Last updated 9 August 2026. This policy covers the pages under
insta.host that serve these tools, and the Windows and macOS applications published here.
In short
- No accounts and no sign-in. Nothing here asks who you are.
- No cookies and no analytics. These pages set no cookies, use no
tracking scripts, and store nothing in your browser.
- Downloads are anonymous. No registration, no email, no download log
tied to you.
- The software has no telemetry. Simple Scanner, APFS Reader for
Windows and the User Profile Migrator never phone home.
- Donations are optional and handled entirely by Stripe. Card details
never reach these servers.
Who is responsible
These pages and tools are published by Patrick Hamid, trading as insta.host, in
Australia. There is no company data-processing operation behind them — this is a
small, self-funded set of utilities.
APFS Reader for Windows
APFS browsing and extraction happen locally on the Windows computer. The
application opens the image or physical disk you select and writes only
extracted copies to the destination you choose.
It has no telemetry
There is no account, analytics, crash reporting or automatic update
check. The application and its native backend open no network connection.
Encrypted volumes
If you enter a FileVault password, it is sent to the local backend through
standard input rather than a process command line. It remains in the GUI
process memory while the password field is populated and is never sent to
InstaHost, MyTechie or another service.
The website
What is collected when you visit
Nothing is stored about you. These pages set no cookies, run no analytics, embed no
tracking pixels and write nothing to your browser’s local storage. There is no
visitor database, and no request log is kept that records who fetched what.
The application server writes a line to its console only when something fails — an
error type and message, with no IP address and no visitor identifier. Those lines exist so
a fault can be diagnosed, and are not used to build any profile of a visitor.
Rate limiting
To stop the donation endpoint being abused, the number of attempts from a network address is
counted in memory for ten minutes and then discarded. It is never written to disk, never
linked to anything else, and is gone when the service restarts.
Hosting and delivery
The site is served through Cloudflare, which acts as a reverse proxy in front of the origin.
Cloudflare necessarily sees the IP address and request details of every visitor in order to
route and protect the traffic, and handles that data under its own privacy terms. It is used
here for delivery and abuse protection only — no Cloudflare analytics or tracking
product is enabled on these pages.
Web fonts
These pages load their typefaces from Google Fonts. That means your browser makes a request
to fonts.googleapis.com and fonts.gstatic.com, and Google receives
your IP address and user agent as part of it. No font request carries a cookie or an
identifier from this site.
Downloads
Downloading a tool requires no account, no email address and no form. The server checks the
file name against its release manifest, serves the file, and keeps no record connecting the
download to you.
Every download is published with its SHA-256 checksum. The page describes the exact signing
state recorded for each artifact: Authenticode for signed Windows builds, Developer ID and
Apple notarisation for the signed macOS build, or an explicit unsigned warning. These details
let you confirm the file you received is the file that was published.
Simple Scanner
Scanning and file creation happen entirely on your Windows PC or Mac. Pages are held in a
temporary per-session folder while you review them and that folder is removed when the app
closes.
It has no telemetry
There is no analytics, account, usage reporting, crash reporting or automatic update check.
Simple Scanner opens no background network connection.
Email is your choice
If you choose Save & email, the app either opens your own mail client or sends
through the SMTP server you configure. On Windows the SMTP password is protected with DPAPI
for your user account; on macOS it is stored in your login Keychain. It is never sent to
InstaHost or MyTechie.
Donations
The “buy me a coffee” page is optional and entirely separate from using the
tools. Payment is handled by Stripe; the checkout happens on Stripe’s
own pages.
- Card details never touch these servers. They are entered on Stripe and
held by Stripe.
- The amount is sent to Stripe to create the checkout session, along with
a name and a short message only if you choose to type them. Both are optional and
both are truncated before they are sent.
- Stripe becomes the controller of the payment data it collects, under its
own privacy policy, and holds transaction records for as long as its legal and financial
obligations require.
- The thank-you page asks Stripe whether a checkout session was paid, so
it can confirm the amount. Nothing from that lookup is stored here.
A donation buys nothing, unlocks nothing and creates no account. It is not required to use
any tool on this site.
The User Profile Migrator
The application is the part that handles real personal data, because moving a Windows
profile is its job. All of that work happens on the machine it is run on.
It has no telemetry
There is no analytics, no usage reporting, no crash reporting and no update check. The
application opens no network connection of its own. The only outbound traffic it can cause
is:
- A Windows Update driver query, and only when you press
Check Windows Update. That request is made by the Windows Update Agent already on
the machine and goes to Microsoft, under Microsoft’s terms.
- Your web browser, if you click one of the links in the application.
- A winget package lookup, and only when you ask it to match installed
programs against the Windows Package Manager catalogue.
What it writes to the machine
Each run writes a log and a CSV manifest under
C:\ProgramData\UserAccountMigrator\Logs. These record file paths, file sizes,
account names and the outcome of every action — the information needed to audit a
migration and to undo it. They never contain the contents of the files that were copied.
Registry exports and program catalogues are written only where you tell them to go. Nothing
is uploaded, and nothing is sent anywhere.
The data it copies
Copied data goes from one location on the machine (or an attached disk) to another location
you nominate. The application does not read inside the files it copies, other than to hash
them when you have specifically asked for SHA-256 deep verification.
Removing it
There is no installer and no service. Delete the executable, and delete the log folder when
you no longer need the audit trail. Nothing else is left behind, and nothing is written
outside the paths named above.
If you run this tool on a client’s machine, you remain the party responsible for their
data under whatever agreement and privacy law applies to you. The logs it produces are
yours to retain or destroy.
What is never collected
- Names, email addresses or phone numbers — except a name you optionally type into a
donation.
- Any file, document or profile content from a machine the tool is run on.
- Advertising or cross-site identifiers of any kind.
- Anything sold, rented or shared with a data broker. Nothing here is ever sold.
Third parties involved
Cloudflare — delivery and abuse protection
Stripe — donation payments only
Google Fonts — typefaces on these pages
Microsoft — Windows Update, only when asked
Your mail or SMTP provider — only when you choose to email a scan
No other third party receives data from these pages or applications. There is no advertising
network, analytics provider or customer data platform in the path.
Your rights and contact
Because no personal data is stored about visitors, there is in practice nothing held here to
access, correct or erase. Where you have made a donation, the records belong to Stripe, and a
request about them can be made either to Stripe directly or through the contact below and
passed on.
Australian Privacy Principles and the GDPR both grant rights of access, correction and
erasure. To exercise them, or to ask anything about this policy, get in touch through
linkedin.com/in/phamid.
Children
These are technician tools. They are not directed at children, and nothing here knowingly
collects information from anyone.
Changes
If this policy changes, the date at the top of the page changes with it. Material changes
will be described in the release notes for the site.