What Instagram knows about you that you never posted
The advertising dossier inside your export — advertisers holding your information, the interest categories assigned to you, synced contacts, topics and link history — read file by file, without the horror spiral.
There is a folder in every export that people find on a bad evening: the one where the
platform describes you in its own words. Advertisers who hold your information.
Interest categories you never chose aloud. A list of the contacts you once handed over.
Topics, watched videos, links you visited. It reads like a file on you assembled by
someone else, which is exactly what it is — and the first ten minutes with it are
universally the same ten minutes: recognition, then unease, then the slower and more
interesting reading.
This post does that slower reading. It is the dossier stage of this series for a
reason: the sections before it covered what you told the platform (your profile) and
what you did (your activity), and this one covers what the platform concluded — its
inferences about you, delivered back to you as lists. The activity post owns your own
actions and the personal-information post owns your own fields; what follows is
theirs.
Yes, the folder is real, and it is yours to read — that is the point of it existing in
your export. ads_information/ holds the advertisers matched to you, the interest
categories assigned to you, your synced contacts, your topics, and records like videos
watched and links visited. These are the platform's inferences and matchings, not
things you posted, and they are readable one file at a time without a spiral: each
list means "matched to you," not "proven about you." The Privacy tab renders the same
files as counts and tag clouds; this post tells you what each count is counting.
- 1minthe six files that make up the dossier, in one table.
- 5minwhat each list actually asserts, and what it does not.
- ongoing — the honest reading: matched, not measured; inferred, not known.
The folder and its files
The dossier lives with the rest of the privacy material under ads_information/, and
this site's FAQ describes the folder's contents plainly: advertisers matched to you,
off-Instagram activity, and inferences.1 The parser that reads it into the
Privacy tab matches those files by name, which is the shortest honest inventory
there is:2
| File | What it holds | What it is not |
|---|---|---|
| `advertisers_using_your_activity_or_information.json` | Companies Meta has matched to you as holding your information | A list of companies you bought from |
| `ads_interests.json` | Interest categories assigned to your account | Topics you selected |
| `synced_contacts.json` | The contact list uploaded from your device, if you ever synced one | Everyone who follows you |
| `your_topics.json` | Topics Meta associates with your account | Content you posted about |
| `videos_watched.json` | A record of videos watched | Your likes or comments |
| `links_you_have_visited.json` / `link_history.json` | Links clicked through to, where recorded | A complete browsing history |
Two more sit in the same privacy neighbourhood and belong to this reading even though
they are less dramatic: login_activity.json — where and when the account was signed
in from — and the account-history file, which is your own record of changes rather
than an inference. The personal-information post walks the fields you gave; the login
list is the bridge between the two halves of the dossier: an action of yours the
platform kept, sitting beside conclusions of theirs about what that action meant.
What each list actually asserts
The horror in this folder comes from reading each list as a claim. Reading them as
records removes most of it, without making them boring:
Advertisers. The list is companies Meta has matched to your information —
contact details, activity, or both — for advertising purposes. A company appearing
there means a match exists in the system; it does not mean you have an account with
them, that you bought anything, or that a human at that company ever saw your name.
The most common genuine surprise is a company you forgot; the most common false
surprise is inferring a transaction from a match. The count itself is the honest
metric — how many such relationships exist on paper — and the Privacy tab shows it as
a number, not a story. It is also worth knowing the list's texture: most entries are
the mundane advertising supply chain (platforms, networks, retailers you did buy from
once), and the entries worth a second look are the ones you cannot place at all —
which, having read the file, you can now simply name in your notes as unmatched
rather than as ominous.
Ad interests. These are the categories your account is filed under: the platform's
words for what you appear to care about, derived from what you viewed, followed, and
where you lingered. They are model output — which is why the list contains entries you
barely recognise next to entries that are embarrassingly accurate. An interest being
wrong is not an error in the export; the export is faithfully reporting an
approximation, approximations included. The tag cloud in the Privacy tab is exactly
this file, rendered.
Synced contacts. This one is neither inference nor matching — it is a copy of a
list you handed over, if you ever turned on contact syncing from a phone. Its
presence is a record of that decision; its absence means no sync was done or none was
included. If the names are strangers, they are strangers from your own address book.
Its inclusion in an export is also a useful reminder of what "sync" meant when you
tapped it: the list left your device once, became part of the platform's matching
material, and now sits back in your archive as a plain file — which is a considerably
better outcome for you than never having been able to see it at all. The exact name
count the Privacy tab shows is the file's length, nothing interpreted on top.
