隐私政策Privacy Policy
简而言之:DeepTweet 的核心功能无需注册账号、不收集密码;你的设置、AI 配置与缓存都保存在浏览器本地;AI 请求由浏览器直连你自己配置的提供商,不经过我们的服务器;扩展不会把你的推文内容或 X 登录凭据上传到开发者服务器。In short: DeepTweet's core features require no account and never collect passwords. Your settings, AI configuration and cache stay in your browser's local storage. AI requests go directly from your browser to the provider you configure — never through our servers. The extension never uploads your tweet content or X credentials to the developer's server.
1. 概述1. Overview
DeepTweet for X&Twitter(下称「本扩展」或「DeepTweet」)是一款独立开发的 Chrome 扩展(Manifest V3),在 X / Twitter 页面右侧注入智能侧边栏,提供多视图搜索、搜索辅助、AI Chat、数据导出、往年今日等功能。本政策说明本扩展如何处理你的数据,以及你拥有的选择权。DeepTweet for X&Twitter ("the Extension", "DeepTweet") is an independently developed Chrome extension (Manifest V3) that injects a smart sidebar into X / Twitter pages, offering multi-view search, a search assistant, AI Chat, data export, On This Day and more. This policy explains how the Extension handles your data and the choices you have.
2. 扩展权限及其用途2. Browser Permissions and How They Are Used
本扩展在 manifest.json 中声明了以下权限,各权限的用途如下:The Extension declares the following permissions in its manifest.json. Each is used for a specific purpose:
-
cookies 与 webRequest:用于复用你在当前浏览器中已登录的 X Web 会话。具体来说,扩展读取 X 的登录 Cookie(如会话令牌),并在访问 X Web 端公开接口时按 X 的要求携带必要的请求头。这些凭据仅用于从你的浏览器直接向
x.com/api.x.com发起请求,以提供搜索、时间线、书签与导出等功能;它们不会被发送到开发者服务器或任何第三方。cookies and webRequest: used to reuse the X web session you are already logged into in this browser. Concretely, the Extension reads X's login cookies (such as the session token) and attaches the request headers X requires when calling its public web APIs. These credentials are only used to make requests from your browser directly tox.com/api.x.com— for search, timelines, bookmarks and export. They are never sent to the developer's server or any third party. - storage:用于在浏览器本地保存你的偏好设置(主题、标签页开关等)、AI 提供商配置(含 API Key)、数据缓存与导出任务进度。这些数据存储在你的设备上,由你全权控制;卸载扩展或清除浏览器数据即可将其删除。storage: used to keep your preferences (theme, tab toggles), AI provider configuration (including API keys), data caches and export job progress in the browser's local storage. This data stays on your device under your control, and can be removed by uninstalling the Extension or clearing browser data.
此外,扩展声明了若干站点访问权限(host permissions):X 相关域名(x.com、api.x.com 等,为功能所必需)、各 AI 提供商的 API 域名(见第 5 节),以及开发者运营的服务域名(见第 4 节)。In addition, the Extension declares several host permissions: X-related domains (x.com, api.x.com, etc., required for its features), the API domains of supported AI providers (see Section 5), and a server domain operated by the developer (see Section 4).
3. 我们如何处理 X 数据3. How X Data Is Handled
- 扩展不收集、不存储、不传输你的 X 密码,也不要求你为使用核心功能注册任何账号——它复用你浏览器中已有的 X 登录态。The Extension never collects, stores or transmits your X password, and does not require any account for its core features — it reuses the X login session already present in your browser.
- 搜索、浏览与导出的内容通过 X 公开接口直接返回到你的浏览器;导出的文件直接保存到你电脑的本地磁盘。Search, browsing and export results come back to your browser directly from X's public APIs, and exported files are saved straight to your computer's local disk.
- 扩展不会把你的推文、私信、关注关系或浏览历史上传到开发者服务器。The Extension does not upload your tweets, direct messages, social graph or browsing history to the developer's server.
4. 可选邮箱登录与开发者服务器4. Optional Email Sign-in and the Developer's Server
本扩展的所有核心功能均无需账号即可使用。扩展另提供完全可选的邮箱登录功能,用于账户相关能力。只有当你主动在侧边栏的登录面板中输入邮箱并请求验证码时,扩展才会连接开发者运营的登录服务;不使用该功能时,扩展不会与该服务通信。All core features of the Extension work without any account. The Extension additionally offers a completely optional email sign-in for account-related capabilities. Only when you actively enter your email address in the sidebar's sign-in panel and request a verification code will the Extension contact a sign-in service operated by the developer. If you never use this feature, the Extension does not communicate with this service.
- 发送的数据:仅你主动输入的邮箱地址。服务器会向该邮箱发送 6 位验证码或确认链接;验证通过后创建会话并返回会话令牌,令牌保存在浏览器本地。What is sent: only the email address you voluntarily provide. The server emails you a 6-digit verification code or a confirmation link; once verified, it creates a session and returns a session token, which is stored locally in your browser.
- 服务器存储的数据:你的邮箱地址、经 SHA-256 哈希处理的验证码与令牌(不存明文),以及会话记录(存于 Cloudflare D1 数据库)。What the server stores: your email address, SHA-256 hashes of verification codes and tokens (never in plaintext), and session records (in a Cloudflare D1 database).
