Last updated: August 2, 2026
This policy covers the CCSoft+ mobile app, published by CCSoft and listed as
“Who Unfollowed Me – CCSoft+” on Google Play
(package com.ccsoft.aifollowerstracker) and as CCSoft+ on the
Apple App Store.
The short version:
CCSoft+ does not ask you to register, does not create a profile on our systems, and does not operate a backend that stores your data. The app talks to Instagram directly from your device. Everything it works out — who unfollowed you, who does not follow you back, which posts got the most engagement — is calculated on the phone from data the phone fetched.
Because there is no account, there is also nothing for us to hand over, sell, or lose in a breach of our systems. See Delete Account & Data for how deletion works in practice.
The app opens Instagram's real sign-in page inside a web view. You type your username and password into the app's sign-in screen, and the app types those values into the fields of Instagram's own page inside that web view. They are submitted to Instagram and to nobody else.
We are not Instagram, and we do not have any special access to your account beyond what your own session allows.
Using your own Instagram session, the app reads and saves locally:
All of this is written to a local database on the device (Room on Android, a local database on iOS). None of it is uploaded to CCSoft, and none of it is shared with advertisers, data brokers, or any other third party. It stays on the phone until you log out or uninstall.
The app does not read your direct messages, and does not ask for your contacts, photos, location, microphone or camera.
Three things leave the device: anonymous product analytics, crash reports, and your purchase. Nothing in these contains your follower lists, your posts, your comments, or your password.
On Android the app sends usage events to Google Firebase Analytics. On iOS it sends the same events to Amplitude. The events are:
| Event | What is sent with it |
|---|---|
| Screen or tab opened | The name of the tab, e.g. “followers” |
| Data refresh started | Nothing beyond the event itself |
| Paywall shown | Which part of the app triggered it |
| Subscription plans loaded | How many plans loaded, or the error text if loading failed |
| Plan selected / purchase started | The store product identifier |
| Purchase result | Product identifier, whether it succeeded, was cancelled or failed, and a short failure reason |
| Purchase restored | Whether a previous purchase was found |
| Rating prompt shown, skipped or answered | Why it was skipped, or which button you pressed |
On iOS only, Amplitude additionally records app sessions, app open/background events and screen views automatically, and the app sets the Amplitude user identifier to your Instagram username after you sign in. That means iOS analytics events are linked to your Instagram username. Android does not send the username at all. If you would rather that identifier were removed, see Delete Account & Data.
Alongside these events, the analytics service records the app version, the device model and operating system, and an approximate location — country and city, worked out from the IP address of the connection, never from GPS. The app does not request location permission and cannot read your precise position.
Google Firebase Crashlytics receives a report when the app crashes: the stack trace, device model, operating system version, app version and an app instance identifier. It does not include your Instagram data.
The app uses Firebase Remote Config to fetch settings such as refresh limits and feature switches, and Firebase Cloud Messaging to deliver push notifications. Both involve a device or installation token issued by Google. Push notifications are optional; on Android 13 and later, and on iOS, the app must ask for your permission first, and you can revoke it in your system settings at any time.
Every other request the app makes goes to Instagram, on your behalf, using your session. The one exception is on iOS: if you use the AI comment-suggestion feature, the app downloads a language model file from Hugging Face so that suggestions can be generated on the device. The download is a plain file fetch and carries none of your data.
CCSoft+ offers optional paid subscriptions.
We never receive or store your card number, bank details, billing address or store account identity. The only record on your device is a flag saying whether a subscription is currently active. Both stores have their own privacy policies covering the transaction.
CCSoft+ is for adults. It is not directed at anyone under 18, we do not knowingly collect data from minors, and the app is declared to Google Play as an 18-and-over app. If you believe a minor has used the app and you want the associated diagnostic data removed, email us and we will delete it.
Depending on where you live, you may have rights to access, correct, delete or restrict the processing of personal data, and to object to it. We are not making a certification claim here; we are telling you how to exercise those rights with an app built this way:
If the app changes what it collects, this page will be updated and the “last updated” date at the top will change. Material changes will also be noted in the app's store listing release notes.
CCSoft — ccsoft.ai@gmail.com
For deletion requests, use the subject line Data Deletion Request. We respond within 30 days. We will never ask you for your Instagram password.