Is it legal to scrape Instagram? What the terms and the courts say
Published
Is it legal to scrape Instagram? In the United States, collecting public Instagram data is generally not a crime, but doing it while signed in to an Instagram account breaks a contract you agreed to, and the data you collect still carries privacy and copyright rules. Those are three separate questions with three separate answers. Courts have so far been kind to scrapers who read public pages while logged out. They have been much harder on scrapers who used accounts, especially fake ones. And no court ruling about access changes what the GDPR says about a username once it sits in your spreadsheet.
This page walks through each question with the sources, dated, so you can judge your own case. It is a plain-language summary and not legal advice. If a project depends on the answer, a lawyer in your jurisdiction is the person to ask.
The three questions behind "is Instagram scraping legal"
People ask one question and mean three. Keeping them apart is most of the work.
| Question | What decides it | Where scrapers have lost |
|---|---|---|
| Are you breaking a contract? | Instagram's Terms of Use, if you are bound by them | Using accounts to collect data |
| Are you breaking a computer access law? | The CFAA in the US, similar laws elsewhere | Fake accounts, password-protected pages |
| Is what you keep lawful to hold and use? | Privacy law (GDPR and others), copyright | Personal data kept without a basis |
A project can be fine on one row and exposed on another. A researcher reading public posts while logged out may be clear of the contract question and still owe a data protection notice. A marketer pulling captions with their own account is bound by the terms whatever the data is for.
What Instagram's Terms of Use say
Instagram's Terms of Use, as of October 2026, address automated collection directly. Under the heading on what you cannot do, they say:
You can't attempt to create accounts or access or collect information in unauthorized ways. This includes creating accounts or accessing or collecting information in an automated way without our express permission, regardless of whether such automated access or collection is undertaken while logged-in to an Instagram account.
So the terms forbid automated collection without Instagram's permission, signed in or not. The same section adds a rule that matters to anyone planning to sell what they collect:
You can’t sell, license, or purchase any account or data obtained from us or our Service, regardless of whether such data was obtained while logged-in to an Instagram account.
Notice the phrase "regardless of whether". The court ruling described below found that Meta's terms did not reach logged-off scraping by someone who was not a user, and a contract still binds only the people who accepted it. What is clear is that if you have an Instagram account and you use it to collect data automatically, you are acting against terms you accepted. The usual consequence is practical rather than legal: Instagram restricts or disables the account.
What the courts have said about scraping
Two US cases set the frame most people quote. Neither was about hashtags, and both turned on facts worth reading closely.
| Case | What was decided | The detail that mattered |
|---|---|---|
| hiQ Labs v. LinkedIn, Ninth Circuit, April 2022 | Scraping publicly available profiles likely falls outside the federal CFAA | Public pages, no password wall |
| hiQ Labs v. LinkedIn, district court, November 2022 | hiQ breached LinkedIn's User Agreement | Scraping plus fake accounts |
| hiQ Labs v. LinkedIn, consent judgment, December 2022 | $500,000 judgment against hiQ, scraping stopped, code and data destroyed | Stipulated liability, including access through fake accounts |
| Meta Platforms v. Bright Data, N.D. California, January 23, 2024 | Meta's terms did not bar Bright Data's logged-off scraping of public Facebook and Instagram data | Bright Data was not "using" the services when logged off |
hiQ v. LinkedIn
hiQ scraped public LinkedIn profiles. The Ninth Circuit held in April 2022 that hiQ had raised serious questions that reading public pages was not access "without authorization" under the Computer Fraud and Abuse Act. That part is the line people quote as "scraping public data is legal."
The rest of the case is the part people leave out. In November 2022 the district court found hiQ had breached LinkedIn's User Agreement through its scraping and its fake accounts. The parties settled in December 2022 with a $500,000 judgment against hiQ and an injunction requiring it to stop scraping LinkedIn and delete the code and the data it had built. hiQ won the headline and lost the company's data.
Meta v. Bright Data
Meta sued Bright Data for scraping Facebook and Instagram. On January 23, 2024, Judge Edward Chen granted summary judgment to Bright Data on the contract claim. The court found that Bright Data did not "use" Facebook and Instagram when it scraped public pages while logged off, so the terms, which govern users, did not reach it. The court also described the purpose of those terms as stopping account holders from abusing the access their accounts give them.
That is the most favourable ruling a scraper has had against Meta, and its protection is for logged-off collection. It says nothing comforting about a scraper signed in to an account.
