xlegit
Menu

Privacy Policy

This policy explains how xlegit (“we”, “us”) collects, uses, and stores personal data when you use our Chrome extension or visit xlegit.xyz. It also explains what we process about the public X profiles the extension scores. The controller is the operator named in the legal notice. xlegit is an independent project. It is not affiliated with X Corp.

1. What we collect

We collect the smallest amount of data needed to run the service:

  • Email address. We collect it when you create an account in the extension, or leave it on the website to receive the install link or a note when Pro opens. We use it to send sign-in links and account emails, such as receipts and notices about material changes to this policy. If you tick the consent box, we also send the one message you asked for.
  • Profile observations. When you are signed in and request a scan, the extension can send public signals to our API: display name, bio text, follower / following / post counts, join date and avatar URL. Enabling automatic scanning also allows profile and header observations while you browse. It is off by default. During a Free scan, the extension also collects up to 100 public posts as you scroll (id, timestamp, kind, visible text, available engagement counts, media indicators, linked website hosts and reply targets). A Pro scan can also send the profile and posts already visible on the page. We retain visible pinned-post evidence, collection timing and extension version details to understand the sample and missing data. The extension does not open hidden content or collect the account’s entire history. We call this an observation. Observations are tied to your account for evidence verification and abuse prevention. We also retain selected scan snapshots to review, train and evaluate our detection models. These snapshots retain their original capture time and are removed when you delete your account. Signed-out visits only look up the handle’s published score. No profile content is sent. Our server uses the X API to verify submitted evidence and to collect public posts automatically for Pro scans.
  • Score lookups. We may send profile handles to look up existing public scores when a current result is not already saved in your browser. This can happen while signed out or with automatic scanning off. These lookups do not send new profile observations or post text.
  • Timeline look-ups (Pro). With inline scoring switched on, the handles of authors that appear in your feed are sent in batches so their published scores can be shown. These requests are not stored beyond ordinary server logs.
  • Post checks and Feed guard. Timeline post text leaves your browser only when you ask for it: when you press Check post on a single post, or when you turn on Feed guard (off by default) so posts in your timeline are checked as you scroll. For each checked post the extension sends the post id and its visible text (up to 2,000 characters) to our API, which forwards the text to TypeSafe, our processor for these assessments, and returns a warning about scam requests, rage bait or clickbait. We keep the submitted text, the model decision and the first reported nudge, link warning or Focus-mode action per check in a private audit tied to your account until you delete it. Post checks never change a public account score. Turn Feed guard off at any time in the extension’s Settings; no timeline text is sent while it is off and you do not press Check post.
  • Hashed IP address. The API hashes your IP (one-way HMAC with a secret we control) for rate limiting and abuse detection. Our database holds no raw IPs. The edge and hosting providers (Cloudflare, Railway) keep raw IPs briefly in their own request logs.
  • Session token. We use a random token to keep you signed in. It is hashed at rest on our side and kept in the extension’s local storage on yours, for up to 90 days of inactivity.
  • Reports you submit. We store the category and optional note, tied to your account, plus a weight based on your account age and reporter reputation.
  • Disputes. If you dispute a score, we collect the handle, your contact email, your relationship to the account and your reason.
  • Error and diagnostics data. When something breaks, the extension, API and website send an error report to Sentry (error type, message, stack trace, version). The extension attaches no page URLs, handles or your email. The website’s report includes the page URL and browser type. If a stable X page element stops matching, the extension tells our API which selector failed.
  • Popup analytics (optional). Named events from the extension popup are sent to PostHog in the EU. These events never come from the content script. Analytics are off by default when your browser sends Do-Not-Track, and you can turn them off in Settings.
  • Website analytics (cookieless). xlegit.xyz counts page views with PostHog in the EU without cookies or any browser storage: every visit is a fresh anonymous id, so we count views, not people. Do-Not-Track is respected.

