The short version. Audity audits publicly visible Instagram and TikTok profiles.
We never ask for your Instagram, TikTok, or Meta password. We never use OAuth or Login Kit.
We never read your private posts, messages, or logged-in pages. Your audit history stays on your device.
1. What Audity is
Audity is an iOS app that estimates the public-visibility health of a social profile: a shadowban
visibility estimate, an estimated account worth range, a fake-follower estimate, and an AI niche/vibe
summary. Every result is an estimate derived from public signals and is labeled as such
inside the app. Audity does not claim to reveal who viewed a profile, secret admirers, exact unfollower
lists, private messages, or any private account data.
2. What we collect from you
The public @handle you type in, and the platform you chose (Instagram or TikTok).
That is the only thing you actively give us.
No account credentials, ever. There is no login, no password field, no OAuth
consent screen, and no social SDK in the app.
Local audit history — the handles you queried and their public-signal results —
is stored on your device only. Clear it any time from Settings → Clear Local History.
Diagnostics and product telemetry (crashes, performance, feature usage) as
disclosed in the App Store listing's App Privacy section. No advertising SDKs.
3. Third-party services we use
Audity talks to a single first-party backend at https://ait-api.handlelab.app over HTTPS.
That backend uses a small set of third-party services to do its work. All of them operate strictly on
the public, logged-off path — none of them ever receives your Instagram, TikTok, or Meta credentials,
because Audity never collects them.
3.1 Apify — public profile data
What it does: fetches publicly visible Instagram and TikTok profile and post data on our behalf.
What we send: the public @handle you entered and the platform name.
What it returns: publicly visible profile metadata (display name, bio, follower/following
counts, profile picture URL, post count) and recent public post metadata (likes, comments, shares, saves, captions).
What it never touches: private posts, direct messages, logged-in pages, OAuth, Login Kit,
or robots.txt-restricted surfaces.
What it does: serves as a fallback and scale-tier public-profile fetcher for Instagram
when Apify is unavailable or request volume warrants it.
What we send: the same public @handle and platform name.
What it returns: the same shape of publicly visible profile and recent post metadata.
What it never touches: the same red lines as above — no private data, no user login,
no OAuth, no Graph API, no Login Kit.
Provider: HikerAPI.
3.3 AI gateway — niche and vibe analysis
What it does: takes the public bio and recent public post captions
returned above and infers a content niche label, an aesthetic vibe tag, and a short suggestion.
What we send to the model: only the publicly visible bio text, follower/following counts,
and up to five recent public post captions (truncated). No private data of any kind.
What it returns: a small JSON object with niche labels, vibe tags, and a suggestion.
The system prompt explicitly excludes inferences about health, religion, sexuality, or politics.
Provider: an OpenAI-compatible gateway at one.zcode.ltd, routing to
OpenAI / Anthropic class models.
3.4 Apple and Qonversion — subscriptions
What it does: handles subscription billing, trial start, restore, and cancellation
through Apple's standard In-App Purchase flow, with Qonversion as a thin entitlement layer.
What it processes: your Apple ID transaction (handled entirely by Apple) and an opaque
entitlement token. Never your card number, and never your real name unless you provide it through Apple.
What it never touches: no Instagram/TikTok credentials, and no audit data — the billing
layer and the audit layer share nothing.
We do not ask for, store, or transmit social account credentials.
We do not use Instagram Graph API, TikTok Login Kit, OAuth, or any first-party social SDK.
We do not access private posts, follower lists, direct messages, or profile-view data.
We do not build advertising profiles or embed advertising SDKs.
5. Data retention
Audit results are cached on our backend for up to 24 hours so a repeated lookup of the same public handle
does not re-scrape unnecessarily. That cache holds public-signal results keyed by public handle only.
Your local audit history lives on your device and is deleted when you clear it or delete the app.
6. Children
Audity is not directed to children under 13, and we do not knowingly collect data from them.
7. Your choices
Clear local history at any time in Settings.
Manage or cancel your subscription in Apple ID → Subscriptions.
Contact us to ask what a given public handle lookup returned, or to request removal from our cache.
8. Affiliation
Audity is not affiliated with, endorsed by, or sponsored by Instagram, Meta, or TikTok.
All trademarks belong to their respective owners.