Extension privacy policy
Effective September 13, 2026 · Xboost for Chrome and Firefox
Post scoring happens locally. Profiles and drafts are stored in your browser. When you enable AI, selected post content and product context are sent to your configured Codex App Server and OpenAI. You review and publish replies yourself.
Xboost uses information obtained through Chrome extension permissions only to provide its user-facing conversation scoring, discovery, and reply-drafting features. Xboost complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. It does not sell user data, use it for advertising or credit decisions, or allow humans to read it except with explicit user consent, for security purposes, or when required by law.
Local processing and storage
Xboost reads rendered X/Twitter posts to score and highlight conversations. It stores profile names, descriptions, X handles, authoritative product context, keywords, filters, appearance preferences, and discovery state in browser extension-local storage. Source posts, drafts, profile-context revisions, reply history, errors, and deduplication records are stored in extension-owned IndexedDB. This data is not browser Sync.
Upgrades from older versions migrate draft records to IndexedDB in resumable batches. The legacy copy is retained until migration validation succeeds.
Your configured Codex server address and capability token are also stored locally without additional extension-level encryption. Protect your browser profile and server. Temporary reply handoffs are kept in background memory and expire after 30 minutes.
Deleting a profile removes its settings while preserving historical drafts and reply records. Dismissing a draft hides it rather than erasing its stored record. Queued posts keep a snapshot of the selected profile context even if you later edit that profile.
Discovery and manual selection
Discovery stores the selected profile, context snapshot and revision, draft target, search variants, discovery-tab information, visited post IDs, timestamps, rejection counts, progress, and cooldowns locally. Search terms use saved keywords and topics from product context. Opening a search sends those terms to X. Avoid putting confidential information in targeting or context that you do not want used in searches.
While a session is running, eligible highlighted posts rendered as you browse X can join its drafting queue. Local rescanning can happen as drafting capacity becomes available; it does not refresh, scroll, or navigate those pages. You open discovery searches and browse them. The extension does not navigate unrelated tabs or open, refresh, or scroll discovery searches unattended.
Manually selecting a post saves its text, author, and URL locally, including when AI is disabled. Keyword and hashtag suggestions are extracted locally. Only terms you choose or enter are added to your profile. Selected posts are sent for drafting only when you enable AI.
Optional AI drafting
AI drafting is off until you enable it. Starting a discovery session enables drafting. While enabled, qualifying posts from open X tabs can be queued automatically. Post text, author handles, post URLs, and the selected authoritative product context are sent to your configured Codex App Server and processed by OpenAI through that server. Previously confirmed replies on a source post can be included to help avoid repetition.
Source posts may contain personal information. Enable AI only for content you are authorized to share. Xboost does not control the retention, training settings, or deletion practices of your server operator, OpenAI, or X.
The capability token is sent to the configured server to authenticate its WebSocket connection. Chrome uses a temporary session header rule restricted to the configured endpoint and socket-host tab. Firefox restricts token injection to the configured extension-origin WebSocket endpoint. Server status and account sign-in operations also communicate with that server.
Codex manages its OpenAI credentials on the server. Xboost does not read ChatGPT browser cookies. Xboost does not operate a developer-hosted data-collection backend and includes no analytics, advertising trackers, or telemetry.
X navigation and assisted replies
Searching sends queries to X. Opening a source post sends its URL to X. At your request, Xboost checks the visible active account and inserts a draft into X's composer. X can process composer text before you submit it. Copy buttons place text on your system clipboard.
Xboost does not automatically click Send, Like, or Follow, or switch X accounts. Switching an extension profile changes local targeting, not your signed-in X account. Follow-back on X opens X Notifications directly; it does not import follower or like records.
Records imported by earlier versions, including older cross-profile assessments, may remain in local storage until extension data is removed. Cross-profile assessment is no longer available, and pending assessments do not run.
Connection security
Xboost supports ws:// and wss://. Plain ws:// is unencrypted and can expose the token and messages to network observers. Prefer localhost with SSH forwarding or encrypted wss:// for remote connections. Review your Codex configuration and logs if you operate the server.
Your controls and deletion
Disable AI, pause or stop discovery, or close the last AI panel to stop new work and request cancellation of active generation. Cancellation cannot be confirmed if the server is disconnected. A browser or extension restart requires explicit resume. Completed drafts, queued records, and history remain stored.
Uninstalling Xboost removes its extension-local data from that browser. Manage separate backups and server/provider records separately, and clear your clipboard separately. Revoking the server capability token prevents future authentication with that token. Private/incognito browsing is disabled for the extension.
This website
The landing page and this policy page include no third-party scripts, external fonts, or analytics. The website stores your chosen theme locally. The hosting provider may retain ordinary access logs. Following external links shares normal navigation information with their destination.