Topics, watched videos, visited links. The behaviour-shaped trio: what the
platform grouped you into, what you watched, what you clicked. Each is an event log or
a bucketing — observable things — and together they are the raw material the first two
lists are made from. Watching and clicking are your actions; the interest category is
the conclusion drawn from them, which is precisely the boundary this post exists to
draw. The watched-videos and link-history files are the ones people under-read: they
are the closest thing in this folder to a timeline, and they turn "why am I filed
under that?" from an unanswerable complaint into a question you can usually answer by
looking at what the log contains beside it.
Their inferences, not your posts
Every section of this series has an owner, and the boundaries are what keep the
reading honest:
- Your profile fields — name, bio, the details you filled in — are the
personal-information post's subject: things you told the platform.
- Your activity — likes, comments, searches, watches — are the activity post's
subject: things you did.
- Their conclusions — advertisers, interests, topics, matchings — are this post's
subject: things the platform derived, handed back as lists.
The distinction matters beyond bookkeeping because the three have different truth
conditions. Your profile fields are true in the way a form is true — you wrote them.
Your activities are true in the way a log is true — they happened. Their inferences
are true in the way a hypothesis is maintained — they are the current output of an
ongoing matching process, and the export captures one moment of it. A dossier snapshot
from last year and one from today can disagree without either being corrupt, because
neither is a measurement of you; both are records of what the system believed at the
time of their request.
Which is also the answer to the folklore versions of this folder. "Meta knows
everything about me" is not what these files show — they show a bounded set of lists,
each with a named source file, each legible on its own. "The interests are predictions
of my future" is even further off: they are labels built from recorded past
behaviour. What the folder supports is a precise and considerably less cinematic
claim: here is how you were categorised, here is who was matched to you, and here is
the behaviour those conclusions were built from — all of it in your own archive,
because an export that hid this section would be an export that hid its own reasoning.
Reading the folder like a ledger
The useful way through this section is procedural rather than emotional — three passes,
in order, and then you are done:
- Advertisers pass. Read the list once, top to bottom, and split it into
recognised and unrecognised. The recognised column is finished — no further
analysis needed. The unrecognised column gets its own note in your files, spelled
out as "matched, source unknown at read time" rather than as a suspicion. Nothing
in the export tells you which of your signals produced a given match, and
pretending otherwise is where speculation starts. - Interests pass. Read the tag cloud looking only for disagreement: entries that
are flatly wrong are the interesting ones, because they show the inference process
failing in a way you can name. Entries that fit need nothing from you — a correct
label is not a revelation. - Contacts pass. If
synced_contactsexists, decide whether the decision thatcreated it still stands. This is the one file in the folder with a future-facing
consequence, because it reflects a setting you can revisit on the platform's side;
the export's role is to have shown you it exists.
Total time: minutes, because the lists are what they are — finite, labelled, and
already sorted by the parser into the Privacy tab's cards. What the three passes buy
is the end of the spiral: every item is either understood, noted as unmatched, or
understood as a wrong label. None of the three needs you to conclude anything about
the platform's intentions, which is the part of the horror that never resolves,
because the folder does not contain the evidence to resolve it either way.
The off-Instagram part
One subsection deserves separating because it looks like surveillance and is closer to
bookkeeping: the off-Instagram activity in the same folder. The shared-interest
relationships between Meta and other sites and apps — the "this site shared your
activity with Meta" plumbing — leave records on this side too, which is what the
folder description means by off-Instagram activity.
The honest reading has two halves. It is genuinely notable that this cross-site
activity appears in a personal export at all — that is the transparency mechanism
working, not a scandal in the file. It is also bounded: what shows up is what was
shared with the platform, not your browsing as such. Sites you visited that never
participate leave nothing here, and the record is a participation log of the
advertising ecosystem rather than a diary of your web life. Reading it as "they
watched me everywhere" inverts the direction of the data: the file shows what others
sent to Meta, kept where you can now read it.
There is a third, quieter observation worth making about the whole folder: every file
in it is a thing the platform was required to be able to hand you — the kind of
record that exists because transparency obligations demand it, wrapped in the same
archive as your own posts. That is why the dossier reads differently from a leak: a
leak is a file you were never meant to hold, and this one arrived addressed to you,
on request, in a structure you can parse down to the field.
