← Back to XFlow

XFlow Privacy Policy

Effective date: September 23, 2026 · Version: 0.1.0 · Publisher: Ryan Zeng

简体中文版

Website visits

This site is statically hosted by GitHub Pages. XFlow's page code does not write cookies or use analytics scripts, tracking pixels, forms, or a custom backend. GitHub may process request and operational data under its Privacy Statement.

Data processed and why

  • Visible post IDs and text on supported X / Twitter pages: used to evaluate posts against enabled strategies when you enable a filtering surface and configure a Provider Key. The extension does not read browsing history on other sites.
  • Strategy names, criteria, and related settings: used to form evaluation requests and present results; settings are stored locally in the browser.
  • Filter activity: recorded only after content is veiled. It may include a content ID, a text preview of up to 500 characters, author, post URL, surface, media type, filter time, device identifier, matched strategy, and reveal or incorrect status.
  • Provider API Keys and optional S3 credentials: stored in the extension's chrome.storage.local for authentication or request signing.
  • Interface language, theme, and other settings: used to provide the extension; interface language stays local and is not part of the S3 sync document.

XFlow does not read X login cookies or sessions or store page HTML, DOM, media files, or a complete browsing path. The current version has no ads, developer telemetry, or developer analytics service.

Who receives data

Your selected Jev Provider.The extension sends post IDs and text, applicable strategy names and criteria, and that Provider's API Key only to the currently selected OpenRouter, Vercel AI Gateway, or TypeSafe service. The request is used to return a filtering decision. A failed request is not automatically forwarded to another Provider. The Provider and any upstream model services it uses process requests under their own terms and privacy policies. Before choosing one, review the OpenRouter Privacy Policy, Vercel Privacy Notice and AI Product Terms, or the TypeSafe Privacy Policy. Provider use may incur third-party charges.

Your configured S3 Endpoint (optional).The extension reads or writes a sync document only after you configure a connection, grant access to the Endpoint, and enable sync. The document includes filter configuration (including strategies and prompts), activity records, and statistics, so it may contain post previews, authors, and post URLs. It excludes Provider API Keys, S3 access credentials, and Session Tokens. Signed request headers give the Endpoint the Access Key ID and optional Session Token; the Secret Access Key is used locally to create the signature and is not sent directly. Once enabled, sync is attempted after configuration changes, at browser startup, and about every 15 minutes. Storage, backup, and retention depend on the service and account you choose.

Apart from these necessary transfers, the XFlow project does not sell this data, use it for advertising, or provide it to other recipients. Do not submit keys or sensitive post content in public issues or support exchanges.

Retention and deletion

  • Activity details are kept for about 30 days; then text previews, authors, URLs, and strategy details are removed. Content identities used for deduplication remain for up to about 12 weeks before being folded into per-device lifetime counts. This does not delete data held by third parties.
  • Use Clear logs on the Dashboard's Log page to remove authors, text previews, original links, and matched strategies immediately. Content IDs, daily statistics, and all-time totals remain. If S3 sync is enabled, the extension attempts to sync the cleared state.
  • Use Clear Activity Data on the Dashboard's General page to remove local activity details and totals. If S3 sync is enabled, the extension attempts to sync the cleared state so older records do not return later.
  • Clear each local Provider Key on the API Keys page. This does not revoke the key at the Provider.
  • Disabling S3 sync does not remove local connection settings or objects already written to S3. Delete remote copies in your S3 service and check its versions and backups.
  • Uninstalling the extension lets the browser remove local extension data. Data already processed or stored by a Provider or S3 service must be managed under that service's policy and account controls.

Security and permissions

Provider Keys and S3 credentials are not exposed to Content Scripts on X pages and are not included in editable configuration JSON or new S3 sync documents. They receive no additional encryption at rest in chrome.storage.local; someone with access to your browser profile may be able to obtain this local data. Provider connections and S3 endpoints use HTTPS, except that S3 endpoint validation allows HTTP for localhost and 127.0.0.1 for local development. X / Twitter page access lets the extension read posts for evaluation and display revealable veils. You grant access to an S3 host separately when saving its Endpoint. The storage permission stores local data; alarms supports scheduled sync after you enable S3.

Chrome Web Store Limited Use

XFlow's use of information obtained from the browser and Chrome extension APIs follows the Limited Use requirements of the Chrome Web Store User Data Policy: it processes only data needed for the user-facing filtering, activity, and user-selected sync features described above; transfers data only to provide those features; does not sell data; and does not use data for personalized or targeted advertising. Developers cannot read local extension data by default. A person may review data you specifically provide for support or as otherwise permitted for legal or security reasons under the policy.

Changes and contact

If data practices change materially, the project will update this policy and notify users in the extension interface or release notes. For privacy, deletion, or policy questions, email ry4nzeng@gmail.com or contact the maintainers through XFlow GitHub Issues. Do not post keys or sensitive content in public issues.