Skip to main content
Bleed app iconBleed
How it worksInsightsPrivacyReviewsCompareFAQ
  1. Home
  2. Privacy Policy
Legal

Privacy Policy.

Effective date: 2026-05-19

Effective date: 2026-05-19

1. Introduction

Welcome to Bleed, an Instagram follower tracking mobile application operated by Anant Jain (“Company,” “we,” “our,” or “us”). This Privacy Policy governs your use of Bleed (the “Service”) and explains how we collect, use, safeguard, and disclose information resulting from your use of our Service.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used here have the same meanings as in our Terms of Service.

Our Terms of Service (“Terms”) govern all use of our Service and, together with this Privacy Policy, constitute your agreement with us (“Agreement”).

2. Data Controller

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws, the data controller is:

Anant Jain
Email: bleedtheapp@gmail.com
Location: London, United Kingdom

3. Definitions

SERVICE: The Bleed mobile application operated by Anant Jain, including the supporting backend services that authenticate the app and fetch public Instagram profile data on your behalf.

PERSONAL DATA: Any information relating to an identified or identifiable natural person.

USAGE DATA: Data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.

PUBLIC PROFILE DATA: Information about an Instagram account that Instagram itself makes publicly visible to anyone with a web browser, including the account’s username, profile photo, follower count, following count, and the list of accounts that follow or are followed by the account when those lists are public.

TRACKED ACCOUNT: An Instagram handle you have added to the Service for follower-change tracking. A Tracked Account may be your own account or any other public Instagram account you choose to monitor.

DATA CONTROLLER: The natural or legal person who determines the purposes and means of processing personal data. For this Privacy Policy, Anant Jain is the Data Controller.

DATA PROCESSORS (OR SERVICE PROVIDERS): Any natural or legal person who processes data on behalf of the Data Controller.

DATA SUBJECT: Any living individual who is the subject of Personal Data.

USER: The individual using our Service. The User corresponds to the Data Subject.

4. Legal Basis for Processing (UK GDPR and EU GDPR)

We process your Personal Data on one or more of the following legal bases:

  • Consent: You have given consent to the processing of your Personal Data for one or more specific purposes, including the optional analytics described below.
  • Performance of a Contract: Processing is necessary for the performance of a contract to which you are a party (the Terms of Service that govern your use of the Service and any paid subscription).
  • Legitimate Interests: Processing is necessary for our legitimate interests, such as preventing abuse, debugging service errors, and improving the Service.
  • Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject (for example, responding to a lawful order from a competent authority).

5. No Instagram Login

Bleed does not require, request, or accept your Instagram username and password. We do not operate an OAuth flow, an in-app web view of Instagram’s login screen, or any other login surface that would expose your Instagram credentials to us. We never hold an Instagram session associated with your account.

All information about Tracked Accounts is read from the same public Instagram surfaces that any person with a web browser can see. The Service can only see what Instagram has chosen to make public.

Bleed does not maintain any identity for you on our backend. The Service's backend is a stateless proxy that holds no database and no user records. The app authenticates to the backend on each request using Apple App Attest, a device-attestation mechanism that proves the request originates from an unmodified copy of the Bleed iOS application on your specific device, without identifying you. Your declared Instagram handle is stored only on your iPhone (in the system Keychain). This identity is not an Instagram account, has no relationship with Instagram, and grants no access to Instagram beyond the public-data path described above.

6. Types of Data Collected

Identity Data

When you connect a handle to the Service, the Instagram handle you supplied is stored only on your iPhone, in the system Keychain. We do not store the handle on our backend, and we do not store any password, session cookie, two-factor token, or other credential at all. The Service's backend has no user database. The app authenticates to the backend on each request using Apple App Attest, which proves the request comes from an unmodified copy of the official iOS application on your specific device, without identifying you.

Tracked Account Profile Data

For each Tracked Account, public profile fields (the username, the public profile photo URL, the public display name, the public follower / following / post counts at the time of last scan) are cached on your iPhone using Apple’s SwiftData framework. We do not cache any of this on our backend; the Service's backend has no database. When a scan runs, the public follower and following lists pass through our backend only as transient bytes in the response stream and are written to your device immediately afterwards; they are never persisted on the backend.

Local Follower History (on your device)

The full follower history for each Tracked Account (the per-day timeline of who follows whom, who unfollowed when, which mutuals exist, and every diff between consecutive scans) is stored on your iPhone using Apple’s SwiftData framework. This data never leaves your device via the Service. Uninstalling the app deletes it.

