Privacy policy
Xtags is developed by yishan. Contact: linyishan@gmail.com. Its single purpose is to display AI-estimated intent and related signals beside posts you browse on X.
Classification is not entirely local. After you explicitly agree to the selected destination, enable Xtags and configure its API key, Xtags sends extracted post text, author handles and your API credential to that service for classification. TypeSafe AI is the default. You may select a compatible custom HTTPS API; provider charges may apply.
1. Data the extension handles
- Post content and author handles: text extracted from rendered post containers on
x.comandtwitter.com. This may include links or personal information contained in the post itself. Rendered posts can include posts outside the current viewport and posts accessible only to your signed-in account; Xtags does not verify that each post is public. - Post identifiers and judgments: the post's status ID, returned probabilities and classification fields, and a local cache timestamp. These are used to associate labels with the correct post and avoid duplicate API calls. The status ID is used locally and is not a separate field in the classification API payload.
- Authentication: the API key that you enter for the selected service. It is sent to that service as an authorization header, not included in the post text.
- Preferences and diagnostics: enabled state, data-transfer consent version and destination, selected API URL, threshold, language, display settings, model and cache reset state; per-tab counters, token counts and the most recent request error.
Xtags does not request access to your full Chrome browsing-history database, passwords, or X authentication cookies. It does not deliberately extract direct messages or read unrelated websites. These limits do not remove personal or sensitive information that may already be present in a post's text.
2. Where the data goes
By default, the extension sends classification requests directly over HTTPS to https://api.typesafe.ai/v1/systemone, operated by TypeSafe AI, Inc. If you configure a custom service, requests go to the complete HTTPS URL you saved instead. The current destination is shown above the consent control. Requests contain the extracted text, author handle, fixed classification questions and selected model, with your API key for authentication. No Xtags-operated server proxies these requests.
TypeSafe necessarily receives connection information such as your IP address and request timing. Its own policy describes processing of input and service metadata, retention and possible processing in the United States. As checked on September 20, 2026, it states that it does not train or fine-tune models on input. This is TypeSafe's statement, not a separate guarantee by Xtags. Its policy does not specify a fixed API-input deletion period. See TypeSafe's privacy policy.
Custom providers: the operator of your chosen API receives the same post content, handles and authentication header, plus connection information such as your IP. Its privacy practices, hosting location, retention and any downstream processing are determined by that operator. TypeSafe's statements do not apply to it. Review the custom provider's policy before consenting. Requests omit cookies and do not follow redirects.
3. Local storage and retention
Your key, service URL, destination-bound consent and preferences are stored in chrome.storage.local, not Chrome Sync. Cached judgments are associated with up to 3,000 post IDs. The extension's cache does not intentionally persist the source post body or handle; these are held in memory while requests are queued or processed. The cache has no fixed time-to-live. Entries remain until cleared, evicted, invalidated by a service/model/cache-format change, or removed with the extension.
Per-tab counters and errors are held in memory for that page. Local storage is not encrypted by Xtags and can be accessible to processes operating as your local user. HTTPS protects transmission; it does not make the browser's local storage encrypted.
4. Your controls and deletion
- New installations and upgrades without a current consent record do not classify posts. Open Settings from the popup, read the notice, select the initially unchecked acknowledgement and click Agree and enable to allow processing. Language changes preserve consent; changes to data practices that require renewed consent will prompt you again.
- Changing the saved service URL pauses processing, clears the saved key and classification cache, and resets consent. Enter a key issued for the new service and consent again. Custom host access is requested only for the selected host; existing permission for a different custom host is removed when possible. You may also revoke host access in Chrome. Unsaved URL edits do not switch the active service.
- Withdraw consent and pause in Settings removes the local consent state, stops queued requests and attempts to cancel active requests. Your key and cache are retained; you can still clear them. Data already sent to the service cannot be recalled.
- Turn off Enabled in the popup to stop scheduling requests and attempt to cancel active requests. Data already received by the service cannot be recalled by pausing.
- To delete local judgments, pause first, then choose Clear cache in Settings. Clearing while enabled can immediately start new classification requests and rebuild the cache.
- To remove the saved API key, empty the API key field in Settings and leave the field so the change is saved. Uninstalling the extension removes its Chrome local storage. Revoke the key with the issuing provider if you no longer want it usable.
- Deleting local data does not delete data held by the selected provider or its downstream processors. Contact that provider using its published support or privacy channel for provider-side requests.
5. Limited use and sharing
Xtags's use of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses data only to provide its disclosed post-labeling feature. It does not sell user data, use it for personalized advertising, or use it for credit or lending decisions. Its only automatic third-party transfer is the data necessary for the selected API provider to perform classification.
The developer does not receive classification traffic or have a backend for reading your posts. The developer does not arrange human review of that data. If you explicitly send information for support, it is used to handle your request; any other access or disclosure is limited to what is necessary for security or required by law. These statements describe Xtags; Each provider's handling is described in its own policy.
6. Support and this website
If you email support, the developer and the email provider receive the information you choose to include. Do not send API keys, account passwords or private posts. You can request deletion of support correspondence by contacting the email above, subject to applicable obligations.
When you visit the public documentation website on GitHub Pages, GitHub may process visitor connection information under the GitHub privacy statement. These pages contain no added analytics, tracking scripts or advertising.
7. Changes and contact
Material changes to the extension's data practices will be reflected in an updated policy and disclosed to users as appropriate before new processing begins. Questions about Xtags can be sent to linyishan@gmail.com.