Contents
Overview
Data We Collect
How We Use Data
Storage & Security
Sharing Data
Your Rights
Cookies
Chrome Compliance
Children's Privacy
Changes
Contact
Overview
X.com Post Copier ("the Extension", "we", "our", "us") is a Chrome browser extension developed and operated by the xPostCopier Team. This Privacy Policy describes what information we collect, how we use and share it in connection with the operation of the Extension. By using the Extension, you agree to the practices described in this Privacy Policy. Short version: We collect minimal data, we don't sell it, and most data stays on your device. We're GDPR-compliant.We will never sell your personal data to third parties. This is a core commitment of our product and business model.
Data We Collect
a) Data retrieved from X.com at your request
When you use the copying features, the Extension accesses the content of posts on X.com that you are currently viewing. This includes:- The text of the post
- Links to media (images, videos) contained in the post
- The post author's name and their @handle
- A link to the original post
b) Account & Premium data (if applicable)
- Anonymous User Identifier — a unique, anonymous ID generated and stored to associate your activity with premium services or a trial period, and for event logging.
- X Handle — if you provide your X handle (or it is detected with your consent), it may be stored to personalize services or link to a premium account.
- Subscription Status — information about your status (premium, trial, expiration date) retrieved from our backend and may be stored locally for faster performance.
- Google Sign-In data — if you sign in with Google, with your consent we access basic profile info (email address and unique identifier) solely for creating and managing your account.
c) Data stored locally on your device
- Saved Posts — when you use the post saving feature, content (text, media links, author data) is stored locally using secure browser storage (
chrome.storage.local). - Visited Posts — a list of identifiers of saved posts you've opened, to help you track viewed content.
- Saved Screenshots — if you use the screenshot saving feature, screenshots may be stored temporarily or permanently in local storage.
- Backend Identification Cookie — a cookie for our domain containing your anonymous user identifier, used to identify your session and integrate with our backend (e.g. for managing premium status).
d) Extension usage data (event logs)
To improve the Extension and diagnose problems, we may collect anonymous or pseudonymous data about your interactions, including:- Types of actions performed (e.g. "Copy Text clicked", "Screenshot used", error events)
- Details about the event (e.g. error messages, anonymized content identifiers)
- Your anonymous user identifier
Data we explicitly do NOT collect
- Your X.com / Twitter password or session tokens
- Your browsing history outside of x.com
- IP addresses (stripped at ingestion)
- Full payment card details (handled exclusively by Stripe)
How We Use Data
Your information is used for the following purposes only:- Providing core Extension features — enabling copying and saving content from X.com
- Managing accounts and subscriptions — handling premium features, trial periods and payments
- Personalization — customizing the Extension (e.g. remembering your X handle)
- Improving the Extension — analyzing usage data and event logs to improve functionality, performance and diagnose errors
- Syncing settings — synchronizing certain data (user identifier, X handle, status) between your devices via browser sync, if enabled
- Communication — if we have your email (via Google OAuth), we may contact you about your account, subscription or important Extension updates
- Security and legal compliance — protecting against abuse and fulfilling legal obligations
Data Storage & Security
Local storage
Saved posts, visited posts, screenshots and the anonymous identifier are stored locally on your computer using secure browser storage mechanisms (chrome.storage.local). This data never leaves your computer unless you enable Google Sync.
Server data
Data sent to our backend server (event logs, account status, X handle) is protected by appropriate technical and organizational measures. Data is encrypted in transit (TLS) and at rest.Retention
Server-side data is retained for as long as your account is active. You can delete all local data at any time from the extension popup → Settings → Delete Account Data, or by reinstalling the Extension. Analytics data is retained for 12 months in aggregated, anonymized form only. We make every effort to protect your data; however, no method of transmission over the Internet is 100% secure.How We Share Your Information
We do not sell your personal data to third parties. We share your information only in the following limited circumstances:- Our Backend Server — anonymous identifier, event logs, account status and X handle are shared with our backend necessary for premium features and account management.
- Google (OAuth Sign-In) — if you use Google Sign-In, information is exchanged with Google for authentication purposes only. Google Privacy Policy →
- Stripe (Payment Processor) — if you purchase premium, your payment data is provided directly to Stripe. We do not store full payment details on our servers. Stripe Privacy Policy →
- Legal requirements — we may disclose information if required by law, court order, or to protect our rights or the safety of others.
- Mergers & Acquisitions — in the event of a merger or acquisition, your data may be transferred to the successor entity, of which you will be informed.
Your Rights & Choices
GDPR (European Economic Area)
If you are in the EEA, you have the following rights:- Right of access — request a copy of the data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing of your data
Managing your data
- Local data — delete saved posts within the Extension, or clear all Extension storage via your browser's developer tools
- Synced data — manage via your browser account settings
- Google Sign-In — revoke the Extension's access via your Google account security settings
Chrome Web Store Compliance
We declare that the use of information received from Google APIs (including the Google Identity API for sign-in) adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:"The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements."We only request the minimum permissions necessary for the proper functioning of the Extension and its features.