Privacy policy
Last updated: 9 October 2026
This policy explains how InstaGrow ("we") handles personal data in the Lens app (Android and iPhone) and on lens.instagrowapp.com. It is written to comply with India's Digital Personal Data Protection Act, 2023 and the rules made under it. We collect only what we need to run Lens.
1. What we collect and why
| Data | Why we need it | How long we keep it |
|---|---|---|
| A random Lens name (like "quiet-tiger-8703") | To identify your account and let friends find you when you share | Until you delete your account |
| Your email address (if you sign in with email or Google) | To sign you in with one-time codes and to recognise your account on new devices | Until you delete your account |
| Your Google account ID (if you sign in with Google) | To sign you in with Google. Google also sends your name and profile photo; we do not store them | Until you delete your account |
| Photos and videos you back up, and their metadata (for example date, camera model and, if your camera recorded it, location) | To store, show, share and stream your library, the core of Lens | Until you delete them (see Trash and Archive below) or your account |
| Thumbnails, previews, edit settings, portrait outlines and streaming copies | To make browsing fast and show your edits on every device | Previews/edits: as long as the photo. Streaming copies: 90 days after last made |
| Who you share items with | To show shared items to them | Until you or they remove the share |
| Device and browser names (for example "Samsung SM-A546E", "Chrome on Windows") and sign-in times | To list your signed-in devices so you can sign them out | Until you sign that device out, or 90 days without use |
| A one-way hash of your phone’s app ID | To give a reinstalled phone its free guest storage back instead of creating new free storage (abuse prevention) | Until you delete your account |
| IP address | To limit abuse (counting requests per network for one hour) | About 2 hours |
| Approximate city (from your IP) when you request QR sign-in on the website | To show "who is asking" on your phone before you approve | At most 2 minutes |
| Sign-in codes we email you | To verify you own the email address | 10 minutes; stored only as a hash |
| Requests you send us (for example "add a storage provider", or the contact form: name, email, message) | To reply and improve Lens | Up to 2 years |
| Invites: which invite or affiliate link or code brought you (from the Google Play install referrer, a website cookie, or a code you type), and whether your phone is an emulator | To give your friend their storage reward or the affiliate their commission, and to stop fake sign-ups | Until you delete your account |
| Clicks on invite and affiliate links: time, browser type and a one-way hash of the IP address | Fraud checks and the inviter’s statistics (counts only, never who clicked) | Raw clicks 30 days; daily counts for the life of the link |
| Affiliates only: name, channels, PAN and UPI ID (encrypted), commissions and payouts | To run the program, pay you and meet tax law (TDS, Form 16A) | 8 years after the financial year (Indian tax and accounting law) |
| A record of reward, commission and payout changes | An unchangeable audit trail, so rewards and payments can be checked | 8 years |
We do not collect your contacts, call logs, SMS, or advertising identifiers, and we do not use third-party analytics or crash-reporting in the app today. If we add analytics, we will update this policy first.
2. Your own storage (Google Drive, OneDrive, Dropbox, Box, S3, WebDAV)
If you connect your own storage, your photos and videos are uploaded directly from your phone to that provider. You sign in to the provider on its own page. On the free plan, the access keys stay on your phone; our servers help exchange the sign-in code but do not keep the keys. We keep only small previews in Lens so your gallery is fast. Your provider’s own privacy policy applies to the files stored there.
3. Where your data is stored and who processes it
We do not sell, rent or trade your personal data. We do not show ads. We do not use your photos or videos to train AI models. Processors act only on our instructions.
- Amazon Web Services (AWS), Mumbai region, India: storage of your photos, videos and account data, our servers, and sending sign-in emails. Data is encrypted at rest and in transit.
- Amazon CloudFront (part of AWS): delivers previews and files quickly. It may cache copies at locations outside India for a short time. Every link is signed and expires.
- Google: only if you choose "Sign in with Google" or connect Google Drive.
- Microsoft, Dropbox, Box or your S3/WebDAV provider: only if you connect them.
4. Processing on your phone
Thumbnails, previews, looks, edits, Night mode and Portrait outlines are made on your phone. The Portrait person outline is made by an on-device model built into the app; your photo is not sent anywhere for it. Long videos may be converted to streaming copies on our servers when someone plays them on another device.
5. Deleting things
- Trash: deleted items stay 30 days and can be restored.
- Archive: after Trash, items are kept for 1 year (recoverable), then permanently deleted.
- "Delete forever" removes the item and all its copies immediately.
- Deleting your account removes your library, account and sign-ins (see the Delete your account page). Deleted data can remain in encrypted backups for up to 35 days before it is overwritten.
- Server logs (errors and timings) are kept for 7 days.
6. Cookies on the website
The website uses only strictly necessary cookies. "__Host-lens" keeps you signed in. It is secure, HttpOnly (scripts cannot read it) and sent only to lens.instagrowapp.com. It lasts up to 30 days or until you log out. If you arrive through an invite or affiliate link, a second cookie, "__Host-lensref", remembers that link’s code for up to 30 days so the right person is credited if you sign up on the website. We use no advertising or tracking cookies.
7. Your rights
Under the DPDP Act you can:
- Get a summary of the personal data we hold about you and how we process it
- Correct or update your data
- Erase your data (delete items, or your whole account)
- Withdraw consent at any time (this stops the related processing; for example, deleting your account stops backup)
- Nominate a person to exercise your rights if you die or become incapacitated
- Raise a grievance with us, and then with the Data Protection Board of India
8. Children
Lens is for people aged 18 and over. Under-18s may use Lens only with the verifiable consent of a parent or lawful guardian. If you believe a child has used Lens without consent, contact us and we will delete the data.
9. Security
We use HTTPS everywhere, encryption at rest, checksums on every upload, signed expiring links, one-way hashed session secrets, and sign-in without passwords. No system is perfectly secure; if a breach affects your data, we will inform you and the Data Protection Board as the law requires.
10. Contact and grievance officer
Questions or requests: use our contact form at lens.instagrowapp.com/contact/. Grievance Officer: choose "Grievance" on the same form (lens.instagrowapp.com/contact/?topic=grievance). We acknowledge grievances within 48 hours and respond within 30 days, usually much sooner.
11. Changes
We will post changes here and update the date below. For significant changes we will notify you in the app before they take effect.