Social Media Toolbox

Privacy Policy

Social Media Toolbox keeps creation data on your device while using an official website account service for login and restricted actions.

Last updated 2026-09-14

In short

  • Your model keys, prompts, post content, generated drafts, history, and batch queues are not uploaded to the official account service.
  • The official website processes account and session data needed for email or optional Google login, extension connection, logout, abuse prevention, and restricted-feature checks.
  • Generation requests go directly from the extension to the AI provider or relay you configured. Platform submissions go directly to X or Xiaohongshu through your existing platform session.
  • The product does not include advertising, analytics, telemetry, or cross-site tracking.

What is stored

LocationDataPurpose and retention
Your browser profileModel configurations and API keys; preferences; editable platform parameters; active post context; generated drafts and history; batch configurations, queues, runtime state, and archivesProvides the extension’s local features. It remains until you delete or reset it, clear the browser profile, or uninstall the extension; short-lived active context may end with the browser session.
Your browser profileA public account snapshot, a random installation ID, a private extension session credential and its parent-session binding, plus short-lived login and resume stateShows login state and authorizes restricted submissions. Private credentials are stored in extension-only IndexedDB; temporary challenges and resume state expire or are consumed.
Official website databaseAccount identity (email and, when supplied by Google, name or image), website sessions, hashed verification values, hashed extension credentials, installation bindings, expiration and revocation records, and hashed rate-limit keysProvides login, session synchronization, logout revocation, and abuse prevention. Records remain for their configured lifetime or operational cleanup; logout revokes the current website session and its derived extension sessions.

What leaves your browser

RecipientWhat is sentWhen
The official Social Media Toolbox website and its hosting, database, and mail providersEmail address or optional Google identity; website cookies; extension ID and random installation ID; short-lived connection values; extension bearer credential; and ordinary request metadata such as IP address and user agent used for security and rate limitingWhen you log in, connect or verify the extension, check a restricted action, renew a session, manage the account, or log out
Your configured AI provider (Anthropic, OpenAI, Google, DeepSeek) or relay Base URLThe relevant post text and images, author display name, style and persona instructions, one-off instructions, model settings, and the API key used for that providerWhen you generate content or test a model connection
X or XiaohongshuThe comment you selected and the target post or note context required by the chosen submission methodOnly when you explicitly start a single or batch submission

A relay Base URL receives the prompt and API key instead of the provider’s official endpoint. Use only a relay you trust. AI and social-platform requests are governed by the recipient’s terms and privacy policy.

What the official account service does not receive

  • Your AI provider API keys, prompts, post or note content, generated drafts, local history, or batch queue.
  • Your X, Twitter, or Xiaohongshu password. The extension uses the platform session already present in your browser.
  • Clipboard contents, screenshots, contacts, precise location, or browsing history outside the declared supported sites.
  • Advertising profiles, product analytics, telemetry, or developer model-training data.

Why each permission or site access is requested

Permission or accessPurpose
storageStores local configuration, content history, queues, public login state, and temporary login state
tabsAssociates work with the correct tab, opens account pages, and restores the extension tab after an extension-started login
sidePanelDisplays the comment workspace in the browser side panel
alarmsSchedules batch work and bounded session rechecks
The configured official website originConnects the website session to this exact extension and checks or revokes restricted-action access
x.com and twitter.comReads the selected post and submits a chosen reply through your platform session
xiaohongshu.comReads selected notes and, when you explicitly choose it, submits single or scheduled batch comments
Configured AI provider or relay originsSends the generation request directly to the service you selected

The extension does not request the browser cookies permission. Extension UI and content scripts receive only a public account snapshot; ordinary web pages cannot read extension storage, and content scripts cannot read the private extension credential database.

Third parties

The website operator uses infrastructure providers to host the website, store account records, and deliver login email (the current mail adapter uses Resend). Google is contacted only when optional Google login is configured and selected. AI providers, relays, X, and Xiaohongshu receive data only for the actions described above.

Security

  • Website sessions use secure, HttpOnly cookies. Verification values, extension credentials, and rate-limit identifiers are stored as hashes on the server.
  • The extension keeps its bearer credential in extension-only IndexedDB and exposes only a public account snapshot to UI surfaces and content scripts.
  • Connection codes and browser challenges are short-lived and single-use. Website logout revokes extension sessions derived from that website session.
  • Model API keys remain in browser extension storage. Prefer a limited key and rotate it at the provider if your browser profile may have been exposed.

Your choices and controls

  • Log out on the official website to revoke that website session and the extension sessions connected through it. Local drafts, history, and queues remain on the device.
  • Delete model configurations and keys in extension settings, reset preferences, or clear local history and queues with the available controls.
  • Uninstall the extension or remove its browser profile to erase extension-local storage.
  • Contact the developer through the channel below for questions or a request concerning server-side account records.

Limited use

Data is used to provide login, account synchronization, abuse prevention, content generation, and the submissions you explicitly request. It is not sold or used for advertising, credit decisions, unrelated profiling, or training the developer’s models.

Children

This product is intended for social media creators and operators and is not directed to children under 13. The operator does not knowingly collect personal information from children.

Changes to this policy

When data handling changes materially, this source and its generated public copy are updated with the release and the date above is changed.

Questions

For questions about this policy or how your data is handled, use the developer contact on this extension’s Chrome Web Store listing under Support.