Privacy Policy

Privacy Policy

This policy explains what LastFollow stores, where it is stored and who else sees it. It covers the LastFollow iPhone app and the lastfollow.app website.

Last updated: September 12, 2026

Scope

LastFollow watches Instagram accounts you choose to track and tells you who started following them and who stopped. Part of that work happens on LastFollow's servers and part of it happens only on your iPhone. This policy applies to the app, to the website at lastfollow.app, and to support email sent to us.

Who you are to us

LastFollow never asks for an email address, a phone number or a name. The first time you open the app it creates a Firebase anonymous account: a random identifier with no personal details attached to it. That identifier is the key to your record on our servers, and it is how the daily check knows which results to send to your phone.

Connecting your Instagram account is optional. Tracking a public account needs no Instagram login at all. What connecting does change is described further down.

Where your information lives

LastFollow works in two different ways depending on the account being tracked, and the difference matters for your privacy. This is the part worth reading closely.

On LastFollow's servers: tracking public accounts

Tracking a public account runs on our own servers, once a day, at the hour you pick. You do not have to open the app for it to happen. A check can only tell you what changed by comparing today's list against the one from the previous check, so the previous list has to be stored. For each public account being tracked, our servers hold:

  • The tracking record: your anonymous identifier, the profile's Instagram id and username, which list is being tracked, whether it is full or count-only, how large the list is, when tracking started, when it was last checked, and whether it is still active.
  • A snapshot of that public profile's follower or following list, kept as the reference the next check is compared against.
  • The differences that came out of those comparisons: who joined and who left.
  • Up to 90 days of that profile's daily follower and following totals, which is what the charts draw.
  • Short-lived daily caches that stop the same profile being scanned twice in one day, a preview cache keyed by the username you searched during onboarding, and a daily counter of paid data requests. The counter holds no personal information.

If the list has more than 1,000 people, no names are collected at all. Only the daily total is stored, and the result you see is the rise and fall of that number over time.

A public profile's snapshot is held per profile and shared by everyone tracking it. If ten people track the same account, it is scanned once, stored once, and the difference is sent to all ten. The snapshot is a record of a public profile, not an item filed under any one person's account.

On your iPhone: your own account and private accounts

Instagram does not expose a private account's lists to anyone, and our servers cannot see them either. If you already follow that account, your own Instagram session can. So for a private account the list is read on your phone, with your own session, and the comparison runs on your phone when you open the app. Your own account works the same way: your lists are read on the device, when you open the app.

Those lists of people never reach LastFollow. For a private profile, the only thing that reaches our servers is a summary: how many people were in the list, when it was read, and how large the last change was. No names, no list of people.

The reason for holding only a summary is that this data comes from your own device rather than from LastFollow's verified scan. It is therefore never written into the shared reference that public tracking is built on.

What your user record holds

One record per user, keyed to the anonymous identifier described above. It contains:

  • The anonymous user identifier.
  • Your push notification token and whether notification permission is granted.
  • The hour you chose for the daily check, your device's offset from UTC, and the check slot derived from those two.
  • A separate reminder slot used for private-profile prompts, since those checks cannot run without you.
  • Your app language, the platform and the app version.
  • Your subscription status and expiry date, and the anonymous customer id issued by RevenueCat.
  • If, and only if, you connect your Instagram account: your Instagram username and your numeric Instagram user id.

Notifications

If you allow notifications, LastFollow stores the push token Apple issues for your device, the state of that permission, the hour you chose, and your time-zone offset. The offset is what lets the check land at the right local hour when you travel. The notification is sent whether or not anything changed, so a quiet day is reported as a quiet day.

You can turn notifications off at any time, in the app or in iOS Settings. Tracking continues; the result is simply shown when you open the app instead of arriving on its own.

Connecting your Instagram account

Connecting is optional and is only needed for two things: seeing your own follower and following lists, and tracking a private account you already follow. Public tracking never asks for it.

  • Sign-in happens on Instagram's own screen. LastFollow never sees your password and never stores it.
  • The session cookie that results from signing in is kept in your device Keychain. It is never transmitted to LastFollow.
  • Your Instagram username and your numeric Instagram user id are stored on your record on our servers. They are also sent to RevenueCat, our subscription provider, as customer attributes. If you would rather that not happen, do not connect the account.
  • LastFollow does not bypass Instagram permissions. A private account can only be read if the connected account already follows it; a pending follow request is not enough.

You can disconnect Instagram at any time with one tap. The public accounts you track and their daily notifications are unaffected.

