This is the page we would want to read if we found ourselves in someone else's report.
Who's Paying, operated by Abscissa AI LLP, joins two kinds of public information: what brands are advertising right now, and what a creator publicly posts. That means reading data about people who did not ask us to, so we would rather explain exactly how it works than leave you guessing. The Privacy Policy covers rights and retention; this page covers mechanics.
What we never touch
Before the detail, the flat denials:
- We never ask for, receive or hold an Instagram password.
- There is no Instagram login, no OAuth, no connected app, no access token. Who's Paying is not authorised on anyone's account, and cannot be.
- We never read direct messages, private accounts, close-friends posts, story viewers, archived content or anything else behind a login — except screenshots of your own Instagram Insights that you choose to upload for a media kit (see below).
- We never post, comment, like, follow, message or take any action from a creator's account. The product cannot write to Instagram at all.
- We never send an email to a brand. Contacts are shown to the creator, who decides whether to write.
Everything below reads public sources or licensed third-party feeds, except the Insights screenshots you upload yourself. None of it requires a credential belonging to a creator.
The six steps of a scan
A scan starts when someone verifies an email and types an Instagram handle. Scanning is free and no credit is spent to run one — the same six steps run either way. Credits are spent to unlock a brand's people and pitch, ten credits to a brand, and on media kit extras described below; every brand's name, niche and fit are shown free, and on your own report the best-fit brand with a contact on file is open free. We never ask for an Instagram login at any point.
Step 1 — Public Instagram profile and posts
What is read: the creator's public Instagram profile and recent public posts.
From which source: a third-party data provider, Monid. An alternate route uses Apify. Neither route uses a creator login.
What is stored: handle, public display name, follower count, post count. Per post: shortcode, post type, play, like and comment counts, caption text, tagged brand names, the paid-partnership flag and the posted-at timestamp. Raw provider responses are cached in an http_cache table so we do not re-fetch and re-pay for the same data.
Basis relied on: for the creator who ran the scan, their own request and consent, given by submitting their handle. For any other person visible in that public data, publicly available information under DPDP section 3(c)(ii).
Step 2 — Reel transcription
What is read: the audio of a few selected public reels from that profile.
From which source: one transcription provider, Deepgram or Groq, set by the service's configuration. There is no automatic switch between them — a scan uses whichever is configured, and if it fails the reel simply has no transcript.
What is stored: the resulting text transcript, kept as a working artifact. We keep transcripts because the words in a reel are the clearest signal of what a creator actually talks about — far better than a caption.
Basis relied on: the creator's request and consent. Only public reels are transcribed. If a reel is private, it is invisible to us.
Step 3 — Meta Ad Library search
What is read: active ads shown in India, in the topic space the earlier steps identified.
From which source: the Meta Ad Library, Meta's own public transparency database of ads.
What is stored: advertiser pages, ad creatives and the search terms we used. Ads sometimes feature other creators, by handle or by face; where that appears in a creative, it is stored as part of the creative.
Basis relied on: publicly available information under DPDP section 3(c)(ii). The Ad Library exists precisely so ads can be publicly inspected. We hold no permission from Meta and claim none.
Step 4 — Language model processing
What is read: your Instagram handle, your public display name, your follower count, post captions, reel transcripts and summaries derived from them. To be plain: this content can identify you, and we do not pretend otherwise.
From which source: sent to Azure OpenAI. Azure OpenAI does not train on this data.
What is stored: the model's outputs — the classified vertical, extracted topics, and drafted report prose — plus metadata about each call for cost control.
Basis relied on: the creator's request and consent. This step produces interpretation, not raw fact; everything it says is a machine-generated estimate.
Step 5 — Brand contact lookup
What is read: for up to five matched brands, a business contact email at that brand's company domain.
From which source: Hunter.io.
What is stored: the contact email, plus the role or name where the provider returns one, attached to the report.
Basis relied on: publicly available information under DPDP section 3(c)(ii) — work addresses at a company domain, published or discoverable as business contact details, not personal inboxes. This is the step we treat most carefully, because the person concerned is a stranger to the whole transaction. Two guardrails: the address is shown to the creator only, and Who's Paying never emails it. If you are that person, see below — we will remove you without argument.
Step 6 — The report
What is read: everything gathered above.
From which source: our own PostgreSQL database.
What is stored: the report — brand matches, the evidence for each, an indicative rate card in INR, and pitch drafts the creator can edit and send themselves.
