Legal

Privacy

What stays in the darkroom, and what never leaves it.

Last updated: July 2026

Findercraft is Instagram analytics for photographers. This page describes what we store, why, and who can reach it. Access is invitation-only (an allow-listed Google account); we do not sell personal data or run advertising profiles on your archive.

Account

Google sign-in.

Sign-in uses Auth.js with Google OAuth. We store the account identifiers Auth.js needs (such as your Google email and user id) so a session can resolve to your archive. Sign-in is denied unless your email is on the operator allow-list.

Instagram connection

Encrypted at rest.

When you connect an Instagram Business account, we store a long-lived Meta access token encrypted with AES-256-GCM. The token is used only by background sync and publish jobs to pull media insights and (when you schedule) publish drafts you authored. You can disconnect at any time; disconnecting removes the stored token.

Archive & metrics

Your archive cache.

We cache post metadata and engagement metrics from the Meta Graph API in Postgres so the app never calls Instagram on page render. Daily metric snapshots are banked so history can outlive Meta's short retention window. Thumbnails are stored in Vercel Blob because Meta CDN URLs expire; they exist to render your archive inside the product.

EXIF uploads

Parsed, then discarded.

Camera settings are recovered when you upload original exports in the browser. We parse EXIF in memory (and match frames by capture time and perceptual hash), then persist only the derived fields — lens, focal length, aperture, shutter, ISO, and related craft metadata. The uploaded original file is not kept.

Public folios

Opt-in only.

If you enable a public profile, a chosen URL slug can show milestones, craft signature, and forward-looking progress to anyone with the link. Raw daily metrics, funnel signals, and audience demographics stay private. Sharing is off by default.

Processors

Where the work runs.

The product runs on Vercel (Node.js serverless) with Postgres and Vercel Blob. Google and Meta are subprocessors for authentication and Instagram data respectively. We do not use your archive to train third-party models.

Contact

Questions about this policy.

Reach us via the contact page — email the darkroom operator listed there (or reply to whoever invited you).