Privacy Policy
Last updated: February 8, 2026
Summary: RaffleCat respects your privacy. We only access data strictly necessary to conduct Instagram giveaways. We do not sell, share, or store your personal data on our servers. All information is processed locally on your device.
1. Introduction
RaffleCat ("we", "our" or "the application") is a mobile application designed to help content creators and influencers conduct fair and transparent giveaways on Instagram. This Privacy Policy describes how we collect, use, and protect information when you use our application.
By using RaffleCat, you accept the practices described in this policy. If you do not agree with these practices, please do not use the application.
2. Information We Collect
2.1. Information provided through Instagram (Meta) login
RaffleCat offers the option to connect your Instagram account through Meta's OAuth protocol. Login is required exclusively to access the official Instagram Graph API, which allows obtaining 100% of comments from your own posts in an official and verifiable manner.
When you log in with Instagram, we receive the following minimal information through Meta:
- Instagram username: to identify your account within the app.
- Instagram user ID: technical identifier for API queries.
- Temporary access token: a token issued by Meta that expires automatically and is used solely to read comments from your posts.
- Linked Facebook Page ID and name: required by Meta for Instagram Graph API access.
Why do we need login? Instagram does not allow access to the complete list of comments on a post without the owner's authorization. Meta login is the only official and legal mechanism to obtain all comments and guarantee a fair draw with verified data. Without this access, we can only obtain a limited sample of approximately 300 comments (Quick Mode).
2.2. Instagram post data
When you provide the link to an Instagram post, we temporarily access:
- Post comments: usernames and text of each comment.
- Post caption: to automatically detect giveaway rules using AI.
- Post image: only as a visual reference within the app.
Important: we only access posts you own when using verified mode (with login). We never access third-party posts, direct messages, followers, private profile information, or any other personal data.
2.3. Device data
We may collect anonymous technical information for diagnostic and service improvement purposes:
- Device type and operating system.
- Application version.
- Anonymous error reports (through Sentry).
This information does not allow us to personally identify you.
3. How We Use Information
We use the collected data exclusively to:
- Conduct giveaways: import comments, apply filters, and select winners randomly and verifiably.
- Detect giveaway rules: analyze the post caption to automatically suggest rules (required mentions, hashtags, etc.).
- Generate cryptographic verification: create a unique hash that certifies the integrity and transparency of the giveaway.
- Improve the application: anonymous technical data helps us fix errors and improve performance.
4. Data Storage and Security
- Local processing: all giveaway data (comments, results, configuration) is processed and stored exclusively on your device.
- No own servers: we do not store comments, usernames, or giveaway results on any external server of ours.
- Secure token: the Instagram access token is stored encrypted in the device's secure storage (Keychain on iOS, EncryptedSharedPreferences on Android) and expires automatically.
- No tracking: we do not use tracking cookies, tracking pixels, or similar technologies for advertising purposes.
5. Sharing Information with Third Parties
We do not sell, rent, or share your personal information with third parties.
The only third-party services that may receive data are:
- Meta (Instagram Graph API): to authenticate your session and read comments from your posts. See Meta's Privacy Policy.
- Firebase (Google): for anonymous usage and performance analytics. See Firebase Privacy Policy.
- Sentry: for anonymous technical error reports. See Sentry Privacy Policy.
6. Requested Instagram Permissions
When connecting your Instagram account, we request the following minimal permissions through Meta:
- instagram_basic: to read basic profile information (username).
- instagram_manage_comments: to read comments from your own posts.
- pages_show_list: to identify the linked Facebook Page (required by Meta).
What we do NOT do:
- We do not post anything on your behalf.
- We do not send direct messages.
- We do not access your followers or following lists.
- We do not access other people's posts.
- We do not delete or modify comments.
7. Data Retention
- Giveaway data remains on your device until you manually delete it or uninstall the application.
- The Instagram access token expires automatically according to Meta's policy (generally 60 days).
- You can disconnect your Instagram account at any time from the application, which immediately deletes the stored token.
8. Your Rights
You have the right to:
- Disconnect your account: at any time from the app's main screen.
- Delete your data: by uninstalling the app, all locally stored data is automatically deleted.
- Revoke permissions: you can revoke RaffleCat's access from your Instagram account settings on Meta (Manage app access).
- Request information: you can contact us to request details about processed data.
9. Children's Privacy
RaffleCat is not intended for children under 13 years of age. We do not intentionally collect information from minors. If you are a parent or guardian and believe your child has provided information, please contact us so we can take the necessary measures.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify of any significant changes through the application or by publishing the new version on this page. We recommend reviewing it regularly.
11. Contact
If you have questions, concerns, or requests related to this Privacy Policy, you can contact us at:
- Email: rafflecat.app@gmail.comp
12. Platform Compliance
RaffleCat complies with:
- Meta Platform Terms: we use the Instagram Graph API in accordance with Meta's platform terms and policies.
- Apple App Store Guidelines: we comply with Apple's review guidelines for apps using third-party login services.
- Google Play Developer Policies: we comply with Google Play's user data policies.