Privacy Policy Plain English

Your exported X (Twitter) data never leaves your browser — XPorter has no servers and no account. Normal exports contact only X-owned services (x.com and the public abs.twimg.com client-asset CDN). The only data sent outside X is an anonymous, non-personal usage summary when you uninstall, used solely to understand why people leave and improve the extension. No personal data and none of your exported content is included.

What the extension accesses

XPorter accesses the following to perform the exports you start and build the local seen-post dataset:

What XPorter does NOT do

Anonymous uninstall feedback

When you uninstall XPorter, Chrome opens a short feedback page. To understand why people leave and what to fix, XPorter attaches an anonymous, non-personal usage summary to that page. It contains only aggregate product stats:

This summary contains no usernames, no exported content, no X data, and nothing that identifies you. If you choose to leave a written comment on the feedback page, only the text you type is sent.

The data is stored in a private spreadsheet via Google Apps Script / Google Sheets (Google acts as the data processor). It is used only to improve XPorter and is never sold or shared. This is the only user or extension-usage data XPorter transmits outside X-owned services. The anonymous summary is recorded when the feedback page loads; any written comment is sent only if you choose to submit one.

Permissions explained

cookies

Reads authentication tokens (CSRF token) from your X.com session to make authenticated API requests.

activeTab

Detects when you're on an X.com profile and identifies the username being viewed.

downloads

Saves the exported CSV, JSON or XLSX file to your Downloads folder when you click download.

storage & unlimitedStorage

Stores preferences, resumable export batches, recent export history, anonymous usage counters, and the deduplicated seen-post dataset locally in Chrome. unlimitedStorage prevents larger local datasets and exports from being truncated by Chrome's normal storage quota.

Host access to x.com

Required to make API calls to X.com to retrieve the data you asked to export.

Data storage

Third-party services

XPorter integrates with no analytics platforms, ad networks or trackers. Normal exports contact X-owned x.com APIs and may read a public abs.twimg.com client asset as text; that asset is never executed, and no authentication or export data is sent to the CDN. The only communication outside X-owned services is the anonymous uninstall feedback above, stored via Google (Apps Script / Google Sheets).

Data security

All communication with X-owned services uses HTTPS. Authentication tokens are handled in memory, are never written to disk, and are sent only to x.com API requests — never to abs.twimg.com.

Children's privacy

XPorter is not directed at children under 13 and does not knowingly collect information from minors.

Changes to this policy

Updates will be reflected on this page with a new effective date. Significant changes will be noted in the extension's changelog.

Contact

Questions about this policy or the extension? Message me on Telegram (fastest reply), or email art.lemelson@gmail.com (I check it rarely, so I may be slow). You can also find me on GitHub.

Effective date: July 26, 2026