Privacy

Operated by Hekmon · https://x.productdirs.com · Effective 2026-07-31

Overview

This Privacy Policy explains how Save X's Chrome extension and optional account-backed services handle data. The extension processes data only to provide the archive features you select. Most extension data stays in extension-scoped browser storage or is sent directly to a destination you choose; optional AI enrichment is the only capture flow sent through the Save X service.

Data we collect

The extension handles these categories only when the related feature is used: - Captured website content: selected X or Xiaohongshu/Rednote post text, author name or handle, source URL, quoted text, timestamps, and image, video, or article links. - Authentication information: your Memos personal access token, an optional scoped Save X API key, and X's ct0 CSRF cookie during bookmark sync. The X cookie is used only for requests back to X and is not persisted by Save X. - Extension settings and activity: destination origins, webhook URL, tags, capture modes, locale, bookmark or collection checkpoints, delivery status, source URLs, timestamps, and sanitized error codes. Local history does not keep a second full copy of captured post text. - Optional account data: the name, email, avatar, provider subject, session identifiers, IP address, and user agent supplied through OneAuth when you connect an account. - Optional AI data: the public X fields sent for enrichment, a one-way input hash, task metadata, generated summary, and generated tags. The raw capture is transmitted for processing but is not stored in the Save X task database. - Optional support data: only after you confirm opening the OnlineChat compatibility form, the detected and tested Memos versions, extension version, compatibility status, sanitized error code, and selected language are placed in the page's URL fragment. If you submit the form, OnlineChat also handles the email address and ticket content you provide. Memos credentials and Memo content are not included automatically. - Optional analytics: if analytics are configured in the distributed extension and you enable them, random install and session identifiers plus allowlisted lifecycle, popup, save-result, bookmark-sync, connection, and settings events. These events exclude captured content, source and destination URLs, credentials, and account identifiers.

How we use this data

We use data only to provide, secure, troubleshoot, and improve the user-facing archive features you request; operate an optional account; perform optional AI enrichment; provide support; and comply with legal obligations. We do not sell extension data, use it for personalized advertising or creditworthiness, or transfer it for unrelated purposes. Human access is prohibited except with your explicit consent, for security investigation, legal compliance, or aggregated internal operations.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Save X uses and transfers Chrome API data, captured website content, and derived data only as necessary to provide or improve its disclosed single-purpose archive features, to protect security, or to comply with law. It is never sold, used for personalized advertising or creditworthiness, or made available for human review except with explicit consent, for security, to comply with law, or in aggregated and anonymized internal operations.

Third-party processors

Data is transferred only as needed for the feature you choose: - Your Memos instance: receives the personal access token, formatted capture, tags, and visibility directly from the extension. Save X does not receive the Memos token. - Your webhook endpoint: receives captured and formatted text, source URL, author fields, quoted text, media and article URLs, tags, trigger, timestamps, and any generated summary. You control this endpoint and are responsible for its privacy and security. - X: receives bookmark requests using your current X session and ct0 CSRF cookie. The cookie is not sent to Save X, Memos, webhooks, analytics, or AI providers. - OneAuth at oneauth.hekmon.com: provides optional account authentication and returns the identity fields needed to create a Save X session. Google receives identity and OAuth data only if you choose Google sign-in through OneAuth. - The Save X API at x.productdirs.com and AIAPI Center at aiapi.hekmon.com: receive selected public X text, author fields, source URL, quoted text, and tag policy only after you enable AI enrichment. AIAPI Center currently routes the DeepSeek V4 Flash model to DeepSeek or ZenMux, so either provider may receive that AI prompt. - OnlineChat at onlinechat.hekmon.com: handles the compatibility fields listed above only after you confirm opening its hosted support form; if you submit a ticket, it also receives the email address and ticket content you enter. - MailHub at mail.hekmon.com: delivers configured account verification, password-reset, welcome, support-reply, and operational emails through its Resend-compatible API. It receives the recipient email address plus the subject and message content needed to deliver that email. - Cloudflare: hosts the Save X, OneAuth, AIAPI Center, OnlineChat, and CF Plausible services and provides network, storage, analytics infrastructure, and abuse protection; it may process request metadata such as IP address and headers. - Analytics: the submitted extension build has no analytics write key and sends no extension analytics. If a later disclosed build configures analytics and you opt in, Hekmon's CF Plausible service at ai-cf-plausible.macros-hekk.workers.dev, hosted on Cloudflare, receives only the random identifiers and allowlisted events described above. The website currently has no analytics provider configured.

Cookies and local storage

The extension stores settings, approved destination credentials, synchronization checkpoints, and its analytics choice in Chrome local storage. Extension-scoped IndexedDB stores the webhook URL and local delivery history. Credentials remain until you disconnect the destination, clear extension data, or remove the extension. X's ct0 cookie is read only when bookmark sync is enabled or manually started and is not copied into extension storage. The website uses a required account-session cookie and locale preference; website attribution or analytics storage is written only after you accept optional cookies.

Data retention

Extension-local data remains until you disconnect a destination, clear extension data, or remove the extension. Deleting a Memo keeps a local tombstone to prevent an enabled automatic mode from re-saving it. Content already delivered to Memos or a webhook is retained under that destination's controls. Account records remain while your account is active and for a limited period needed for security or legal obligations. AI task metadata, the input hash, and generated result remain in task history until account deletion; raw capture text is not stored in the task database. Submitted support tickets and email delivery data are retained under the OnlineChat and MailHub service controls and applicable legal requirements. Optional analytics are kept for a limited rolling window.

Your rights

Depending on your location, including under the GDPR and the CCPA/CPRA, you may have the right to access, correct, delete, or export your personal data and to object to or restrict certain processing. You can disable optional capture, AI, and analytics features in the extension; disconnect destinations; clear extension data through Chrome; manage content at your Memos or webhook destination; export account data; or delete your account below. Contact support@hekmon.com for any other request.

Export your data

Delete your account

Children's privacy

Save X is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact support@hekmon.com and we will delete it.

Security and international transfers

Remote Memos, webhook, Save X, and AI destinations must use HTTPS; plain HTTP is accepted only for an explicit local loopback destination on your own device. Credentials are kept in extension-scoped storage and are not included in local history or analytics. All executable extension code is packaged with the extension; remote X resources used for bookmark compatibility are read as text and never evaluated. Processors may operate outside your country, using appropriate transfer safeguards where required.

Changes to this policy

We may update this policy from time to time. Material changes update the effective date above; continued use of Save X after a change means you accept the updated policy.

Contact us

Questions about this policy or your data: support@hekmon.com.