Your exported X (Twitter) data never leaves your browser — XPorter has no servers and no account. Normal exports
contact only X-owned services (x.com and the public abs.twimg.com client-asset CDN).
The only data sent outside X is an anonymous, non-personal usage summary when you uninstall, used solely to
understand why people leave and improve the extension. No personal data and none of your exported content is
included.
XPorter accesses the following to perform the exports you start and build the local seen-post dataset:
abs.twimg.com CDN and parsed as text to derive a request header required by some X feeds. XPorter
does not execute that remote code and sends the CDN no cookies, auth headers, usernames, or export data.pbs.twimg.com without credentials and adds them locally to
a Media sheet. This is off by default. Images are not sent to XPorter or any third-party server; the original
media URL remains in the export even when a preview cannot be downloaded.storage.local.When you uninstall XPorter, Chrome opens a short feedback page. To understand why people leave and what to fix, XPorter attaches an anonymous, non-personal usage summary to that page. It contains only aggregate product stats:
This summary contains no usernames, no exported content, no X data, and nothing that identifies you. If you choose to leave a written comment on the feedback page, only the text you type is sent.
The data is stored in a private spreadsheet via Google Apps Script / Google Sheets (Google acts as the data processor). It is used only to improve XPorter and is never sold or shared. This is the only user or extension-usage data XPorter transmits outside X-owned services. The anonymous summary is recorded when the feedback page loads; any written comment is sent only if you choose to submit one.
cookiesReads authentication tokens (CSRF token) from your X.com session to make authenticated API requests.
activeTabDetects when you're on an X.com profile and identifies the username being viewed.
downloadsSaves the exported CSV, JSON or XLSX file to your Downloads folder when you click download.
storage & unlimitedStorageStores preferences, resumable export batches, recent export history, anonymous usage counters, and the
deduplicated seen-post dataset locally in Chrome. unlimitedStorage prevents larger local datasets and
exports from being truncated by Chrome's normal storage quota.
Required to make API calls to X.com to retrieve the data you asked to export.
storage.local so interrupted exports can be resumed
without losing already saved rowsstorage.local for up to seven days to avoid repeating the same X requests. Failed lookups expire
after one hour, and the cache is capped at 25,000 accountsstorage.local and cleared when you uninstallstorage.local to build the uninstall summary, and removed when you uninstallXPorter integrates with no analytics platforms, ad networks or trackers. Normal exports contact X-owned
x.com APIs and may read a public abs.twimg.com client asset as text; that asset is never
executed, and no authentication or export data is sent to the CDN. The only communication outside X-owned
services is the anonymous uninstall feedback above, stored via Google (Apps Script / Google Sheets).
All communication with X-owned services uses HTTPS. Authentication tokens are handled in memory, are never
written to disk, and are sent only to x.com API requests — never to
abs.twimg.com.
XPorter is not directed at children under 13 and does not knowingly collect information from minors.
Updates will be reflected on this page with a new effective date. Significant changes will be noted in the extension's changelog.
Questions about this policy or the extension? Message me on Telegram (fastest reply), or email art.lemelson@gmail.com (I check it rarely, so I may be slow). You can also find me on GitHub.
Effective date: July 26, 2026