Instagram Hashtag Scraper

Is it legal to scrape Instagram? What the terms and the courts say

Published

Is it legal to scrape Instagram? In the United States, collecting public Instagram data is generally not a crime, but doing it while signed in to an Instagram account breaks a contract you agreed to, and the data you collect still carries privacy and copyright rules. Those are three separate questions with three separate answers. Courts have so far been kind to scrapers who read public pages while logged out. They have been much harder on scrapers who used accounts, especially fake ones. And no court ruling about access changes what the GDPR says about a username once it sits in your spreadsheet.

This page walks through each question with the sources, dated, so you can judge your own case. It is a plain-language summary and not legal advice. If a project depends on the answer, a lawyer in your jurisdiction is the person to ask.

The three questions behind "is Instagram scraping legal"

People ask one question and mean three. Keeping them apart is most of the work.

QuestionWhat decides itWhere scrapers have lost
Are you breaking a contract?Instagram's Terms of Use, if you are bound by themUsing accounts to collect data
Are you breaking a computer access law?The CFAA in the US, similar laws elsewhereFake accounts, password-protected pages
Is what you keep lawful to hold and use?Privacy law (GDPR and others), copyrightPersonal data kept without a basis

A project can be fine on one row and exposed on another. A researcher reading public posts while logged out may be clear of the contract question and still owe a data protection notice. A marketer pulling captions with their own account is bound by the terms whatever the data is for.

What Instagram's Terms of Use say

Instagram's Terms of Use, as of October 2026, address automated collection directly. Under the heading on what you cannot do, they say:

You can't attempt to create accounts or access or collect information in unauthorized ways. This includes creating accounts or accessing or collecting information in an automated way without our express permission, regardless of whether such automated access or collection is undertaken while logged-in to an Instagram account.

So the terms forbid automated collection without Instagram's permission, signed in or not. The same section adds a rule that matters to anyone planning to sell what they collect:

You can’t sell, license, or purchase any account or data obtained from us or our Service, regardless of whether such data was obtained while logged-in to an Instagram account.

Notice the phrase "regardless of whether". The court ruling described below found that Meta's terms did not reach logged-off scraping by someone who was not a user, and a contract still binds only the people who accepted it. What is clear is that if you have an Instagram account and you use it to collect data automatically, you are acting against terms you accepted. The usual consequence is practical rather than legal: Instagram restricts or disables the account.

What the courts have said about scraping

Two US cases set the frame most people quote. Neither was about hashtags, and both turned on facts worth reading closely.

CaseWhat was decidedThe detail that mattered
hiQ Labs v. LinkedIn, Ninth Circuit, April 2022Scraping publicly available profiles likely falls outside the federal CFAAPublic pages, no password wall
hiQ Labs v. LinkedIn, district court, November 2022hiQ breached LinkedIn's User AgreementScraping plus fake accounts
hiQ Labs v. LinkedIn, consent judgment, December 2022$500,000 judgment against hiQ, scraping stopped, code and data destroyedStipulated liability, including access through fake accounts
Meta Platforms v. Bright Data, N.D. California, January 23, 2024Meta's terms did not bar Bright Data's logged-off scraping of public Facebook and Instagram dataBright Data was not "using" the services when logged off

hiQ v. LinkedIn

hiQ scraped public LinkedIn profiles. The Ninth Circuit held in April 2022 that hiQ had raised serious questions that reading public pages was not access "without authorization" under the Computer Fraud and Abuse Act. That part is the line people quote as "scraping public data is legal."

The rest of the case is the part people leave out. In November 2022 the district court found hiQ had breached LinkedIn's User Agreement through its scraping and its fake accounts. The parties settled in December 2022 with a $500,000 judgment against hiQ and an injunction requiring it to stop scraping LinkedIn and delete the code and the data it had built. hiQ won the headline and lost the company's data.

Meta v. Bright Data

Meta sued Bright Data for scraping Facebook and Instagram. On January 23, 2024, Judge Edward Chen granted summary judgment to Bright Data on the contract claim. The court found that Bright Data did not "use" Facebook and Instagram when it scraped public pages while logged off, so the terms, which govern users, did not reach it. The court also described the purpose of those terms as stopping account holders from abusing the access their accounts give them.

That is the most favourable ruling a scraper has had against Meta, and its protection is for logged-off collection. It says nothing comforting about a scraper signed in to an account.

Logged in or logged out: why it decides so much

Put the two cases side by side and one fact keeps deciding the outcome: whether the scraper was a user of the site at the time.

Here is the catch for Instagram hashtags. Instagram serves hashtag feeds only to signed-in requests, so there is no logged-out route to the posts under a tag. That leaves two honest options: use an account you control and accept the account risk, or use Instagram's own API, which is the route Instagram permits. Our comparison of Instagram hashtag API options covers what the official route allows and what it does not.

Personal data: public is not the same as free

A post is public. The username on it is still personal data. The GDPR defines personal data as:

any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier ...

A handle is an online identifier, and a caption can say a great deal about the person who wrote it. If the GDPR applies to you, collecting posts makes you a controller of that data, with the duties that come with it. Article 14 covers data you did not get from the person directly and requires you to tell them certain things about the processing. It carves out cases where that would be impossible or take disproportionate effort, notably for research and statistics, and even then expects you to protect the people's rights, including by making the information public.

In practice that means a few habits that cost little:

Other privacy laws, such as the California CCPA, have their own rules. The direction is the same: public does not mean ownerless.

Copyright in the photos

Instagram's terms are explicit that it does not own what people post: "We do not claim ownership of your content." The person who took the photo usually does. Scraping a post's text and numbers for analysis is a different act from republishing the photo. Download images for analysis if you must, but do not repost them, put them in an ad or sell them without the owner's permission. For user generated content campaigns, asking the creator first is the standard practice, and our guide to collecting user generated content on Instagram walks through it.

A checklist before you collect anything

Run through these before the first run, not after.

  1. Can the official API do it? If yes, that is the permitted route. Use it.
  2. Whose account will you use? Only one you control, and one you can afford to lose. Never fake or bought accounts.
  3. Are you planning to sell or license the data? Instagram's terms forbid it. Rethink the plan.
  4. Does the GDPR or a similar law apply? If so, write down the purpose, the basis and the retention date.
  5. Which fields do you actually need? Keep those and drop the rest.
  6. Will anything be published? Publish aggregates, not people.
  7. Is the volume reasonable? A day of posts under one tag is a different act from mirroring a platform.

Where this tool sits

This site documents an Instagram hashtag scraper that runs on Apify. It does not make the questions above go away, and it does not pretend to. What it does is take a clear position on the ones it can.

Because it runs signed in, using it means acting against Instagram's terms as they read today. For many marketing and research jobs people decide that risk is acceptable for a throwaway account. For some it is not, and that is a fair decision.

When you should not scrape at all

Scraping is the wrong tool more often than vendors admit.

If none of those apply, our step by step guide on how to scrape Instagram hashtags and the walkthrough for building a hashtag dataset you can trust cover the practical side.

The honest summary: reading public Instagram data is rarely a crime, using an account to do it breaks Instagram's terms, and the privacy duties follow the data wherever you store it. Decide on all three before the first run.

All articles