Legal

Privacy Policy

How we handle the handle you type, the upstream API call, and your rights — written plainly.

Last updated 12 June 2026GDPR + CCPA aligned~8 min read
Jump to section
Section 01

Introduction

GWAA is a network of 27 free, anonymous Instagram and YouTube tools. We do not require sign-up, payment, or any persistent account. This Privacy Policy explains exactly what happens to the handle, URL, or input you type into one of our tools, where it travels, how long anything is kept, and what rights you have under GDPR, CCPA, and similar laws.

Read this document once. The promises here are short, specific, and verifiable.

Who we are

The short version: we do not store the inputs you type, do not run analytics that identify you, and do not have an account to log into. The handle goes to an upstream API, the result comes back, the cache expires in 60 minutes.
Section 02

Information We Collect

We split this into three buckets so you can see each one separately.

Inputs you type into tools

When you use a tool like the Story Viewer or Money Calculator, your input (handle, URL, number, hashtag) is sent from your browser to our server. The server forwards it to the upstream public API, receives the response, and renders it back to you. The input is held in memory only for the duration of the request.

Server-level logs

Our web server records standard access logs: IP address, timestamp, URL requested, user agent. These logs are kept for 30 days for security and abuse mitigation, then rotated out. We do not correlate them with any user identity.

What we do not collect

  • No account, no email, no payment information — there is nothing to register for.
  • No persistent identifier in your browser beyond the theme preference (light/dark).
  • No fingerprinting, no cross-site tracking pixels, no third-party analytics that identify you personally.
Section 03

How We Use Your Information

Inputs you type are used only to fulfill the specific tool request you triggered. We do not aggregate, profile, sell, or share your inputs with advertisers. There is no "data products" side of GWAA.

Specifically

  • Tool execution: handle → upstream API → result returned to your browser.
  • Caching for performance: the upstream response is cached for up to 60 minutes so repeated visits do not hammer the API. After 60 minutes the entry expires automatically.
  • Abuse prevention: IP-level rate limits at the edge to block scraping bots. No per-user history is built.

What we do not do

We do not use your inputs to train AI models, build user profiles, retarget you with ads, or share with any third party other than the upstream provider that returns the result.

Section 04

Third-Party Services

GWAA's tools call several upstream services to retrieve public data. We disclose all of them so you know exactly who sees the handle you type.

RapidAPI upstream providers

  • mediacrawlers — primary Instagram data provider, called per request.
  • scraper21 — fallback provider when the primary returns empty or rate-limits.

Both providers receive the handle or URL you supplied. They do not receive your IP address or browser identifier — only the input string forwarded by our server.

Infrastructure and delivery

  • Cloudflare — CDN, DDoS protection, edge caching. May see your IP at the edge for security purposes.
  • Google Fonts — fonts are served from Google's CDN; Google may log the request per their own policies. To opt out, install a CSS-blocker for fonts.
What we do not use: no Facebook Pixel, no Google Analytics, no advertising cookies. Period.
Section 05

Cookies & Tracking

GWAA uses one client-side storage entry, and it is functional only:

  • theme-preference — stores your light/dark mode choice. Stored in browser localStorage. Never sent to our server.

No tracking cookies

We do not set tracking cookies, advertising cookies, or analytics cookies. There is no consent banner because there is nothing requiring one. Cloudflare may set a short-lived security cookie at the edge to identify bots; this is documented in Cloudflare's own privacy policy.

How to clear

Delete localStorage through your browser's developer tools or site settings. The site continues to work; you will just see the default light theme.

Section 06

Your Privacy Rights

Because we do not hold accounts or persistent records tied to you, most rights are structurally satisfied by default. There is no profile to access, no history to delete, no consent to withdraw.

Under GDPR (EU / UK)

  • Right to access — we do not store user-identifiable records. There is nothing to give you a copy of.
  • Right to erasure — the 60-minute upstream cache expires automatically. To force a purge sooner, email [email protected].
  • Right to object / restrict — stop using the tools; nothing remains tied to you after the cache window.
  • Right to lodge a complaint — with your local supervisory authority, e.g. the ICO in the UK or your national DPA.

Under CCPA / CPRA (California)

We do not sell personal information. We do not collect categories of personal information beyond what is described above. California residents have the right to know, delete, and opt out of sale; given we collect nothing identifiable and sell nothing, these rights are honored by default.

Section 07

Data Retention

Retention is short and bounded.

  • Tool inputs: held in memory only during the request. Not persisted to disk.
  • Upstream API cache: up to 60 minutes. Then evicted.
  • Server access logs: 30 days, then rotated out.
  • Theme preference (your browser): until you clear localStorage.

There is no analytics warehouse. There is no "user table." There is no archive of past inputs.

Section 08

Data Security

GWAA serves all pages over HTTPS via TLS. The upstream API calls also use HTTPS. We do not collect or store payment information; there is no payment surface to secure. We do not store passwords or hashes because there are no accounts.

What we still do

  • HTTPS-only with HSTS where supported.
  • Edge-level rate limits and DDoS protection through Cloudflare.
  • Patching of our PHP runtime and dependencies on a routine cadence.
  • No vendor receives data they do not need for the specific tool you ran.
Section 09

Children's Privacy

GWAA is not directed at children. We do not knowingly collect information from users below the age of 13 (United States) or 16 (European Union, depending on member state). If a parent or guardian becomes aware of a child interacting with our tools and wants the corresponding cache window cleared sooner than 60 minutes, write to [email protected] with details and we will act promptly.

Section 10

International Data Transfers

GWAA's primary infrastructure is hosted in the United States. Cloudflare's edge serves content from a location near you. The upstream RapidAPI providers may operate from regions outside your own. When you use a tool from outside the US, your input is transferred internationally in the course of fulfilling the request.

We rely on each provider's own safeguards and contractual commitments to maintain protections equivalent to those of your home jurisdiction. We do not use sub-processors that do not publish their own privacy disclosures.

Section 11

Changes to This Policy

If we change this policy, the "Last updated" date at the top of this page changes too. For material changes that affect the meaning of the promises above, we will post a short banner on the homepage for at least 30 days so returning users can see it.

This is not a contract; it is a description of how the tools operate today. Continued use after a change means you accept the updated description.

Section 12

Contact Us

The fastest way to reach a human:

Most replies land within one business day.