Privacy Policy

PostHeap  ·  Last updated: July 11, 2026

Overview

PostHeap is a personal library tool that syncs your Instagram saved posts into your own PostHeap account. This policy explains what data the Chrome extension and web app collect, how it is used, and how it is stored.

The short version: your data goes to your account and nowhere else. Nothing is sold, shared with third parties, or used for advertising.

PostHeap is an independent tool and is not affiliated with, endorsed by, or sponsored by Instagram or Meta Platforms, Inc. Instagram is a trademark of Meta Platforms, Inc.

What data is collected

Instagram saved post metadata. When you use the extension, it reads the saved-posts data that Instagram already delivers to your browser as you browse. This includes: media URLs, captions, post timestamps, and the author's public handle for each post you have saved. No Instagram credentials, passwords, direct messages, follower lists, or any other Instagram data are accessed.

PostHeap session token. After you click "Connect Extension" in the PostHeap dashboard, your Supabase access token (a short-lived authentication credential) is passed to the extension and stored locally on your device using chrome.storage.local. This token is used to authenticate API calls to your own PostHeap account — it is never shared with any third party.

Sync counters. The extension stores a count of how many posts have been synced in the current session. This is stored locally on your device only.

How data is stored

All extension data (auth token, sync state, counters) is stored locally on your device using chrome.storage.local. This data is not synced to Google's servers — chrome.storage.sync is not used.

Saved post data is transmitted to postheap.vercel.app/api/ingest (your own PostHeap account) and stored in your personal Supabase database. You own this data and can delete it at any time from the PostHeap dashboard.

How data is used

Captured saved post metadata is used solely to populate your personal PostHeap library so you can search, browse, and manage your Instagram saves. It is used for no other purpose.

The PostHeap session token is used solely to authenticate requests to your own account's API endpoint. It is not transmitted to any server other than postheap.vercel.app.

Third-party services

PostHeap uses Supabase for database storage and authentication. Your post data and account credentials are stored in a Supabase project. See Supabase's Privacy Policy.

PostHeap uses Vercel to host the web application. See Vercel's Privacy Policy.

No analytics, advertising, or tracking services are used. No data is shared with any other third party.

Data sharing

Your data is not sold, rented, or shared with any third party. Post data is transmitted only to your own PostHeap account endpoint. The extension does not communicate with any server other than Instagram (to read your own saved feed) and postheap.vercel.app (your own account).

Data retention and deletion

Saved post data is retained in your Supabase database for as long as your account exists. You can delete individual posts or your entire library at any time from the PostHeap dashboard.

Local extension data (token, counters) is cleared when you uninstall the extension or disconnect your account from the popup.

Changes to this policy

If this privacy policy changes materially, the "Last updated" date at the top will be updated. Continued use of the extension after a policy change constitutes acceptance of the updated policy.

Contact

Questions about this privacy policy? Email devbysagar@gmail.com.