What is shown: every brand's name, niche and why it fits, and an indicative rate floor. A brand's people and its pitch are shown to a signed-in account that has unlocked that brand — ten credits — or, on the account's own report, for its best-fit brand with a contact on file, free. For a brand with nobody on file, unlocking asks our providers (Hunter.io, and LinkedIn company pages through Apify) for a marketing contact at the brand's confirmed company domain; you are charged only if we find someone; a brand where we found nobody, or whose website we could not confirm, shows its pitch free (with its public Instagram handle, so you can message the brand yourself). What we find is stored as a brand contact under the same rules as every other contact on this page. The rate ceiling is shown to the account that ran the scan. Locked content is removed before the response leaves our server — it is not sitting in the page waiting to be revealed.
Basis relied on: the creator's request and consent. The report is machine-generated and the numbers are estimates. No deal, no income and no brand response is promised, implied or arranged by us.
After the scan: your media kit
What is read: the profile and reel numbers the scan already stored, your profile picture and your top reels' cover images (fetched once from Instagram's image servers when you first open the editor), and — only if you upload them — screenshots of your own Instagram Insights audience screens.
From which source: our own database, Instagram's public image servers, and you. A brand's logo on a brand-pitch kit comes from logo.dev, by the brand's name.
What is stored: a copy of those images in private storage, the kit's text you edit, the audience numbers you confirm, and for each published kit a frozen copy of what you published. Insights screenshots are read by a language model to pre-fill the audience numbers, then deleted 90 days after upload; they are never shown to anyone, you included.
What is shown: only what you publish, to people who have the kit's link. Brands matched in your report are never shown on a public kit.
Basis relied on: your request and consent. You confirm you are the account or authorised to represent it before anything is published.
If you are a creator we scanned and you did not ask us to
Your handle may appear in someone else's report — because someone typed it in, because you feature in a brand's public ad, or because a brand you work with turned up in a match. Scanning needs a verified email, but that email does not have to be yours, so someone else can submit your handle; the Terms of Use forbid submitting one you have no right to, and you do not have to justify asking us to remove it. Write to raghav@ostryaai.com with:
- your Instagram handle, and
- enough to show the handle is yours (a DM from that handle, or a temporary post or story we can see, works fine).
We acknowledge within 24 hours and complete removal within 15 days, deleting the stored data about you and adding the handle to a suppression list so future scans do not re-collect it.
Two honest limits. There is no self-serve delete button — removal is done by hand by an operator. And we cannot remove you from the Meta Ad Library, Instagram or Hunter.io; those are not our systems. We can only remove what is in ours, and we will. Full steps are on Data Removal.
If your work email appeared as a brand contact
If you work at a brand and Step 5 surfaced your business email, you can have it deleted. No conditions.
Write to raghav@ostryaai.com from that work address, or any address that reasonably shows the request is yours, naming the email or the company domain to remove. We acknowledge within 24 hours and complete within 15 days. We delete the contact record and block the address from future lookups — and the whole domain if you prefer, so your company's contacts are never looked up at all.
Again: Who's Paying has never emailed you and will never email you. If you received a pitch, it came from a creator who chose to write to you, and you should reply to them or ask them to stop.
Non-affiliation
Who's Paying and Abscissa AI LLP are not affiliated with, endorsed by, sponsored by, partnered with, or licensed by:
- Meta Platforms, Inc. and its group companies;
- Instagram;
- the Meta Ad Library;
- Hunter.io;
- Monid, Apify, Deepgram, Groq or Microsoft Azure, beyond being a paying customer of the services we use;
- any brand, advertiser or company named in a report.
A brand appearing in a report has not selected the creator, has not been contacted by us, and has committed to nothing. Brand names, logos and handles belong to their owners and are used only to identify the advertiser that ran a public ad.
We read public sources and pay third-party data providers. That is the whole of our access, and we claim no permission we do not have.
Accuracy, and telling us we got it wrong
Public data goes stale. A follower count moves, an ad ends, an employee leaves. A report reflects what the sources said at the moment of the scan and is not re-checked afterwards. If something about you in our systems is wrong, we will correct it — same route as removal, at raghav@ostryaai.com.
Contact
Data source questions, removals and corrections: Raghav Mandhana, Grievance Officer, at raghav@ostryaai.com or +91 93527 04864. Address: 130, 3rd Floor, Right Side, Kirti Nagar, New Delhi, West Delhi, Delhi, India – 110015. More on Contact, Privacy Policy and Data Removal.