What the Extension Accesses
When you start an export, the extension reads your active Instagram session cookies and requests the selected follower or following list from Instagram. Extraction and spreadsheet creation run entirely in your local browser sandbox.
The extension stores mission history, progress cursors, and extracted records in local browser storage (chrome.storage.local and IndexedDB) so you can resume interrupted jobs or download past missions. Generated CSV or Excel (.xlsx) files are saved directly to your computer through Chrome's native download feature. Local mission data remains securely on your device until you delete it, clear extension data, or uninstall the extension.
Licensing, Payments, and Required Google Sign-In
Subscriptions are attached to your verified Google account. The extension checks subscription status with the VoltCast server (https://api.voltcastapp.com) over HTTPS.
-
Google Account Verification: The extension sends a Google access token (obtained via
chrome.identity) to the VoltCast server over HTTPS for account verification. The server verifies this token directly with Google (https://www.googleapis.com/*) and stores the account's stable Google identifier (OAuth ID), email address, and total free-trial usage counter. - Optional Binance Payment Verification: For optional Binance cryptocurrency payments, the extension sends the transaction reference ID and selected plan tier; the server verifies the payment on-chain and activates that Google account.
- Manual Activation: An authorized administrator may also activate a registered account manually using its verified Google email address.
- Data Retention: The server stores subscription and payment records strictly needed to provide the service. Account data is retained while the service operates or until an eligible deletion request is fulfilled. Chrome Sync of profile and license settings is optional. Google's services are subject to Google's privacy policy.
Free-Trial Quota Accounting (500 Records Limit)
The free tier provides a lifetime quota of 500 extracted follower records per verified Google account.
https://api.voltcastapp.com for quota accounting. No Instagram user profiles, usernames, follower details, or cookies are ever transmitted to or stored on VoltCast servers.
Once the 500-record threshold is reached, further exports require upgrading to an unlimited paid plan. Quota state is cryptographically signed to prevent manipulation while preserving total user anonymity regarding which profiles were extracted.
Comprehensive Data Processed & Storage Matrix
The table below provides a complete, itemized breakdown of every data element processed by version 1.0.12 of the Extension:
| Data Element | Source | Operational Purpose | Storage Location | Third-Party Sharing |
|---|---|---|---|---|
|
Public Instagram Profile Data Usernames, IDs, follower counts, verified badges |
Instagram GraphQL / DOM | Generating Excel (.xlsx) / CSV file requested by user |
Local device storage only IndexedDB & downloads |
None (0%) |
|
Instagram Session Cookies sessionid, ds_user_id, csrftoken |
instagram.com cookies | Authenticating user's own read-only requests to Instagram |
Volatile RAM only Never sent to VoltCast server |
None (0%) |
|
Google Account Identity OAuth ID, Google email, access token |
chrome.identity / Google OAuth | Mandatory account verification, licensing, and quota enforcement |
VoltCast secure licensing server HTTPS encrypted (api.voltcastapp.com) |
Verified with Google OAuth only |
|
Quota & Mission Accounting Record count (0-500), random mission UUID |
Local export runner | Accounting free-tier quota usage against Google account |
VoltCast server database Counts only, no profile data |
None (0%) |
|
Payment References (Optional) Binance transaction hash, plan selected |
User input during upgrade | On-chain payment verification and subscription activation |
VoltCast billing server Retained for billing records |
None (0%) |
|
User Preferences Export format, delay intervals, audio toggles |
User selections in UI | Preserving configuration across browser sessions |
chrome.storage.local Optional Chrome Sync |
None (0%) |
Permissions & Sharing Justification (Manifest V3)
Every permission declared in manifest.json is strictly tailored to a verified functional purpose:
cookies & *.instagram.com
Host Access
Authenticate browser-side requests to Instagram for the user-initiated export without requiring re-login.
identity & *.googleapis.com
OAuth Access
Required Google Sign-In and account verification to enforce the 500-record free quota and attach subscriptions.
storage
chrome.storage.local
Save UI settings, local mission state, progress checkpoints, and encrypted license details locally.
downloads
Local Disk
Save compiled CSV and Excel (.xlsx) export spreadsheets directly to the user's computer Downloads directory.
tabs
Active Tab
Open the exporter dashboard tab and read target profile username from the active Instagram URL.
declarativeNetRequest
Header Handling
Set request headers required by the Instagram web request flow to ensure uninterrupted pagination.
offscreen & notifications
User Experience
Play optional audio completion alerts via offscreen document and show desktop notifications when export finishes.
api.voltcastapp.com
VoltCast API
HTTPS host access for account verification, free-quota checks (500 records), license status, and payments.
Data We Strictly NEVER Access (Negative Declaration)
We never prompt for, intercept, read, or store your Instagram or Google account passwords. Authentication happens entirely through secure browser cookies and official Google OAuth dialogs.
The Extension has no access to your Direct Messages (DMs), private chat histories, unread message counters, or confidential inbox threads.
The Extension cannot view, track, or record your web browsing activity, search queries, or visited domains outside the explicitly declared hosts.
We do not embed third-party analytics SDKs, keyloggers, screen recorders, or telemetry trackers. No keystroke telemetry is transmitted to external remote servers.
Security, Data Rights & Official Contact
All communication between the Extension and the VoltCast API server uses strong HTTPS encryption. Avoid exporting data you are not authorized to access.
- Local Deletion: Clear all local mission data at any time via Extension Settings or by uninstalling the extension.
- Server Record Deletion: To ask about data handling or request deletion of eligible server records (Google email, license logs), email our privacy officer.