your existing session — we never receive that session, and it stays in your browser.
It acts when you start a discovery run, send a message, check for replies, or run a warm-up. It also reads a small public configuration file from our hosting domain so selector changes on Instagram can be fixed without an extension update; that request contains no personal data. Reply checking reads who sent the most recent message in each conversation in order to mark creators as replied — it does not read, store or transmit message contents.
Creator Scout interacts with Google and Instagram through your own browser session, subject to those companies' own terms and privacy policies. We have no affiliation with, and are not endorsed by, Google or Meta/Instagram. Our AI features use OpenAI as a processor; payments are handled by Stripe; hosting and functions run on Google Firebase.
Discovery collects publicly visible information about creators — handle, display name, bio, follower counts, public post captions and any business email a creator has chosen to publish in their bio. You are the controller of that data in your workspace: keep it only as long as you need it, honour any request from a creator to be removed, and use the app's delete and archive controls to do so.
If what we send or log changes, this page changes with it and the date above is updated.
Questions? Email support@ideaequity.ai.