HCLOUT

Blog / Gone but not forgotten

What Happened to Hyp3r? The Instagram Data Scraping Scandal That Killed a $23 Million Startup

Hyp3r secretly scraped millions of Instagram users' locations and stories. Instagram banned them, and the $23M startup collapsed. Full story inside.

Updated 2026-03-17

What Happened to Hyp3r? The Instagram Data Scraping Scandal That Killed a $23 Million Startup — Gone but not forgotten

In August 2019, a Business Insider investigation revealed that a San Francisco marketing company called Hyp3r had been secretly collecting and storing the location data, personal posts, and Instagram Stories of millions of users. The company wasn't some shady bot operation. Hyp3r was a trusted Facebook Marketing Partner, backed by $23 million in venture capital, with Fortune 500 clients like Marriott International. And they were scraping Instagram's platform in ways that violated every privacy rule they had agreed to follow.

Quick Answer: Hyp3r was a location-based marketing platform that was banned from Instagram on August 7, 2019, after Business Insider exposed its mass data-scraping operation. The company had been harvesting public Instagram posts, geotagged location data, and even disappearing Instagram Stories from millions of users, then selling this intelligence to hotel chains, gyms, and retail brands. Instagram sent Hyp3r a cease and desist letter and permanently revoked its platform access. The $23 million startup never recovered and is now permanently closed.


What Was Hyp3r?

Hyp3r was a "location intelligence" marketing platform founded in 2015 by Carlos Garcia, Jorge Suarez, Juan Carlos Hernandez, and Omar Ramos. The company was headquartered in San Francisco and positioned itself as a tool that helped businesses engage with customers in real time based on where they were physically located.

How Hyp3r Worked

The pitch to businesses was compelling. Imagine you run a hotel chain. A guest checks into your property, takes a photo of the lobby, and posts it to Instagram with a location tag. Within minutes, your front desk team sees the post in the Hyp3r dashboard and sends a welcome message or offers a room upgrade.

That was the legitimate version of what Hyp3r did. The reality was far more invasive.

Hyp3r's platform combined several data collection methods:

Geotagged Social Posts: The company collected every public Instagram post tagged at specific locations, including the poster's username, profile information, post content, comments, and likes.

Location Geofencing: Businesses could set up digital perimeters (geofences) around physical locations. Hotels, airports, gyms, shopping malls, and casinos could monitor every public social media post made within those boundaries.

Anonymous Device Tracking: Hyp3r tracked the movement of individual customers through anonymous mobile device IDs, building profiles of where people went and how often.

Instagram Stories Collection: This was the most alarming practice. Instagram Stories are designed to disappear after 24 hours. Hyp3r built tools that automatically saved and archived Stories before they vanished, something Instagram's API explicitly did not allow.

Who Used Hyp3r?

The company attracted major corporate clients. Marriott International was their most prominent customer, using Hyp3r across their hotel properties to identify and engage guests in real time. Other clients included 24 Hour Fitness, Brookfield Properties, and various hospitality and retail brands.

Hyp3r was also a registered Facebook Marketing Partner, a designation that gave the company a veneer of legitimacy and official approval. Being a Facebook Marketing Partner meant that Facebook (Instagram's parent company) had vetted and endorsed the company.


The Business Insider Investigation

On August 7, 2019, Business Insider published an investigation that exposed the full scope of Hyp3r's data collection. The reporting drew immediate comparisons to the Cambridge Analytica scandal that had rocked Facebook the year before.

What the Investigation Found

The findings were extensive:

Mass Data Harvesting: Hyp3r was collecting data from millions of Instagram users' public posts, building detailed profiles that included their locations, posting habits, social connections, and content preferences.

Exploiting a Security Flaw: Hyp3r took advantage of an Instagram security lapse that allowed non-logged-in users to view posts from public location pages. This meant Hyp3r could scrape location data at scale without even needing authenticated API access for some of its operations.

Storing Disappearing Content: Instagram Stories are built around impermanence. Users share moments knowing they'll disappear in 24 hours. Hyp3r was silently archiving these Stories, stripping away the privacy guarantee that users relied on.

Policy Violations: Despite being a Facebook Marketing Partner, Hyp3r was operating in direct violation of Instagram's data collection policies. Instagram's platform policy explicitly prohibited the kind of mass scraping and data storage Hyp3r was engaged in.

The Cambridge Analytica Comparison

Several publications drew parallels between Hyp3r and Cambridge Analytica, the political consulting firm that harvested data from millions of Facebook users to build voter profiles. SiliconAngle ran a piece titled "Shades of Cambridge Analytica: Instagram terminates partner collecting user data."