What is never on our servers

  • Your Instagram password. Sign-in happens on Instagram's own screen and LastFollow only reads the result.
  • Your Instagram session cookie. It stays in the device Keychain.
  • Your own account's follower and following lists.
  • The lists of people inside a private account you track. Only the counts and timestamps described above are stored.
  • Your full payment card number. Apple handles payment and does not pass it to us.

We do not sell personal information.

Why we use this information

  • To run the daily check on the accounts you track and work out what changed.
  • To send the notification at the hour you chose, in your own time zone.
  • To keep the count history the charts are drawn from.
  • To give you access to the paid features your subscription covers, through Apple.
  • To keep the service working: preventing duplicate scans, staying inside the daily budget for paid data requests, and protecting the service from misuse and technical abuse.
  • To work out which advertising campaign an install came from, when you have allowed tracking. This is described in its own section below.
  • To answer support email you send us.

The website

lastfollow.app is hosted on Firebase Hosting and may use Google Analytics for website measurement: pages visited, referrer, approximate region and device type. That measurement is about the website only. It is separate from, and never joined to, the Instagram data the app works with. You do not need an account to read the site.

Advertising measurement and the tracking prompt

There is no advertising inside LastFollow. We do buy ads elsewhere to bring people to the app, and this section is about the single thing we measure as a result: which ad an install actually came from, so we can stop paying for the ones that do not work.

On iPhone that measurement can use the device's advertising identifier, and iOS requires your permission before any app may read it. LastFollow asks once, on the welcome screen, in these words: “This lets us see which ad brought you here, so we can stop paying for ads that do not work. It is never used to build a profile of you.”

  • If you allow it, the advertising identifier may be read and used to attribute an install or a subscription to the campaign it came from. Google's advertising and analytics services receive it for that purpose.
  • If you decline, the advertising identifier is not used at all. Everything in the app behaves exactly the same; only the campaign attribution is lost.

It is never used to build a profile of you, it is never joined to the Instagram lists or to the accounts you track, and it is never sold. There is nothing in the app to target you with, because the app carries no ads.

You can change your answer at any time in iOS Settings, under Privacy & Security, then Tracking. This is the only part of LastFollow that counts as tracking under Apple's definition, and it is why the App Store privacy card lists a device identifier under tracking.

Who else processes this information

Each of these providers processes information under its own terms.

  • Google Firebase — anonymous authentication, the database that holds the records described above, the cloud functions that run the daily check, push message delivery, usage analytics, remote configuration, and hosting for this website. On iPhone its analytics may include the device's advertising identifier, but only when you have allowed tracking.
  • HikerAPI — the third-party data provider that reads public Instagram data for the daily server check. It receives the identifiers of the public profiles being checked.
  • RevenueCat — subscription state. It receives the anonymous customer id, and, if you have connected Instagram, your Instagram username and user id as customer attributes.
  • Apple — App Store distribution, payments, subscriptions and diagnostics. We never receive a full payment card number.
  • Google advertising services — campaign measurement only, and only when you have allowed tracking. They receive the advertising identifier so an install or a subscription can be attributed to the ad it came from.
  • Google Analytics — measurement of the lastfollow.app website as described above, and the app's own usage measurement through Firebase, which runs on the same Google analytics infrastructure.

Your controls

  • Delete everything from inside the app. Settings → “Delete my account and data” permanently removes your server record, the accounts you were tracking and your notification settings. It is not reversible.
  • Disconnect Instagram at any time with one tap. Public tracking and its notifications keep running.
  • Turn notifications off at any time. The result is then shown when you open the app.
  • Manage or cancel your subscription in your Apple App Store account settings. Apple handles renewals, cancellations and refund eligibility.
  • Write to us. Privacy and deletion requests can be sent to support@lastfollow.app.

Retention

We keep information only for as long as it is needed for the purposes above, unless a longer period is required for legal, security or accounting reasons. Daily count history is capped at 90 days, and older days fall away. The daily caches exist for the day they are made. Your tracking records and their results are kept while you are tracking the account, and deleting your account and data in the app removes them along with the rest of your record. A public profile's snapshot belongs to that profile rather than to you, so it is not part of what your record holds.

If you email support, we hold your message and the address you sent it from for as long as needed to deal with it.

Children

LastFollow is not directed to children under 13. If you believe a child has provided personal information to us, contact us so we can review and delete it where required.

Instagram and Meta

LastFollow is not affiliated with Instagram or Meta. It reads only what Instagram already makes available, and it is read-only: it never posts, follows, likes or acts on anyone's account. You are responsible for using LastFollow in a way that respects applicable laws, platform rules and other people's privacy.

Changes to this policy

When what we store, or who processes it, changes, this page changes with it and the “Last updated” date at the top is revised. The version published here is the one that applies.

Contact

For privacy requests, deletion questions or support, contact us at support@lastfollow.app.