Where the Instagram login activity screen lives
The screen is called Where you're logged in. It sits inside Accounts Centre, which is the shared settings area Instagram uses for accounts linked to the same login.
- Open Instagram and tap your profile picture, bottom right.
- Tap the three-line menu, top right.
- Tap Accounts Centre. Some phones spell it Accounts Center — same thing.
- Tap Password and security.
- Tap Where you're logged in, then pick the account you want to look at.
Instagram moves these menus around every few months. If the wording on your phone does not match, type "Where you're logged in" into the search box at the top of Settings. That search still finds it when the path changes.
Do this on the app, not a browser, if you can. The app list is the one that shows your phone sessions properly.
What each line actually tells you — and what it does not
Every row is one session (a live logged-in connection between a device and your account). A session stays open until someone logs it out, so an old phone you sold two years ago can still be sitting on that list.
| What you see | What it proves |
|---|---|
| Device name, like "iPhone 14" or "Chrome, Windows" | The type of device. It is self-reported by the device, so treat it as a hint, not proof. |
| A city name | Only a guess, worked out from the IP address (the number your internet connection shows to websites). It is often wrong by a few hundred kilometres. |
| "Active now" | Someone is using that session right now. This is the row to look at first. |
| A date, like "2 March" | The session is still open but idle. Still worth logging out if it is not yours. |
Three things this screen does not show, and people mix these up constantly:
- Failed login attempts. Somebody trying your password and failing does not appear here. That arrives as a separate alert, which we cover in the Instagram suspicious login attempt guide.
- Profile viewers. This is not a list of who looked at your account. Instagram does not publish that anywhere, to anyone.
- Apps you connected. A third-party app you gave permission to is on a different screen entirely. Removing those is its own job — see how to remove third-party app access from Instagram.
Why a city you have never visited is usually not a hacker
This is the number one false alarm, so deal with it before you panic.
Your location on that screen is guessed from your IP address. Indian mobile networks route data through gateways in big cities. A phone sitting in Kota can easily report Mumbai. A phone in Siliguri can report Kolkata. Broadband is a bit more accurate, but not much.
So the useful question is not "do I recognise this city?" It is "do I recognise this device?" A metro name next to your own phone model is normal. An unknown device is the real signal, whatever city it claims.
How to spot a login that is not yours
Work down this list, in order:
- A device type you have never owned — a desktop browser when you only use the app, or an Android when you only use an iPhone.
- Anything marked "Active now" while your own phone is in your hand and closed.
- A session that appeared right after you used a "free followers" site, an engagement app, or any tool where you tapped "log in with Instagram".
- A session dated to a day you know you were offline.
One or more of these does not confirm a break-in. It confirms something worth ending. Logging out a session costs you nothing, so when in doubt, log it out.
Log it out, and what to do in the next five minutes
- On the same screen, tap the device and choose to log it out. On some versions you tap "Select devices to log out" at the bottom and tick them.
- Then change your password. Do it in this order. The logout ends the session now; the password change stops it coming straight back.
- Turn on two-factor authentication (a second one-time code asked for after your password, so a stolen password alone is not enough). Our step-by-step is in Instagram two-factor authentication in India.
- Check your registered email and phone number are still yours. Attackers change these first, and a changed email is far worse than a changed password.
- Come back to this screen tomorrow. If a strange session reappears, the problem is not solved and you should treat your email account as compromised too.
If you have read enough and just want to start, you can place a small first order — pick the service, paste your public link, and pay in rupees by UPI. No password is ever needed.
Use this screen as a before-and-after check on any paid order
Here is the part almost nobody tells you, and it is the most useful habit in this article.
Take a screenshot of Where you're logged in before you buy anything from any growth service. Take another one two days later. Then compare.
The logic is simple. A service that only needs your public username never logs into your account, so it can never appear on that list. If a new session shows up after you bought something, that service used a login — and the only way it had one is because you typed your password into it.
This is exactly why we ask for a public username or a post link and nothing else. Run the before-and-after check on us and the two screenshots will look identical, because we never touch your login. Our published rates are ₹750 per 1,000 followers with a minimum of 50, ₹84 per 1,000 likes with a minimum of 100, and ₹17 per 1,000 reel views with a minimum of 100 — you pay in rupees by UPI, and the Instagram followers page shows the number before you order.
Being straight with you about the rest of it: buying engagement is against Instagram's Terms of Service, the rulebook you agreed to when you made the account. Bought numbers work as social proof beside real posting. They are not a growth plan on their own, and the password rule above matters far more than the price.
The tools that do show up on this list
Some things will legitimately appear, and you should not log all of them out blindly:
- Instagram in a desktop browser, if you have ever posted from a laptop.
- A scheduling tool you connected on purpose, if you logged in through Instagram to set it up.
- An old phone still signed in. Harmless, but end it anyway — a sold or repaired phone is a real risk.
- A family member's device, if you share the account for a shop or a page.
Anything you cannot place in one of those four boxes should go.
Make it a monthly habit
Open this screen once a month. It takes twenty seconds and it is the cheapest security you will ever get on Instagram — no app to install, nothing to pay, nothing to sign up for.
Pair it with two-factor authentication switched on and a password you use nowhere else, and you have closed the three doors that actually get used. Everything else is noise.