The comparison was apt. Both companies operated as trusted platform partners. Both collected far more data than their agreements allowed. Both used that data to build detailed profiles for commercial purposes. And in both cases, the platform failed to catch the violation until journalists exposed it.


Instagram's Response

Instagram moved quickly after the Business Insider story broke.

Immediate Actions

Within hours of the publication, Instagram:

  • Sent Hyp3r a formal cease and desist letter
  • Permanently banned Hyp3r from the platform
  • Revoked the company's Facebook Marketing Partner status
  • Patched the security vulnerability that allowed non-logged-in users to view location page posts

An Instagram spokesperson told reporters: "Hyp3r's actions were not sanctioned and violate our policies. As a result, we've removed them from our platform. We've also made a product change that should help prevent other companies from scraping public location pages in this way."

How Instagram Failed

The scandal also reflected poorly on Instagram. Several uncomfortable questions emerged:

Why wasn't this caught sooner? Hyp3r had been scraping Instagram data for years. The company raised $17 million in Series A funding in September 2018, nearly a year before being banned. During that time, the scraping continued unchecked.

What does "Marketing Partner" mean? Facebook's Marketing Partner designation was supposed to signal that a company had been vetted and approved. Hyp3r's behavior proved that the vetting process was inadequate.

Where was the monitoring? If Instagram couldn't detect that a partner was mass-scraping location data and archiving disappearing Stories, what else was happening on the platform without oversight?

Public Knowledge, a consumer advocacy group, issued a statement: "This is yet another troubling example of big tech companies failing to monitor their own platforms and protect user data."


How Hyp3r Defended Itself

After the ban, Hyp3r attempted damage control.

The Company's Position

Hyp3r's initial response was to minimize the scope of the violation. Carlos Garcia, the company's CEO, told CNBC that Hyp3r's data collection was limited to publicly available information and that the company had not violated any laws.

Garcia also indicated that the company planned to request a meeting with Facebook to discuss the situation, suggesting Hyp3r believed the ban might be reversible.

The Meeting That Changed Nothing

CNBC reported that Hyp3r was "planning talks with Facebook" after being booted from Instagram. If those talks happened, they didn't produce results. Facebook and Instagram showed no interest in reinstating the company.

The distinction Hyp3r tried to draw between "publicly available data" and "data collected in violation of platform policies" didn't hold up. Just because a post was technically public didn't mean Hyp3r had the right to systematically scrape, store, and sell it. The platform's terms of service existed precisely to prevent this kind of bulk data collection.


The Collapse of Hyp3r

Without Instagram access, Hyp3r's business model evaporated.

Why the Ban Was Fatal

Hyp3r's entire value proposition depended on real-time access to geotagged social media posts, and Instagram was the dominant source of that data. Without it, the platform had nothing to offer clients.

Consider the math: Instagram was the largest source of geotagged public posts in the world. No other platform came close in terms of location-tagged content volume. Losing Instagram access was like a search engine losing access to the internet.

The Financial Fallout

Hyp3r had raised $23 million in venture capital from investors including SVB (Silicon Valley Bank), Thayer Ventures, and Structure Capital. The $17.3 million Series A round closed in September 2018, less than a year before the scandal broke.

Those investors lost their money. Hyp3r is now listed as "permanently closed" on business databases. The company never recovered, never pivoted, and never raised additional funding.

What Happened to the Team

Carlos Garcia's first company, Scrapblog, had grown to 3.5 million users and was one of the first apps on Facebook's platform. His second company, Nobox, worked with global brands like Netflix, Samsung, and Marriott. Hyp3r was supposed to be his biggest success. Instead, it became a case study in how quickly a startup can collapse when its core business practices are exposed as policy violations.


Timeline: The Complete History of Hyp3r

DateEvent
2015Hyp3r founded by Carlos Garcia and co-founders in San Francisco
2016-2017Company grows, signs Marriott International and other major clients
2017Achieves Facebook Marketing Partner status
September 2018Raises $17.3 million Series A from SVB, Thayer Ventures, Structure Capital
2018-2019Continues mass data scraping from Instagram at scale
August 7, 2019Business Insider publishes investigation exposing data scraping
August 7, 2019Instagram sends cease and desist, permanently bans Hyp3r
August 8, 2019Hyp3r seeks meeting with Facebook; CNBC, TechCrunch, Engadget cover story
Post-2019Hyp3r ceases operations; company listed as permanently closed

The Broader Impact on Location Marketing

The Hyp3r scandal forced the entire location marketing industry to reckon with how it collected data.

Platform Policy Tightening

Instagram patched the specific vulnerability that Hyp3r exploited, preventing unauthenticated access to location page data. But the changes went further. Facebook (now Meta) tightened its Marketing Partner requirements and increased scrutiny of how partners accessed platform data.

