1. Scope and effective date

This policy applies to the CopyIns website and the CopyIns Chrome extension from August 13, 2026. It does not apply to Instagram, Meta, Chrome Web Store, source media hosts, or other third-party destinations.

2. Website and extension

The website accepts supported public Instagram URLs and asks a server-side parser to identify eligible media. The extension is a separate browser workflow for one eligible media item already loaded and visible on the current Instagram page.

3. Public Instagram URLs

When you submit a URL on the website, the complete normalized public Post, Reel, Carousel, or legacy IGTV URL is sent to the CopyIns parser. Do not submit credentials, cookies, tokens, private links, or personal account data.

5. Server and security data

Cloudflare hosting, network security, and request handling may process IP address, User-Agent, time, route, response status, and error information. The parser hashes IP address and User-Agent together for a bounded local rate-limit key with a 60-second logical window; expired entries are removed by later map activity or isolate termination. The raw values are not used as the local map key. Cloudflare may keep its own platform logs under the settings and retention configured for the production account.

6. Analytics, cookies, and consent

When a Google Analytics measurement ID is configured, the website loads Google Analytics with analytics storage enabled and advertising storage, ad user data, personalization, and Google signals disabled. Page reporting uses origin and path without the query string. Download events use bounded categories such as result, item count, option count, error code, item number, and quality label; they are not configured to send the submitted URL, media URL, post ID, or filename.

The locale switch uses URL paths. CopyIns does not need an Instagram cookie or login cookie. If advertising or another consent-dependent service is enabled later, the notice and controls must be updated before that use begins.

7. Extension permissions

The extension uses activeTab, downloads, scripting, storage, and https://www.instagram.com/* for the narrow current-page media workflow. The purpose of each permission is explained on the Extension page and in the Chrome Web Store disclosure.

8. Local extension storage

chrome.storage.local keeps the filename mode and media-button display preference. chrome.storage.session temporarily keeps a download ID, source tab, media type, content key, and generated filename so an interrupted download can be reported back to the original page. It is normally cleared after a terminal download event; if Chrome does not deliver that event, the record can remain until the browser session ends. The extension does not build a separate long-term download-history database, but Chrome can keep its normal download-manager history.

9. Extension data-access boundaries

The extension does not request cookie, history, identity, contacts, clipboard, all-sites, webRequest, or notification permission. Its content script locally observes the Instagram page DOM and checks visible image and video elements to decide where an eligible action can appear. A deeper, bounded MAIN-world read occurs only after a user clicks a media action. Unclicked media is not uploaded to CopyIns or persistently catalogued. The normal download path does not intentionally extract, retain, or transmit Instagram passwords, cookies, access tokens, browsing history, contacts, direct messages, or unrelated page content.

10. Optional failure feedback

After an eligible download failure, the extension may show a field preview. Only after a second explicit confirmation does it request the narrow optional permission for feedback-api.downxvideo.com and send one classified report. Chrome may retain an optional permission after it is granted; CopyIns uses it only for a user-confirmed feedback submission.

A report may include post or media ID, extension version, media type, page context, fixed error code, failure stage, evidence route, candidate count, source/status/MIME/size classes, ready/DRM state, filename mode, username shape, and browser/OS categories. It excludes full page or media URLs, signed CDN URLs, cookies, credentials, usernames, captions, filenames, page content, media files, raw exceptions, stacks, and persistent device IDs.

Raw reports containing a post ID have a 30-day logical lifetime and are deleted by the scheduled cleanup after expiry; de-identified aggregate counts are kept for at most about 90 days, and abuse-prevention IP HMAC keys for at most about 24 hours. A report ID and one-time deletion token are returned for early deletion requests. This feedback path depends on separate production DNS, database, secrets, policy, and real-world verification; if those are not deployed, no report is accepted.

11. Service providers

The production setup may use Cloudflare Pages and Functions for hosting, CDN, security, and parsing; Google Analytics only when configured; the optional shared feedback service only after explicit confirmation; Chrome Web Store for extension distribution after publication; and Instagram or its CDN as the source destination for media. No additional provider should be described as active until production configuration confirms it.

12. Sharing, sale, and advertising

CopyIns does not sell submitted Instagram URLs, media files, extension preferences, or optional failure reports. Technical data is shared only with providers needed to operate, secure, measure, or distribute the service as described here. Advertising is not enabled unless the production configuration explicitly enables it; this policy and consent controls must be updated before personalized advertising is introduced.

13. Retention and deletion

Website result cache entries stop being reusable after a 30-second logical lifetime and local rate-limit entries after a 60-second logical window; physical removal follows later in-memory cleanup or isolate termination. Browser preferences remain until the user changes them, clears extension storage, or removes the extension. Optional feedback follows the approximate 24-hour, 30-day, and 90-day limits above. For deletion or privacy questions, contact [email protected] with the report ID and deletion token when applicable. The repository shows this address in product copy but cannot verify inbox ownership or deliverability.

14. Security measures

CopyIns validates supported URL shapes, restricts media hosts, bounds request sizes and caches, applies rate limits, and rejects ambiguous extension media instead of expanding access. No internet service can guarantee absolute security.

15. International processing

Cloudflare, Google, Chrome Web Store, Instagram, and other infrastructure providers may process technical data in countries other than your own. Their safeguards and locations are governed by their own terms and the production account settings used by the operator.

16. Privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive information about personal data. Contact [email protected]. Identity and scope may need to be verified before a request is fulfilled.

17. Children

CopyIns is not directed to children who cannot lawfully consent to online services in their jurisdiction. Do not submit a child’s personal information or use the service in violation of age requirements.

19. Policy updates

Material changes will be posted on this page with a revised date. A new extension release or data path must be reflected here and in the store disclosure before release.

20. Contact

For privacy questions, deletion requests, or legal notices, email [email protected]. CopyIns is the public product name; no separate company name, postal address, or jurisdiction is claimed on this page because the repository does not contain verified operator details. Those details must be added when the operator provides them.