Where this shows up in the app
The Privacy tab is this folder, rendered: stat cards for ad interests, advertisers,
synced contacts and topics — each showing the count the underlying file contains —
then the tag clouds for the interest and topic lists themselves. The footprint
percentage the tab displays is arithmetic on those counts (a set share of each list
size, capped), which makes it a summary of exposure by count, not a verdict about
risk; the lists underneath are the actual evidence, and they are what this post has
been reading.3
The structure of that tab is worth stating in one sentence because it mirrors the
reading order above: counts first, itemised lists second, interpretation never. A card
that says twelve advertisers is a fact about a file; a caption underneath explaining
what advertisers are is orientation; there is deliberately nothing on the tab that
tells you how to feel about the number, because the feeling was never data.
The Compare view carries the same two counters side by side for anyone comparing two
exports: ad interests and advertisers, per account. Counts moving between exports is
itself information — a growing advertiser list is a growing set of matches — and
reading that change is the dossier equivalent of the follower-diff reading the
relationships post teaches: numbers first, stories about the numbers only after.
What the horror gets wrong, and what it gets right
The Reddit-thread reading of this folder — screenshot, outrage, "they know
everything" — gets one thing right and three things wrong, and the order matters:
- Right: this is real data, and it is yours. The lists exist, they are in the
export, and the ability to read them is the transparency working as designed.
- Wrong: it is not a dossier of your life. It is a dossier of your matchability:
interests assigned, companies matched, contacts compared. The posts you never made,
the thoughts you never typed, and most of what you did off-platform are not in it —
see the five-questions post for the boundary. - Wrong: it is not secret. It arrived in your own archive, unencrypted, next to
your own posts. Secret files are not delivered on request to the account holder.
- Wrong: recognising yourself in it is not a confession. An interest category you
agree with is a label that happened to fit; it is evidence about the platform's
inference quality, not new information about your interior life.
The response the folder actually earns is the unglamorous one: read the lists, note
the advertisers holding your contact information you do not recognise, check whether
the synced-contact list reflects a decision you still agree with — and remember that
the file itself is the custody question, not the inference question. Who should hold
this archive is the security post's subject; what the archive says about you is
here.
Are these files proof that Instagram is tracking me?
They are proof of matching: advertisers matched to your information, interests
assigned from your recorded behaviour, and — where you enabled syncing — a contacts
copy. Each item names its source file and can be read as such. They are the platform's
conclusions delivered to you, which is a different thing from a surveillance log, and
the five-questions post draws the line on what is absent from the whole export.
Why are some ad interests completely wrong?
Because they are model output built from behavioural signals — what was watched,
followed, lingered on — and models overfit, misattribute, and decay over time. The
export faithfully reports the list, errors included; a wrong entry is information about
the inference process, not corruption in your archive. Two exports taken months apart
can disagree, which is the cleanest proof that the list is a maintained hypothesis
rather than a fact about you.
Can I remove advertisers or interests from my export?
Not from the export — the file is a snapshot of what the account held at request time,
and editing it would falsify the record. Managing the lists on the platform's side is
a platform question; a later export then reflects whatever the account holds then. The
export's job is to show you the current state honestly, which it does by containing it.
What is the difference between this folder and my activity section?
Direction. Activity is what you did — events your account recorded as yours. This
folder is what the platform concluded from what it saw, plus matchings made against
your information. The first is a log, the second is a model, and reading either one as
the other is where both misreadings start.
Does this section mean my export contains other people's data?
No. Synced contacts contains names and numbers from a list you uploaded — your own
address book, which your archive is entitled to reflect — and every other list is
about your account's matching, not other people's records. Company names and interest
labels are not people's data, and no conversation, profile, or action of anyone else
appears in this folder. The dossier is strictly about how you were categorised.
Where this was checked
1: The ads_information/ folder's contents — advertisers matched to you,
off-Instagram activity, inferences — as described in this site's own FAQ on export
folder contents, and the file names carried in the export itself.
2: packages/shared/src/parsers/privacy.ts — the JSON and HTML collectors matchads_interests, advertisers_using_your_activity_or_information /advertisers_using_your_info, synced_contacts, your_topics, videos_watched,links_you_have_visited / link_history, login_activity, and the account-history
files by name into the Privacy tab's data.
3: The Privacy tab (apps/web-next/src/views/Privacy.tsx) renders these lists as
stat cards with counts, tag clouds for interests and topics, and a capped percentage
computed from those counts — the tab displays the file's contents, it does not
re-derive them.
Footnotes
- folder
- code
- tab