Privacy

Privacy Policy

This policy explains how onSensor's website, web app, and Chrome extension handle information.

Last updated: September 2, 2026

The short version

The extension runs only on Instagram, Facebook and TikTok profile pages. It reads creator-profile and post information visible there so it can rank content and save profiles you choose. The optional YouTube feature described below belongs to the web dashboard, not to the extension. On those pages the extension reads what the page has already rendered, which is what lets Scan work when you press it. No ranking is shown until you do. Nothing leaves your browser until you act either: profile and post data is sent to onSensor when you scan a profile, save one, or revisit a profile already on your sensor while signed in. Analysis results are stored in your browser. We do not sell personal data, build advertising profiles, or transmit unrelated browsing history.

1. Scope and who operates the service

This Privacy Policy applies to onSensor, including the web application and browser extension (together, the “Service”). In this policy, “we,” “us,” and “our” refer to the operator of onSensor.

Questions and privacy requests can be sent to support@onsensor.com.

2. Information we handle

Account and authentication information

  • Your email address and account identifier.
  • Your password is submitted to our authentication provider to sign you in. We do not store or log the plain-text password.
  • Access and refresh tokens, your email address, and the Service endpoint are stored in Chrome's local extension storage while you are signed in.

Workspace information

  • Folder names, tracked profiles or channels, settings, and generated alerts.
  • Cached folder and workspace totals stored locally to make the extension popup load quickly.

Supported-page content

On Instagram, Facebook and TikTok profile pages, the extension may process the current page URL and creator or profile information visible to you, including:

  • Platform identifiers, display names, handles, profile URLs, avatar URLs, biographies, external links, verification status, and publicly displayed profile metadata.
  • Follower, following, subscriber, post, video, Page-like, and total-view counts when the platform makes those figures available.
  • Post or video identifiers, captions or titles, thumbnails, permalinks, media type, publish time, duration, and displayed view, like, and comment counts.
  • An image of the analysis panel a scan produced, containing the same public profile figures, ranking and post thumbnails the panel showed on screen.

The extension may read relevant page markup and responses returned by the supported platform to the page. For a full profile analysis, it may load additional profile posts through the platform's own page endpoints and may use a temporary background tab or window. It does not read the contents of private messages, collect comment text, record keystrokes, or inspect unrelated websites.

Local analysis data

Completed Instagram, Facebook and TikTok profile analyses, including the profile and post fields listed above, are cached in Chrome's local extension storage. Local storage is used even when you use the free ranking tools without a onSensor account.

Technical records

Our hosting and database providers may process standard request information such as IP address, browser or device information, timestamps, requested endpoints, response codes, and error details. We use these records to deliver, secure, troubleshoot, and prevent abuse of the Service. We do not operate third-party advertising trackers in the Service.

3. When page data leaves your browser

Opening a profile page sends nothing and shows nothing. The extension reads the profile and post information the page has already rendered. That reading is local and is what Scan builds on. And restores any earlier scan from your browser's local storage. A ranking appears only after you press Scan, or when one you ran before is restored. The extension sends profile or post data to our backend only in the following flows, each of which you start:

  • You press Scan Profile or Scan Page: when the scan finishes, the public creator profile and the public metrics of its posts are sent to onSensor and added to the shared creator dataset described in section 5. This happens whether or not you go on to save the profile to a folder. The same scan also stores one image of the analysis panel it just drew — the figures, the ranking and the post thumbnails already on your screen, as the Screenshot button would produce them — so that a scan can be illustrated later. The image is kept in private storage, is not published anywhere by storing it, holds nothing about you or your account beyond the record of which account ran the scan, and is stored at most once every twelve hours per profile. It is stored only while you are signed in.
  • You choose Save or Sensor: the visible creator profile and available post metrics are saved to your selected folder.
  • A signed-in user revisits a tracked profile: the extension first checks a locally cached set of profiles already tracked by that account. Only a matching Instagram, Facebook or TikTok profile is refreshed on our server.

Visiting an Instagram, Facebook or TikTok profile does not cause that profile to be uploaded merely because you opened it. A scan is a button you press. We do not receive a list of all sites or profiles you visit.

4. How we use information

  • Authenticate you and keep your session active.
  • Rank visible posts and identify performance outliers.
  • Save and organize profiles in your private folders.
  • Build historical snapshots, growth measures, alerts, and workspace totals.
  • Refresh public creator and content metrics when supported.
  • Maintain local caches so repeated analyses and popup views load faster.
  • Protect the Service, enforce rate limits, diagnose parsing failures, and prevent abuse.
  • Respond to support, privacy, and legal requests.

