Spriga

How we protect your account

Connecting your Instagram means trusting us with a real credential. Here is exactly what happens to it — no jargon, no invented badges.

Sealed in your browser

Your password (or session) is encrypted on your own device before it is sent, using a public-key sealed box (libsodium). Only ciphertext ever leaves this page — our servers and database never receive the plaintext, and no Spriga employee can read it.

Stored sealed, opened only to log in

We keep the sealed credential so we can quietly sign back in if Instagram expires your session — that is what keeps your account connected without asking you to log in again. It is decrypted only inside the worker at the moment of login, on a proxy matched to your region, and never written back in plain text.

Deleted the moment you disconnect

Disconnecting an account removes the stored credential immediately, along with its session. You are always in control — delete any account, or your whole Spriga login, whenever you want.

A word on Instagram

Spriga is an independent third-party tool and is not affiliated with or endorsed by Instagram or Meta. When Instagram emails you about a “new login,” that is us connecting on your behalf — expected, not a breach.