2. What we do not collect

  • Your direct messages, your drafts, or anything from the account you are signed into on X.
  • Posts you read in your timeline, unless you ask us to check them. Pro looks up author handles only. Post text from the timeline is sent solely for the posts you check with Check post or while Feed guard is switched on (see Post checks and Feed guard in section 1).
  • Your private notes and your watchlist. Both are stored only in your browser; we never receive them. Watchlist checks send handles only to look up published scores, like any other score lookup, and the notes export in the extension writes a file to your device for your own backup.
  • Cookies. The website sets none, so no cookie consent banner is needed.
  • Your browsing outside x.com / twitter.com. The extension only runs on those two sites.

3. Why we process it, and on what legal basis

  • Sign-in, account and Pro billing. We use this data to run the service you asked for. Basis: performance of a contract (GDPR art. 6(1)(b)). Invoicing records are also a legal obligation (art. 6(1)(c)).
  • Observations, scores and analysis. We compute trust scores for public profiles from verified public evidence. Both Free and Pro scans use server-side analysis: a sample of the scanned profile’s public posts is sent to xAI’s Grok and, when enabled, TypeSafe’s Jev. Public profile details accompany the post sample, and available avatar checks send the public avatar URL to Sightengine. Basis: our legitimate interest in helping users recognise bots and scams (art. 6(1)(f)). Section 9 explains what this means for the account holders being scored.
  • Community reports. We aggregate reports, weight them by reporter reputation, and show them beside the score. Basis: legitimate interest (art. 6(1)(f)).
  • Rate limiting and abuse detection. We use hashed IPs and usage events. Basis: legitimate interest in keeping the service available (art. 6(1)(f)).
  • Disputes and takedown notices. We use this data to handle requests and explain our decisions. Basis: legal obligation and legitimate interest (art. 6(1)(c), (f)).
  • Website analytics and error reporting. We use cookieless page counts and crash reports. Basis: legitimate interest (art. 6(1)(f)). No storage is accessed on your device, so no consent is required under ePrivacy / LSSI art. 22.2.
  • Install-link and Pro-opening emails. Basis: your consent (art. 6(1)(a)), given by ticking the box. You can withdraw it with the unsubscribe link.

4. Sub-processors

  • Railway (United States) provides application hosting and managed Postgres. It stores everything listed in section 1 except payment details.
  • Cloudflare (United States, EU edge) provides DNS, TLS termination and proxying for xlegit.xyz and the API. It sees the IP address of every request and keeps short-lived request logs.
  • Resend (United States) sends transactional email. It receives your email address and the contents of the email.
  • Stripe (United States) handles payments for Pro. Stripe receives your billing details directly. We store only a customer id and subscription status.
  • xAI (United States) provides language-model analysis of a profile’s public posts during Free and Pro scans. Your xlegit account details are not included. xAI processes API inputs and outputs under its API data terms.
  • TypeSafe provides Jev assessments of a scanned profile’s public profile details and a sample of its own posts. Your xlegit account details and browsing history are not included. Manual post checks and the optional Free or Pro feed guard also send the visible post text to TypeSafe to assess manipulation signals. Optional reply nudges, link warnings and reversible focus mode reuse these assessments. The private audit records the first reported occurrence of each action per check, without draft text or link destinations; linked pages, DMs and drafts are not collected by this feature. Feed guard is off by default. We retain these checks, including submitted text and model decisions, in a private audit associated with your account until you delete it. These checks do not change public account scores.
  • Investigation tools. When you submit a conversation or interest comparison, the selected text, topics and public profile samples are sent to TypeSafe. The growth workspace also sends the audience, topic, notes and optional draft you submit. Eligible profile scans use public post samples to describe recurring topics, tone and writing formats. These descriptions do not change the trust score. Growth plans and drafts follow the same private investigation retention and deletion rules. We never open your inbox or collect drafts automatically. Submitted URLs are inspected from our server using header requests without your cookies; destination servers can see our request. Pro can separately enable this inspection when Link guard pauses a click. Domain registration and reputation lookups use the existing providers. Private results, bounded inputs, prompts, model outputs, costs and corrections are available to the operator for review and retained for 30 days, with earlier deletion available in Investigate. Saved views and monitoring baselines remain until removed. Monitoring uses available X API data and produces private in-app change notices. None of these findings automatically changes a public score.
  • Sightengine (France) checks a scanned profile’s public avatar URL for AI generation and faces during server-side image checks.
  • Sentry (United States) provides error reporting for the API, workers, website and extension.
  • PostHog (European Union) provides optional popup analytics and cookieless website analytics as described above.

