Privacy notes
These notes describe the implementation; they do not promise complete anonymity or zero logging.
Updated 7 October 2026 · Implementation and access limits
Official contact: support@privpeek.com
Operator and contact
Operator: PrivPeek.
For support, privacy, terms or content-rights enquiries, use the official contact email below.
Before launch, the operator must confirm operating jurisdiction, hosting regions, log retention and privacy-request procedures. These facts have not been supplied.
Search processing
The normalized public handle is sent to Instagram in a logged-out public-page request from the server. No Instagram credentials or visitor IP are forwarded by application code. Search handles appear in result URLs and may be retained by browser history and hosting logs.
Preview processing
Profile and media previews use a same-origin proxy to allowlisted Instagram CDN hosts. The server fetches those files; no remote tracking SDK is configured. Opening an original source or external biography link contacts that destination directly.
Abuse prevention
Production retrieval and media requests require shared Upstash counters using an HMAC of the trusted Vercel client IP. Redis keys contain no raw IP or handle. Counters expire after the configured window, normally 60 seconds. Requests fail closed if these protections are unavailable. Local development uses bounded process-local limits.
Caching
Profile and media JSON may be cached in process memory: profile 15 minutes, posts and reels 10 minutes by default, bounded to 5,000 entries. This cache is not shared across serverless instances. TTL is enforced on access or pruning; expired entries can remain in memory until pruned or the process ends. The viewer entry request directly retrieves data; it does not use the chain cache. API JSON uses no-store. Preview responses permit private browser caching for five minutes. No search-history database is configured.
Analytics and logging
Application code does not deliberately persist search history or log responses, credentials or tokens. Prepared local events contain only an event name and mode. No GA4 identifier or external analytics destination, tracking cookies or browser-storage history is configured. Hosting, Instagram and Upstash have their own logging and retention; the operator must review them.