Usage Data (via Analytics)

We use Mixpanel, a third-party analytics service, to collect anonymous usage data. This includes: device type and model, operating system version, the features of the Service you use, interaction patterns and frequency of use, session duration, app version, and an anonymous device identifier generated by Mixpanel. We do not collect your IP address directly, though Mixpanel may process IP addresses for geolocation purposes on their servers. Mixpanel’s automatic event tracking is disabled; we only track specific defined events. Our Mixpanel project is hosted in the European Union.

Analytics events never contain Instagram usernames, follower lists, the contents of any insight list, or any other information that would identify the Instagram accounts you track or be tracked by.

Subscription and Purchase Data

Subscription and in-app purchase transactions are processed entirely by Apple through the App Store. We use RevenueCat, a third-party subscription management service, to verify purchase status and manage entitlements. RevenueCat generates an anonymous customer identifier and cross-references it with our analytics so we can understand subscription behaviour in aggregate. We do not have access to your payment details, credit card information, Apple ID, real name, or email address.

Local Notifications

With your permission, Bleed may send local notifications to remind you to scan, to inform you that a per-target cooldown window has lifted, or to relay similar on-device-scheduled prompts. These notifications are generated and scheduled entirely on your device by the iOS app and are not sent from any server. You can disable notifications at any time through your device’s Settings.

Data We Do NOT Collect

We do not collect:

  • Your Instagram password or session cookies (we have no login surface).
  • Your Instagram DMs, stories, posts, or any private Instagram data.
  • The follower or following lists of any account, stored persistently on a server.
  • Your real name, email address, or any contact information except where you provide them voluntarily (for example, by emailing us about a support issue).
  • Special category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation).
  • Financial or payment information of any kind (Apple processes all payments and we never see them).
  • Precise geolocation data.
  • Your contacts, microphone, camera, photos, or any other device sensor data not strictly required to render the app.
  • Cross-app advertising identifiers (no IDFA collection; no IDFV forwarded to third parties).

7. Use of Data

We use the collected data for the following purposes: to provide and maintain the Service; to authenticate the app to the backend; to display Tracked Account information in the dashboard; to understand how the Service is used and identify areas for improvement; to detect, prevent, and address technical issues; to detect and prevent abuse, fraud, or violations of the Terms of Service; and to comply with our legal obligations.

We do not use, read, or analyse the follower history stored on your device. That data is held in SwiftData on your iPhone; we do not have a copy of it on our servers and we do not derive analytics insights from it.

8. Retention of Data

We do not retain any personal data on our backend. The Service's backend has no user database; nothing about you is stored server-side. Identity Data (your handle) and Tracked Account Profile Data live only on your iPhone — in the system Keychain and in Apple’s SwiftData framework respectively — and are deleted when you remove the relevant target in the app, choose Disconnect in Settings, or delete the app. Anonymous analytics events are retained by Mixpanel per their standard retention windows. We will retain such data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

9. Transfer of Data

Your data may be processed by our service providers in countries outside the United Kingdom or the European Economic Area (EEA). Where we transfer data outside of the UK or the EEA, we ensure that adequate safeguards are in place, including transfers to countries with an adequacy decision, the use of UK International Data Transfer Agreements (IDTA), EU Standard Contractual Clauses (SCCs), and other lawful transfer mechanisms.

10. Disclosure of Data

We may disclose your data:

  • For law enforcement purposes if required to do so by law or in response to valid legal process.
  • In connection with a business transaction such as a merger, acquisition, or sale of all or a portion of our assets.
  • To our service providers bound by data processing agreements that limit their use of the data to what we instruct.
  • If we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.

11. Security of Data

We implement appropriate technical and organisational measures to protect your data, including: encryption of data in transit using TLS/SSL; Apple App Attest authentication for all backend traffic, which cryptographically proves each request originates from an unmodified copy of the official iOS application on a real Apple device; storage of the connected handle and App Attest credentials in the iOS Keychain (not in user-readable storage); the principle of least privilege on backend service-account access; a stateless backend with no user database to compromise; regular dependency updates; and secure development practices. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will: notify the relevant supervisory authority (in the UK, the Information Commissioner’s Office) within 72 hours of becoming aware of the breach; notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and document all personal data breaches.

