DEV Community

roehler
roehler

Posted on Fully Autonomous

What I learned parsing Instagram, TikTok, X and Facebook data exports in the browser

Most "who unfollowed me" apps want your Instagram password. I wanted a tool that doesn't, so it works with the data export every platform offers instead: you download your data, drop the ZIP into a web page, and it's analyzed locally. The parsers are now open source: https://github.com/RobinOehler/unfollowtool-export-parsers

A few things that surprised me:

1. Instagram's export format changes constantly. Since 2020 there have been at least five shapes: a single connections.json, relationships_followers, numbered followers_1.json parts, entries where the username only lives in title (2024), and label_values records whose labels are translated into the account's language (2025). The parser identifies fields by value shape and position, never by label.

2. Meta's JSON is mojibake by design. Every UTF-8 byte of a non-ASCII character is written as its own \u00XX escape, so "José" arrives as "José". Decoding means re-assembling the bytes and reading them as UTF-8.

3. Big ZIPs don't fit in memory. Exports that include photos easily reach several GB. Instead of loading the whole archive, the reader parses the ZIP central directory with Blob.slice() and inflates only the follower files with DecompressionStream('deflate-raw'), including ZIP64. JSZip remains as a fallback for older browsers.

4. TikTok TXT files get re-saved as UTF-16. Open Follower.txt in Windows Notepad, click save, and it's UTF-16 with a BOM. Labels like "Username:" are also localized ("Gebruikersnaam:"), so the parser falls back to structure: the date-valued label is the date, the remaining one is the username.

5. Never trust URLs from the file. X's userLink, Facebook names, HTML anchors: all of it is untrusted input. Entries only get a profile URL that is rebuilt from a validated username or ID on the platform's own host.

6. X gives you IDs, Facebook gives you names. X archives contain numeric account IDs only (no usernames, no dates); Facebook exports contain display names only. The data model has to allow username: null and still produce stable keys.

The whole thing is about 2,900 lines of dependency-free JavaScript with around 250 tests on generated fixtures. It powers https://www.unfollowtool.com/, and I'd love issue reports for export layouts it doesn't know yet.

Top comments (0)