Privacy policy

Last updated: 9 October 2026

This policy explains how InstaGrow ("we") handles personal data in the Lens app (Android and iPhone) and on lens.instagrowapp.com. It is written to comply with India's Digital Personal Data Protection Act, 2023 and the rules made under it. We collect only what we need to run Lens.

1. What we collect and why

DataWhy we need itHow long we keep it
A random Lens name (like "quiet-tiger-8703")To identify your account and let friends find you when you shareUntil you delete your account
Your email address (if you sign in with email or Google)To sign you in with one-time codes and to recognise your account on new devicesUntil you delete your account
Your Google account ID (if you sign in with Google)To sign you in with Google. Google also sends your name and profile photo; we do not store themUntil you delete your account
Photos and videos you back up, and their metadata (for example date, camera model and, if your camera recorded it, location)To store, show, share and stream your library, the core of LensUntil you delete them (see Trash and Archive below) or your account
Thumbnails, previews, edit settings, portrait outlines and streaming copiesTo make browsing fast and show your edits on every devicePreviews/edits: as long as the photo. Streaming copies: 90 days after last made
Who you share items withTo show shared items to themUntil you or they remove the share
Device and browser names (for example "Samsung SM-A546E", "Chrome on Windows") and sign-in timesTo list your signed-in devices so you can sign them outUntil you sign that device out, or 90 days without use
A one-way hash of your phone’s app IDTo give a reinstalled phone its free guest storage back instead of creating new free storage (abuse prevention)Until you delete your account
IP addressTo limit abuse (counting requests per network for one hour)About 2 hours
Approximate city (from your IP) when you request QR sign-in on the websiteTo show "who is asking" on your phone before you approveAt most 2 minutes
Sign-in codes we email youTo verify you own the email address10 minutes; stored only as a hash
Requests you send us (for example "add a storage provider", or the contact form: name, email, message)To reply and improve LensUp to 2 years
Invites: which invite or affiliate link or code brought you (from the Google Play install referrer, a website cookie, or a code you type), and whether your phone is an emulatorTo give your friend their storage reward or the affiliate their commission, and to stop fake sign-upsUntil you delete your account
Clicks on invite and affiliate links: time, browser type and a one-way hash of the IP addressFraud checks and the inviter’s statistics (counts only, never who clicked)Raw clicks 30 days; daily counts for the life of the link
Affiliates only: name, channels, PAN and UPI ID (encrypted), commissions and payoutsTo run the program, pay you and meet tax law (TDS, Form 16A)8 years after the financial year (Indian tax and accounting law)
A record of reward, commission and payout changesAn unchangeable audit trail, so rewards and payments can be checked8 years

We do not collect your contacts, call logs, SMS, or advertising identifiers, and we do not use third-party analytics or crash-reporting in the app today. If we add analytics, we will update this policy first.

2. Your own storage (Google Drive, OneDrive, Dropbox, Box, S3, WebDAV)

If you connect your own storage, your photos and videos are uploaded directly from your phone to that provider. You sign in to the provider on its own page. On the free plan, the access keys stay on your phone; our servers help exchange the sign-in code but do not keep the keys. We keep only small previews in Lens so your gallery is fast. Your provider’s own privacy policy applies to the files stored there.

3. Where your data is stored and who processes it

We do not sell, rent or trade your personal data. We do not show ads. We do not use your photos or videos to train AI models. Processors act only on our instructions.

  • Amazon Web Services (AWS), Mumbai region, India: storage of your photos, videos and account data, our servers, and sending sign-in emails. Data is encrypted at rest and in transit.
  • Amazon CloudFront (part of AWS): delivers previews and files quickly. It may cache copies at locations outside India for a short time. Every link is signed and expires.
  • Google: only if you choose "Sign in with Google" or connect Google Drive.
  • Microsoft, Dropbox, Box or your S3/WebDAV provider: only if you connect them.

4. Processing on your phone

Thumbnails, previews, looks, edits, Night mode and Portrait outlines are made on your phone. The Portrait person outline is made by an on-device model built into the app; your photo is not sent anywhere for it. Long videos may be converted to streaming copies on our servers when someone plays them on another device.

5. Deleting things

  • Trash: deleted items stay 30 days and can be restored.
  • Archive: after Trash, items are kept for 1 year (recoverable), then permanently deleted.
  • "Delete forever" removes the item and all its copies immediately.
  • Deleting your account removes your library, account and sign-ins (see the Delete your account page). Deleted data can remain in encrypted backups for up to 35 days before it is overwritten.
  • Server logs (errors and timings) are kept for 7 days.

6. Cookies on the website

The website uses only strictly necessary cookies. "__Host-lens" keeps you signed in. It is secure, HttpOnly (scripts cannot read it) and sent only to lens.instagrowapp.com. It lasts up to 30 days or until you log out. If you arrive through an invite or affiliate link, a second cookie, "__Host-lensref", remembers that link’s code for up to 30 days so the right person is credited if you sign up on the website. We use no advertising or tracking cookies.

7. Your rights

Under the DPDP Act you can:

  • Get a summary of the personal data we hold about you and how we process it
  • Correct or update your data
  • Erase your data (delete items, or your whole account)
  • Withdraw consent at any time (this stops the related processing; for example, deleting your account stops backup)
  • Nominate a person to exercise your rights if you die or become incapacitated
  • Raise a grievance with us, and then with the Data Protection Board of India

8. Children

Lens is for people aged 18 and over. Under-18s may use Lens only with the verifiable consent of a parent or lawful guardian. If you believe a child has used Lens without consent, contact us and we will delete the data.

9. Security

We use HTTPS everywhere, encryption at rest, checksums on every upload, signed expiring links, one-way hashed session secrets, and sign-in without passwords. No system is perfectly secure; if a breach affects your data, we will inform you and the Data Protection Board as the law requires.

10. Contact and grievance officer

Questions or requests: use our contact form at lens.instagrowapp.com/contact/. Grievance Officer: choose "Grievance" on the same form (lens.instagrowapp.com/contact/?topic=grievance). We acknowledge grievances within 48 hours and respond within 30 days, usually much sooner.

11. Changes

We will post changes here and update the date below. For significant changes we will notify you in the app before they take effect.