✨ ThreadPilot by Xtensions World
Privacy Policy
Effective date: July 4, 2026
The short version: ThreadPilot has no analytics, no tracking and no ads.
Your saved tweets, tags and notes stay on your device. Tweet text is sent to an AI
service only at the moment you click an AI feature, and we never see your X account
credentials. Card details are handled entirely by Razorpay — we never receive them.
1. Data stored on your device only
The following is kept in your browser's local extension storage and is never transmitted to us:
- Your feature preferences and settings
- Saved tweets, tags and notes (Read-Later dashboard)
- Onboarding/tour state
- A randomly generated install ID (a UUID that identifies your install — not you)
- Your trial start date and license token
- Any optional API keys you add (Gemini, Safe Browsing)
Uninstalling the extension deletes all of this immediately.
2. Data sent to third-party AI services
When — and only when — you click an AI feature (Summarize, Translate, Compose Assist,
Reply Suggester), the text of the tweet or thread you are viewing (or the draft you are
writing) is sent to one of these services to generate a response:
| Service | When used | Their policy |
| Chrome built-in AI (Gemini Nano) | Preferred when your Chrome supports it — runs on your device; nothing leaves your browser | — |
| Pollinations.ai | Default cloud AI | pollinations.ai |
| Hugging Face (Inference API & Spaces) | Fallback when the default is unavailable | huggingface.co/privacy |
| Google Gemini API | Only if you add your own API key | policies.google.com |
- We send only the text needed for the feature — never your X username, password, cookies, or session tokens.
- Nothing is sent in the background; requests happen only on your explicit click/shortcut.
- These providers process the text to generate a response; we do not control their retention. Avoid using AI features on text you consider sensitive.
3. Link Shield
Link safety checks run locally using pattern heuristics (lookalike domains,
shorteners, suspicious TLDs). If you optionally add your own Google Safe Browsing API key,
the URLs you're checking are sent to Google's Safe Browsing service for a real-time verdict.
4. Purchases & licensing
- Payments are processed by Razorpay. We never see or store your card/UPI details. Razorpay's policy: razorpay.com/privacy.
- After a successful payment, Razorpay sends us your payment ID and the email you used at checkout. We store these with your license key in our license database (Cloudflare) so we can activate your copy, provide support, and honour refunds.
- During activation, the extension sends your license key (or payment ID) and its random install ID to our license server. This binds your license to your install and prevents key sharing. No browsing data is ever included.
- The extension re-checks license validity with our server about once a day (license token + install ID only).
5. What we never do
- No analytics, telemetry, or usage tracking
- No ads and no ad networks
- No selling or renting data to anyone
- No reading your timeline in the background — content is processed only when you invoke a feature
- No collection of your X credentials
6. Data retention & deletion
- Local data: removed instantly when you uninstall the extension.
- License records (email, payment ID, license key, install ID): kept for as long as needed to honour your lifetime license. Email janhavirawat25@gmail.com to request deletion — note that deleting your record deactivates your license.
7. Children
ThreadPilot is not directed at children under 13 and requires an X account, which has its own age requirements.
8. Changes to this policy
If we make material changes, we'll update this page and the effective date above.
9. Contact
Questions or requests: janhavirawat25@gmail.com
Xtensions World · xtensionsworld.com