Public evidence source

We also use the X API to verify profile headers and a sample of submitted posts, and to collect up to 100 public posts automatically for Pro scans. These requests identify the public profile or posts being checked. We do not send your xlegit email address or use your personal X login credentials for these server requests.

5. International transfers

Some sub-processors are based in the United States. We rely on Standard Contractual Clauses or each provider’s equivalent legal mechanism (including the EU-US Data Privacy Framework where the provider is certified) for transfers from the European Economic Area, the United Kingdom, and Switzerland.

6. Your rights

You can delete your account and everything tied to it at any time from the extension popup → Settings → Delete account. This also cancels a Pro subscription. You can obtain a copy of the data tied to your account on request, or by calling the account export endpoint of our API (GET /v1/me/export) with your signed-in session. To access, export, correct or restrict your data, or to object to processing based on legitimate interest, email support@xlegit.xyz from the address on file. We answer every request within 30 days. You may also lodge a complaint with your local data-protection authority. In Spain that is the AEPD (aepd.es).

7. Retention

DataKept for
Private investigations, selected conversation text, submitted links, model audit and context corrections30 days, or until you delete investigation history or your account. Non-content usage records remain until expiry so deleting history does not reset an allowance.
Post checks (Check post and Feed guard: submitted post text, model decision, reported automation actions)Until you delete your account.
Saved investigation views, monitored accounts and the latest monitoring baselineUntil you remove the saved view, stop monitoring or delete your account.
Email address, reporter reputationUntil you delete your account.
Profile observations and training snapshots (public signals, up to 100 public posts and a visible pinned post of the observed profile)Retained for historical scoring and review. Raw observations and training snapshots are removed for profiles whose scores are withheld.
ScoresRetained for score history and audit. Withheld scores are not served publicly.
Community reportsUntil you withdraw them or delete your account.
Sessions (hashed token, hashed IP)90 days rolling, or until you sign out.
Sign-in links (hashed token, hashed IP)15 minutes.
Usage events (anonymised when you delete your account)365 days, then deleted automatically.
Stripe webhook events30 days.
Stripe customer id and subscription statusUntil you delete your account. Stripe keeps its own billing records as required by tax law.
Disputes (handle, contact email, reason)Until resolved, plus 12 months so we can show how a decision was reached.
Install-link / Pro-interest emails (with your consent)Until the launch mail is sent or you unsubscribe, whichever comes first.

8. Children

xlegit is not directed at children. You must be at least 14 to use it in Spain, and at least the age of digital consent in your country elsewhere (16 in most of the EEA, 13 elsewhere). We do not knowingly collect data from children.

9. Information for X account holders

If you have a public X account, xlegit users who open your profile may cause us to process data about it even though you have never used xlegit. This section is the notice required by GDPR art. 14.

  • What we process: the signals publicly visible on your profile page when a user opened it. These include your display name, handle, bio, follower / following / post counts, join date, avatar URL and up to 100 recent public posts. We also process the scores computed from those signals and any community reports about the account. During Free and Pro scans, a sample of those public posts is read by a language model and available avatar evidence is checked by an image model.
  • Where it comes from: public profile pages rendered in a user’s browser and public profile data returned by the X API. The server verifies browser evidence through the API and can collect public posts automatically for Pro scans.
  • Why, and on what basis: to help our users recognise bots and scams before engaging. This is our legitimate interest and theirs (art. 6(1)(f)). Scores are estimates, shown as such, and are never blended with community reports.
  • How long: observations and scores are retained for historical review. Their dates remain visible so readers can recognise an old scan. Reports are kept until withdrawn.
  • Your rights: you can object to the processing, ask what we hold, ask us to correct it, or ask us to withhold your score entirely. Use the dispute form: we acknowledge within 72 hours and decide within 30 days. A withheld score shows users only that it was withheld at the account holder’s request. You may also complain to your data-protection authority.

10. Changes

We will post material changes to this policy on this page. Substantive changes that affect existing accounts will trigger an email to the address on file.

11. Contact

Questions about this policy: support@xlegit.xyz. The controller’s identity and postal address are in the legal notice.