Logged in or logged out: why it decides so much
Put the two cases side by side and one fact keeps deciding the outcome: whether the scraper was a user of the site at the time.
- Logged out, public pages: the strongest position under US law, as of the rulings above. No account means no accepted terms to breach, and public pages are hard to frame as unauthorized access.
- Logged in with your own account: you are bound by the terms. A breach is a contract matter, and the realistic outcome is losing the account.
- Logged in with fake or bought accounts: the position that lost in hiQ. Fake identities turn a contract question into an access question.
Here is the catch for Instagram hashtags. Instagram serves hashtag feeds only to signed-in requests, so there is no logged-out route to the posts under a tag. That leaves two honest options: use an account you control and accept the account risk, or use Instagram's own API, which is the route Instagram permits. Our comparison of Instagram hashtag API options covers what the official route allows and what it does not.
Personal data: public is not the same as free
A post is public. The username on it is still personal data. The GDPR defines personal data as:
any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier ...
A handle is an online identifier, and a caption can say a great deal about the person who wrote it. If the GDPR applies to you, collecting posts makes you a controller of that data, with the duties that come with it. Article 14 covers data you did not get from the person directly and requires you to tell them certain things about the processing. It carves out cases where that would be impossible or take disproportionate effort, notably for research and statistics, and even then expects you to protect the people's rights, including by making the information public.
In practice that means a few habits that cost little:
- Collect only the fields the job needs. A sentiment study needs captions and dates. It rarely needs to keep usernames once the analysis is done.
- Set a retention date and delete the raw rows when it passes.
- Write down why you hold the data. A one-paragraph note on purpose and basis is what you will be asked for first.
- Do not publish rows. Charts and counts travel well. A table of other people's handles and captions does not.
Other privacy laws, such as the California CCPA, have their own rules. The direction is the same: public does not mean ownerless.
Copyright in the photos
Instagram's terms are explicit that it does not own what people post: "We do not claim ownership of your content." The person who took the photo usually does. Scraping a post's text and numbers for analysis is a different act from republishing the photo. Download images for analysis if you must, but do not repost them, put them in an ad or sell them without the owner's permission. For user generated content campaigns, asking the creator first is the standard practice, and our guide to collecting user generated content on Instagram walks through it.
A checklist before you collect anything
Run through these before the first run, not after.
- Can the official API do it? If yes, that is the permitted route. Use it.
- Whose account will you use? Only one you control, and one you can afford to lose. Never fake or bought accounts.
- Are you planning to sell or license the data? Instagram's terms forbid it. Rethink the plan.
- Does the GDPR or a similar law apply? If so, write down the purpose, the basis and the retention date.
- Which fields do you actually need? Keep those and drop the rest.
- Will anything be published? Publish aggregates, not people.
- Is the volume reasonable? A day of posts under one tag is a different act from mirroring a platform.
Where this tool sits
This site documents an Instagram hashtag scraper that runs on Apify. It does not make the questions above go away, and it does not pretend to. What it does is take a clear position on the ones it can.
- It uses a session from an account you control. It holds no Instagram accounts, has no account pool and creates no accounts. That keeps it out of the fake-account pattern that lost in hiQ.
- The account risk is yours, and the getting started guide says so plainly: "Expect the account you use to be rate limited by Instagram and eventually actioned, so use one you are willing to lose."
- It collects what you asked for and stops. One hashtag, an exact result limit and a date window, written to your own dataset. That makes it easy to collect only what the job needs.
Because it runs signed in, using it means acting against Instagram's terms as they read today. For many marketing and research jobs people decide that risk is acceptable for a throwaway account. For some it is not, and that is a fair decision.
When you should not scrape at all
Scraping is the wrong tool more often than vendors admit.
- You need a handful of posts. Read them in the app and copy what you need. Our guide to searching Instagram hashtags without an account covers what you can see by hand.
- The account you would use is your business account. Losing it costs more than any dataset is worth.
- You need a published, citable dataset. Reviewers will ask how it was collected. The official API, or a data access program, gives you an answer that holds up.
- You want to resell the data. That is the use Instagram's terms forbid most directly, and the one most likely to draw a lawsuit.
If none of those apply, our step by step guide on how to scrape Instagram hashtags and the walkthrough for building a hashtag dataset you can trust cover the practical side.
The honest summary: reading public Instagram data is rarely a crime, using an account to do it breaks Instagram's terms, and the privacy duties follow the data wherever you store it. Decide on all three before the first run.