Privacy Policy

X Observatory · Last updated: 2026-09-02

X Observatory is a local-first, read-only Chrome extension for researching public X accounts and content selected by the user.

Data handled

The extension may handle public X profile, relationship, search, post, and post-participant data when the user starts a collection task. It also handles collection job metadata, source coverage, evidence, derived topics, intent, and scores. Raw business data is stored in browser IndexedDB until the user deletes it or removes the extension. Standard data exports are created only on explicit user action.

Google OAuth is used only to establish the current user's identity for the X Observatory service. The Google access token remains in Chrome Identity cache and transient extension/auth-function memory. The auth function validates its audience and issues a pseudonymous, user-bound service token valid for at most five minutes. The service does not store the Google account identifier, email address, token, or service token.

X cookies, CSRF tokens, Authorization values, transaction IDs, Google access tokens, and service tokens are not written to IndexedDB, extension persistent storage, exports, application logs, or analytics. X cookies remain browser-managed; X Authorization and CSRF values remain in the active page's in-memory request wrapper.

Service boundary

The transaction service receives only the read-only method/path, public verification key, animation frame paths, and public X JavaScript asset URL needed to generate a single-use transaction ID. It does not receive X cookies, CSRF, Authorization values, request variables, features, cursors, account input, request body, or X response data.

What we do not do

The extension does not sell data, use data for advertising, transfer data to data brokers, or permit human review of collected content. It does not infer political, health, religious, racial or ethnic, sexual-orientation, or financial attributes. It performs no write actions on X: no follows, likes, reposts, replies, or messages.

User control and security

Users choose the target and sources, can stop collection at any time, can delete local projects, and can choose whether to export data. Missing or incomplete sources remain Unknown and are traceable to their collection job and source. Service traffic uses HTTPS, bounded schemas, fixed read-only allowlists, and short-lived tokens.

Use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Report privacy or security issues to jlee07905@gmail.com or at GitHub Issues.