- 该服务不会接收:你的 X 登录凭据、Cookie、推文内容或浏览数据。What the service never receives: your X credentials, cookies, tweet content or browsing data.
- 你可以随时在扩展内退出登录,服务器端会话将同时被吊销。You can sign out within the Extension at any time, which also revokes the server-side session.
5. AI Chat 与第三方 AI 提供商5. AI Chat and Third-Party AI Providers
- AI Chat 与 AI 翻译等功能使用你自己配置的模型提供商(如 OpenAI、DeepSeek、OpenRouter、智谱、Moonshot、MiniMax、阿里 DashScope、x.ai、Groq、SiliconFlow、Mistral 等)。你的 API Key 保存在浏览器本地存储中,仅随请求发往你所配置的提供商。Features such as AI Chat and AI translation run on the model provider you configure yourself (e.g. OpenAI, DeepSeek, OpenRouter, Zhipu, Moonshot, MiniMax, Alibaba DashScope, x.ai, Groq, SiliconFlow, Mistral). Your API key is kept in the browser's local storage and is only sent to the provider you configured, as part of your requests to it.
- AI 请求由你的浏览器直接发往所选提供商的 API,不经过开发者服务器中转;你的 API Key 与对话内容不会发送到开发者服务器。AI requests go directly from your browser to the chosen provider's API, without passing through the developer's server. Neither your API key nor your conversations are sent to the developer's server.
- 当你针对某个 X 账号使用 AI Chat 时,扩展会通过 X 公开接口拉取该账号的公开资料与推文,并将其作为对话上下文发送给你选择的 AI 提供商。该提供商对这些数据的处理适用其自身的隐私政策,请在配置前查阅。When you use AI Chat about an X account, the Extension fetches that account's public profile and tweets via X's public APIs and includes them as conversation context sent to your chosen AI provider. That provider's own privacy policy governs how it handles this data — please review it before configuring the provider.
6. 匿名使用统计6. Anonymous Usage Analytics
为了解哪些功能被使用、改进产品,本扩展通过 Google Analytics 4(Measurement Protocol)收集匿名的功能使用统计。我们刻意将收集范围控制在最小:To understand which features are used and to improve the product, the Extension collects anonymous feature-usage statistics via Google Analytics 4 (Measurement Protocol). Collection is deliberately kept to a minimum:
- 事件仅包含功能名称与少量非内容参数(例如「执行了一次搜索」「切换到某个标签页」「打开设置」),不包含搜索关键词、用户名、推文内容、邮箱地址或 API Key。Events contain only feature names and a few non-content parameters (e.g. "a search was performed", "switched to a tab", "opened settings") — never search keywords, usernames, tweet content, email addresses or API keys.
- 统计标识符是在你浏览器本地生成的随机 UUID,保存在本地存储中,不与你的任何真实身份关联。The analytics identifier is a random UUID generated and kept in your browser's local storage, and is not linked to any real-world identity.
- 扩展不含广告 SDK,不进行跨站行为跟踪;统计数据发送失败会被静默忽略,不影响任何功能。The Extension contains no advertising SDKs and performs no cross-site behavioral tracking. Failed analytics deliveries are silently ignored and never affect functionality.
7. 我们不会做的事7. What We Do Not Do
- 不收集你的 X 密码或任何网站的登录密码。We do not collect your X password or the login password of any website.
- 不出售、出租或以任何方式与第三方交易你的个人数据。We do not sell, rent or otherwise trade your personal data with third parties.
- 不在开发者服务器上保存你的推文、私信、关注关系或浏览历史。We do not store your tweets, direct messages, social graph or browsing history on the developer's server.
- 不要求注册账号即可使用搜索、AI Chat、导出等核心功能。We do not require account registration for core features such as search, AI Chat or export.
8. 免责声明8. Disclaimer
- 本扩展为非官方第三方扩展,与 X Corp. / Twitter 无任何关联,亦未获得其授权或背书。「X」「Twitter」及相关商标归其各自所有者所有。The Extension is an unofficial third-party extension and is not affiliated with, authorized or endorsed by X Corp. or Twitter. "X", "Twitter" and related trademarks belong to their respective owners.
- 本扩展依赖 X Web 端的公开接口。X 的接口策略、访问限制或服务条款发生变化时,扩展的部分或全部功能可能降级或失效;我们会尽力通过版本更新跟进,但不对此作出保证。The Extension relies on the public interfaces of the X web app. If X changes its API policies, access restrictions or terms of service, some or all features may degrade or stop working. We will do our best to keep up through version updates, but make no guarantee of continued availability.
- 你在使用本扩展访问 X 时仍应遵守 X 的服务条款;因使用本扩展而产生的账号相关风险(如访问频率限制)由你自行承担。You remain responsible for complying with X's Terms of Service when using the Extension, and you assume any account-related risks arising from its use (such as rate limiting).
9. 本政策的更新9. Changes to This Policy
如本政策发生变化,我们会在本页面公布新版本并更新顶部日期;涉及数据处理方式的重要变更,会随扩展版本更新说明一并告知。建议你定期查阅本页面。If this policy changes, we will publish the revised version on this page and update the date above. Material changes to how data is handled will be noted alongside the Extension's release notes. We encourage you to review this page periodically.