13. Your Data Protection Rights Under UK GDPR and EU GDPR

If you are a resident of the United Kingdom, the European Union, or the European Economic Area, you have the following rights:

  • The right of access: You can ask us for a copy of the personal data we hold about you.
  • The right to rectification: You can ask us to correct inaccurate personal data.
  • The right to erasure: You can ask us to delete the personal data we hold about you (subject to our legal obligations).
  • The right to restrict processing: You can ask us to limit how we use your personal data.
  • The right to object to processing: You can object to processing that we carry out on the basis of legitimate interests.
  • The right to data portability: You can ask us to provide your personal data in a structured, commonly used, machine-readable format.
  • The right to withdraw consent: Where processing is based on consent, you can withdraw that consent at any time.
  • Automated decision-making: The Service does not engage in automated decision-making that produces legal effects concerning you.

Because the Service's backend holds no user database and stores no personal data about you, the right of erasure is satisfied by erasing the on-device data the iOS app holds. The most direct way to do this is to use the in-app Disconnect option in Settings, which clears the connected handle from your iPhone's Keychain and deletes all locally stored follower history. Removing the app from your iPhone is equivalent. To exercise any other right, email bleedtheapp@gmail.com and identify the request as a data-subject access request.

You have the right to complain to the UK Information Commissioner’s Office (ICO) at https://ico.org.uk, or to your local EU or EEA data protection authority.

14. Your Rights Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)

If you are a California resident, you have the following rights:

  • Right to know: what Personal Data we collect about you, the categories of sources, the purposes for which we collect it, and the categories of third parties with whom we share it.
  • Right to delete: the Personal Data we hold about you, subject to certain exceptions.
  • Right to correct: inaccurate Personal Data.
  • Right to opt out of sale or sharing: we do not sell or share your data for cross-context behavioural advertising, ever.
  • Right to non-discrimination: we will not deny you the Service, charge you a different price, or provide a different quality of Service because you exercised your CCPA / CPRA rights.
  • Right to limit use of sensitive personal information: we do not collect sensitive personal information as defined by the CCPA and CPRA.

To exercise any of these rights, contact us at bleedtheapp@gmail.com. We will respond within 45 days.

15. Service Providers

Bleed uses these third-party service providers to operate:

  • Apple App Store and StoreKit. Distributes the app and processes payments. Subject to Apple’s privacy policy.
  • Public-data provider. A third-party service that fetches public Instagram profile data on our behalf. They receive the handle being looked up and the associated public data fields. They do not receive any information about you that is not strictly necessary to complete the lookup, and they are bound by a data processing agreement.
  • RevenueCat. Manages subscription entitlement. Sees a randomly generated customer ID and transaction state. To learn more, visit www.revenuecat.com/privacy.
  • Mixpanel (EU). Anonymous product analytics. No personally identifiable information sent. To opt out of Mixpanel tracking, visit https://mixpanel.com/optout/. For more information, visit https://mixpanel.com/terms/.
  • Cloudflare. Hosts this marketing website and the backend that the iOS app talks to. Standard edge-server access logs apply. Cloudflare does not see follower history or any Instagram credentials — the backend's role is limited to authenticating the iOS app via Apple App Attest and proxying public-data requests to the third-party data provider.

Each of these providers is bound by a data processing agreement and is contractually obligated to keep data confidential and process it only as instructed.

16. No Advertising or Remarketing

We do not use any advertising SDKs, remarketing services, or behavioural advertising technologies. We do not serve ads within the app. We do not share your data with advertising networks. We do not sell your data, ever.

17. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. We strongly advise you to review the Privacy Policy of every site you visit. We assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

18. Children’s Privacy

Our Service is not intended for use by children under the age of 18. We do not knowingly collect personally identifiable information from children under 18. If you become aware that a child has provided us with Personal Data, please contact us immediately at bleedtheapp@gmail.com and we will delete it from our records.

19. International Data Transfers

For transfers outside the UK or the EEA, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs), and other appropriate safeguards. You may request a copy of the safeguards by contacting us at bleedtheapp@gmail.com.

20. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective date” at the top. For material changes, we will make reasonable efforts to notify you via a prominent notice on the Service before the change takes effect.

21. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a complaint, please contact us:

By email: bleedtheapp@gmail.com
Operator: Anant Jain
Location: London, United Kingdom

For UK residents, you may lodge a complaint with the Information Commissioner’s Office: https://ico.org.uk/make-a-complaint/.

Get Bleed

Try Bleed for free.

Download Bleed and see who actually stuck around and who quietly left. No login. No password. Free to start.

Privacy Policy
Terms of Service
Press
App Store

© 2026 Bleed. Made by Anant Jain. Not affiliated with Instagram or Meta.