Privacy Policy
Effective date: 21 July 2026
Who we are
Simpleembed ("we", "us") provides a service at simpleembed.com that lets website owners connect Instagram professional accounts and display their posts as embeddable feeds on other websites. Questions about this policy: emvaernes@gmail.com.
Data we collect
Account data. When you create an account we store your email address, a display name if you provide one, and your workspace settings (plan, feeds, and their configuration).
Instagram data.When you (or a client using your auth link) connect an Instagram professional account, we receive from the Instagram API, with your explicit approval on Instagram's consent screen: the account's username and app-scoped ID, an access token, and the account's media (post images/video thumbnails, captions, permalinks, timestamps). We do not receive your Instagram password.
Billing data. If you upgrade to a paid plan, payment is processed by Stripe. We store only your Stripe customer and subscription identifiers — never card numbers.
Cookies. We use a single first-party session cookie to keep you signed in, and a short-lived cookie to secure the Instagram connection flow. We do not use advertising or cross-site tracking cookies.
How we use data
We use the data above solely to operate the service: rendering your feeds as embeds and JSON, keeping posts in sync on a schedule, serving post images through our proxy so embeds keep working, and managing your account and billing. Instagram data is used in accordance with the Meta Platform Terms. We do not sell personal data, and we do not use your data for advertising.
Where data is stored
Data is stored in Google Firebase (Firestore and Firebase Authentication) and served through Vercel's hosting platform. Instagram access tokens are stored server-side and are never readable from the browser. Post images are fetched from Instagram's CDN and passed through our servers; embeds on third-party sites load images via our proxy.
Sharing
Feeds you create are public by design: anyone with a feed's embed URL can view its posts, images, captions, and permalinks — that is the product's purpose. We share personal data only with the processors named above (Google, Vercel, Stripe, Meta Platforms) as needed to run the service, and when required by law.
Retention and deletion
We keep your data while your account is active. You can delete individual sources (which also deletes their synced posts, stored tokens, and dependent feeds) from the dashboard at any time.
Instagram data deletion.If you remove Simpleembed's access from your Instagram account settings, Meta notifies our deletion endpoint and we delete the connected source, its access token, and all synced posts automatically. You can also email us at emvaernes@gmail.com to request deletion of your entire account and all associated data; we complete such requests within 30 days.
Your rights
Depending on where you live (including under the GDPR), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. Contact us at emvaernes@gmail.com to exercise them.
Changes
We will update this page when our practices change and revise the effective date above. Material changes will be announced in the product.