The Privacy Conversation

The Hyp3r case reinforced a growing public awareness that location data is deeply personal. Knowing where someone is at a given moment reveals intimate details about their life, including where they sleep, work out, eat, worship, and travel.

When users tag a location on Instagram, they're sharing that information with their followers. They're not consenting to a corporate surveillance system that tracks their movements across hotels, airports, and shopping malls.

GDPR and CCPA Implications

The Hyp3r scandal coincided with a period of rapidly tightening privacy regulations. The EU's GDPR was already in effect, and California's Consumer Privacy Act (CCPA) was set to take effect in January 2020. Both laws imposed strict requirements on how companies collect, store, and use personal data.

For location marketing companies, the message was clear: the era of treating publicly posted data as a free resource was ending. Legal and regulatory frameworks were catching up with the technology.


Lessons from the Hyp3r Scandal

1. "Publicly Available" Doesn't Mean "Free to Exploit"

Hyp3r's central defense was that it only collected public data. This argument missed the point entirely. Platform terms of service exist to regulate what partners can do with data, regardless of whether that data is technically public. Scraping millions of posts and building surveillance profiles goes far beyond what users intend when they post a vacation photo.

2. Trusted Partner Status Means Nothing Without Oversight

Hyp3r was a Facebook Marketing Partner. Marriott was a client. Venture capitalists invested $23 million. None of these validations prevented the company from violating the very platform it depended on. Trust without verification is meaningless.

3. Disappearing Content Should Actually Disappear

The fact that Hyp3r archived Instagram Stories was particularly troubling. Users chose the Stories format specifically because the content would disappear. Silently overriding that choice is a violation of user trust that goes beyond policy technicalities.

4. Single-Platform Dependency Is a Business Risk

Hyp3r built its entire business on Instagram's data. When Instagram cut access, the company had nothing to fall back on. This is a recurring pattern in social media businesses: building on someone else's platform means they can pull the rug out at any moment.


Frequently Asked Questions

What was Hyp3r?

Hyp3r was a San Francisco-based location intelligence marketing platform founded in 2015. It collected geotagged social media posts, Instagram Stories, and location data to help businesses like hotels and gyms engage with customers in real time. The company raised $23 million in venture capital before being banned from Instagram.

Why was Hyp3r banned from Instagram?

Instagram permanently banned Hyp3r on August 7, 2019, after Business Insider exposed that the company was mass-scraping user data, including locations, posts, and disappearing Instagram Stories. This violated Instagram's platform policies despite Hyp3r being a registered Facebook Marketing Partner.

How did Hyp3r collect Instagram Stories?

Hyp3r built automated tools that captured and stored Instagram Stories before they disappeared after 24 hours. Instagram's API does not provide third-party access to Stories content, meaning Hyp3r used unauthorized methods to archive content that users expected to be temporary.

Was Hyp3r illegal?

Hyp3r's practices violated Instagram's terms of service, but no criminal charges or regulatory fines were publicly reported. The legality of scraping publicly available data remains a contested area of law. However, the company's practices would likely face increased legal scrutiny under GDPR and CCPA.

What happened to Hyp3r after the Instagram ban?

Hyp3r attempted to arrange talks with Facebook to restore access but was unsuccessful. Without Instagram data, the company's business model was unsustainable. Hyp3r ceased operations and is now listed as permanently closed on business databases.

How much money did Hyp3r raise?

Hyp3r raised $23 million in total venture capital funding. The largest round was a $17.3 million Series A in September 2018, backed by SVB, Thayer Ventures, and Structure Capital. Investors lost their money when the company shut down.

Is Hyp3r related to Cambridge Analytica?

The companies are not directly related, but journalists drew comparisons because both were trusted platform partners that collected far more user data than their agreements permitted. Both cases exposed weaknesses in how social media platforms vet and monitor their partners.


Conclusion

Hyp3r's story is a warning about what happens when companies treat user data as a commodity to be harvested rather than a trust to be honored. A $23 million startup with Fortune 500 clients collapsed overnight because its core business practice violated the platform it depended on.

The uncomfortable truth is that Hyp3r was able to operate for years before being caught. If Business Insider hadn't investigated, the scraping might have continued indefinitely. That raises questions not just about Hyp3r, but about how many other companies might be collecting social media data in ways that users never consented to.

In the post-GDPR, post-Cambridge Analytica world, the tolerance for this kind of data collection has collapsed. Hyp3r was one of the last companies to learn that lesson the hard way.


Sources:


Related Reading

Want the growth without the research?

Real accounts, 30-day refill, no password ever asked for.

See prices

Read next