Legal
Privacy policy
This is the policy the Chrome Web Store listing links to. It describes what the SocialStalker extension keeps on your device and what it transmits.
Last updated 24 August 2026
01
Who this covers
SocialStalker: Social Media Downloader is a browser extension published by gitnasr.com. This policy covers the extension and this website. It does not cover Instagram, Facebook or any other site you visit while it is installed — those have their own policies.
There is no account system. You never sign in to SocialStalker, and the extension never asks for a password, an email address or a payment method.
02
What stays on your device
The following is written to your browser storage and is never uploaded as a set:
- Your settings: video poster frame, parallel download count, and the story seen-state blocker toggle.
- A generated install identifier (a random UUID). It is not derived from anything about you or your hardware.
- Short-lived caches used to resolve accounts and media, so repeated actions do not refetch the same thing.
- A queue of pending analytics events, held until they can be delivered.
Uninstalling the extension removes all of it. Downloaded files go straight from the platform to your normal downloads folder; they are never routed through, copied to or stored on any server operated by us.
03
What is transmitted, and to where
The extension reports usage to an endpoint operated by the developer at ss-tel.secretzone.top. On first run it enrols the install identifier and receives a token; after that it sends events, plus a periodic heartbeat roughly every six hours. Reporting is a built-in part of version 2.0.0 and cannot be switched off from the settings page.
An event is recorded when you use a feature, and can include:
- The action taken (for example: profile picture viewed, story downloaded, profile archived), when it happened, how long it took, and whether it succeeded or failed.
- The URL of the page the action was taken on, and the account the content belongs to.
- The number of files, their type, and the media URLs and dimensions involved.
- The extension version and which on-page control was used.
- The identifier of the Instagram or Facebook account signed in to the browser at the time, read from the platform cookie.
- The raw responses the platform returned for the request, captured for diagnosing failures.
The heartbeat carries the extension version, your current settings, and the platform account identifiers signed in at that moment. Crash and error reports are sent to Sentry, a third-party error monitoring service, from all three parts of the extension.
To resolve a Facebook profile picture the extension may look the profile up through the public service at lookup-id.com. Only the public profile URL is sent, without cookies or credentials.
04
Why
Instagram and Facebook change their markup and their private endpoints without notice, and a feature that worked yesterday can fail silently today. The reporting above is what makes those failures visible and fixable, and it is used for that: diagnosing breakage, understanding which features are used, and improving the extension.
The data is not sold. It is not shared with third parties for advertising, and it is not used to build profiles for advertising, creditworthiness or lending purposes.
05
Permissions, and what each is for
- downloads — writes files to your downloads folder.
- cookies and webRequest — read the platform session your browser already holds, so requests are made as you.
- scripting, declarativeNetRequest and activeTab — inject the on-page controls and, when enabled, drop story seen-state requests.
- storage and alarms — keep settings and schedule the delivery of queued events.
- contextMenus — the Facebook right-click entry.
- Host access — instagram.com and facebook.com, plus the reporting endpoint, the Sentry endpoint and lookup-id.com.
06
The seen-state blocker
The option to watch stories without being seen is off unless you turn it on. It drops the seen-state requests the extension can observe, on both the REST path and the GraphQL mutation. It is best effort: a view can still register through a path the extension does not see, and Instagram applies seen state optimistically in the interface, so what you see on screen is not proof of what the server recorded.
07
Retention and deletion
Events are retained only as long as they are useful for diagnostics and product decisions. Because there is no account, the only handle on your records is the install identifier. To request deletion, email [email protected] from any address and include that identifier; you can also clear everything locally by removing the extension.
08
Children
SocialStalker is not directed at children under 13 and should not be used by them.
09
Changes and contact
If this policy changes materially, the date at the top of this page changes with it and the updated version is published here before the release it describes. Questions go to [email protected].