What you told Instagram about yourself

Your profile details live in a few small files under personal information. The parser normalizes different shapes (modern string_map_data with label_values merged, and older simple objects), filters untrusted labels to avoid prototype pollution, and extracts only what is actually recorded.

Most profile details come from a small instagram_profile_information.json (or similar) and related personal files. The parser reads multiple shapes (modern string_map_data with label_values merged, and older flat objects), fills PersonalData fields, and only records what actually exists in the export.

What it collects

PersonalData includes: username, fullName, bio, email, phone, gender, birthday, profilePicUrl, accountCreated (seconds), isPrivate, isProfessional, professionalCategory, accountBasedIn, website. Not every field is present in every export.

Normalizing different shapes

The parser first extracts from personal_info/personal_information or the root. For modern exports, it merges label_values into profile_user[0].string_map_data (wrapping if missing), then reads string_map_data with case-insensitive key matching for common fields: username, full name/name, bio/biography, email, phone (excluding "confirmed/verified/confirmation" variants), gender, date of birth/birthday, profile photo from media_map_data["Profile Photo"], account created/joined/signup timestamp, private flag, website/url. Legacy flat fields (e.g. profile.full_name, info.email, info.birthday, info.gender, createdAt.timestamp) are used as fallbacks.

Account created and location

accountCreated comes from account_created_date/account_created (timestamp seconds) or from the string_map_data entry labeled account created/joined/signup. accountBasedIn comes from account_based_in.based_in or from a Location label_values entry that contains a dict with name/address.

Safety note

Label keys from untrusted JSON are filtered (__proto__, constructor, prototype rejected) and assignments into objects go through a filtered assignSafe (using Object.defineProperty) to avoid prototype-pollution risks when merging arbitrary string_map_data keys. This is a conservative hardening specific to parsing untrusted archive data.

What can be missing

Email/phone may be absent or redacted depending on your export. Birthday/gender may not be recorded. profilePicUrl appears when present in profile media; not all exports include the full history in this file. Treat everything as "what Instagram recorded for this export request" - not as a complete verified identity record.

Where is my 'account created' date?

From account_created_date/account_created or from the profile_user string_map_data entry labeled "account created"/"joined"/"signup". It is returned in seconds since epoch.

Why is my email/phone missing?

It depends on what was included in your Download Your Information request and what the account had on record. Not every export includes contact details.

Does this include all my profile photos?

No. Profile photo history may be in profile_photos.json (covered under Content) rather than only in this personal info file.

Can the labels be weirdly named?

Yes. The parser matches keys case-insensitively (e.g. "Full Name", "full name", "name"). Phone is filtered to avoid "phone confirmed" false positives.

Sources of truth

  • packages/shared/src/types/personal.ts - PersonalData fields.
  • packages/shared/src/parsers/personal.ts - extractPersonalInfo, assignSafe/safeLabelKey (prototype-pollution guard), merging label_values into profile_user.string_map_data, case-insensitive extraction, extractBasedIn.
What you told Instagram about yourself — LMKFR Blog