5. Shared public creator data

Folder names, account settings, and the fact that you track a profile are private to your account. Creator-profile and post information obtained from public platform surfaces is stored in a shared dataset so signed-in users can see consistent, current public metrics without duplicating the same creator record.

For integrity and abuse prevention, a stored public observation can carry an internal reference to the account that supplied it. Other users do not receive that reference. When an account is deleted, that reference is removed or de-identified; the underlying public creator metrics may remain as part of the shared historical dataset where lawful and consistent with applicable platform requirements.

6. Disclosure and service providers

We disclose information only as described below:

  • Infrastructure providers: Supabase provides authentication and database infrastructure, and our hosting provider processes web requests and application logs. They process data for us to operate the Service.
  • Supported platforms: your browser communicates directly with Instagram, Facebook and TikTok as you use those sites, and our backend reads public Instagram and Facebook profiles you track. Their own terms and privacy policies apply to their services.
  • Legal and safety: we may disclose information when required by law or when reasonably necessary to investigate fraud, abuse, security threats, or violations of our Terms.
  • Business transfer: information may be transferred in a merger, acquisition, financing, or sale of assets, subject to applicable notice and consent requirements.

We do not sell user data or browsing data. We do not share it with data brokers or use it for personalized, retargeted, or interest-based advertising.

7. Cookies, local storage, and security

The website uses essential authentication cookies or equivalent browser storage to keep you signed in. The extension uses chrome.storage.local for session tokens, account email, cached folders and totals, and cached profile analyses. It does not use Chrome Sync to send that extension storage between devices.

Production communications with our backend and providers use HTTPS. Session cookies are restricted to HTTPS, scoped to this site, and not readable by page scripts. Access to account-scoped database rows is restricted by user identity. No system is perfectly secure, and local extension storage is protected by your browser profile rather than by separate onSensor encryption, so you should protect access to your device and Chrome profile.

8. Retention

  • Account records, private folders, tracked-profile relationships, settings, and alerts are retained while your account is active or as needed to provide the Service.
  • Local extension analyses remain until extension storage is cleared or the extension is removed. Signing out removes the stored session and account-specific folder and totals caches, but does not by itself erase completed local profile analyses.
  • Public creator and post metrics may be retained as historical, shared observations, subject to applicable law and platform requirements.
  • Rate-limit and security records are retained only as long as reasonably necessary for security, integrity, legal, and abuse-prevention purposes. Standard infrastructure logs follow the retention settings of our service providers.

9. Your controls and deletion rights

  • Remove profiles or folders from your workspace in the web app.
  • Sign out of the extension to remove its saved session and account caches.
  • Clear all local extension data by removing the extension from Chrome.
  • Request access, correction, export, objection, restriction, or deletion where provided by applicable law.

To request account and account-linked data deletion, follow our Data Deletion instructions. Verified requests are completed as soon as reasonably practical and within seven calendar days. Deleting data from onSensor does not delete information held by Instagram, Facebook, TikTok, YouTube, or Google.

10. Chrome Web Store Limited Use disclosure

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

We limit data obtained through extension permissions and supported pages to providing or improving onSensor's disclosed creator-analysis and tracking features. We do not use or transfer that data for personalized advertising, creditworthiness, lending, or sale to data brokers. Humans may access user data only with the user's specific consent for support, when necessary for security or abuse investigation, when required by law, or in aggregated and de-identified form for internal operations.

11. Retired YouTube integration

onSensor previously offered an optional YouTube feature that read public channel and video statistics through YouTube API Services using a Google API key you supplied. That feature has been removed. We no longer call YouTube API Services, and API keys previously saved for it have been deleted from our database.

YouTube channel and video records collected while that feature was active may still appear in your workspace as historical data. They are no longer updated. onSensor never requested or stored your YouTube username or password and never used OAuth access to private YouTube account data. Removing data from onSensor does not remove data from YouTube.

12. Children, changes, and contact

The Service is intended for professional creator research and is not directed to children under 13 or the minimum digital-consent age in their location. We do not knowingly collect personal information from children through the Service.

We may update this policy as the Service or legal requirements change. Material changes will be posted here with a revised date and, where required, additional notice or consent.

For privacy questions or complaints, email support@onsensor.com.