Privacy Policy
Last updated: August 9, 2026
XReply is operated by Sohanur Rahman ("we", "us"). This policy explains what data XReply collects and how it's used, and covers both the XReply website/dashboard at xreply.net and the XReply Chrome extension. XReply is currently in beta.
1. Data we collect
Account and profile:
- Your X account ID, username, display name, email address, and public profile info, via "Sign in with X"
- Profile fields you fill in (name, role, bio, interests, tone preferences)
- Basic usage counts (replies and posts generated, credits remaining) to show on your dashboard
Content you submit for generation:
- The text of a post you click on X, plus the text of the post it is replying to, when you ask for a reply
- Image URLs attached to that post (the public X media links, up to four), when the post has images
- Draft text you type into the extension for impression prediction, quote-repost captions, or scheduled posts
- Images you upload in the extension to attach to a scheduled post
Voice-matching data (used to make replies sound like you):
- Replies you write and send manually on X while the extension is active, paired with the post you were replying to, saved as writing samples
- When you run "Personalize my reply," up to 50 of your own past replies from your public /with_replies page, each paired with the post it replied to, plus your public profile name, bio, and website link
Outreach ("leads") features, only if you use them:
- Your stated outreach goal and plan
- The X handle, display name, and any notes you type about a person you want to message
- Any reply text from that person that you paste in yourself, so the next message can follow on from it
Scheduling and analytics features, only if you use them:
- Posts you schedule and their scheduled times
- An X authorization you grant separately, if you connect your X account so XReply can publish scheduled posts on your behalf
- Your "Active times" engagement heatmap read from your own X analytics page, when you press Process in the extension's Insights tab. This is read from the page you are already signed into and is stored only in your browser
2. What we do not collect
- Your X password or X login credentials. Sign-in happens through X's own OAuth screen; we never see them
- Your direct messages on X. XReply does not read, scrape, or store your DM inbox. Outreach messages are drafted from what you type and are copied to your clipboard for you to send yourself
- Your browsing history, or the content of any site other than x.com and twitter.com
- Keystrokes, form input, cookies, or page content on any other website
- Payment card details. Payments, when enabled, are handled by our payment processor and card data never reaches our servers
3. How we use it
Solely to operate and improve the Service for you: authenticating you, generating replies, posts, captions, and outreach messages tailored to your profile, tone, and past writing, publishing posts you schedule, and showing your usage on the dashboard. We do not sell your data, we do not share it with third parties for advertising or any other unrelated purpose, we do not use it to build advertising profiles, and we do not use it to determine creditworthiness or for lending purposes. Your content is not used to train general-purpose AI models.
4. The Chrome extension
The XReply extension runs only on x.com and twitter.com. It activates when you click a post, open the side panel, or press its keyboard shortcut — it does not silently monitor your feed, and no post content leaves your browser unless you ask for something to be generated. The permissions it requests and why:
- Host access to x.com and twitter.com — to read the post you clicked and show XReply's controls on the page
- Host access to xreply.net and our Supabase project — to call the XReply API and sign you in
- storage — to keep your session, tone setting, feature toggles, saved drafts, and the local Insights report in your browser
- activeTab and scripting — to insert XReply's reply controls into the X tab you are using
- tabs — to detect which of your open tabs is X, to keep those tabs in sync when you sign in or out, and, when you enable the optional post-check feature, to briefly open a post in a background tab and read its public reply counts before closing it
- clipboardWrite — to copy a generated reply or message so you can paste it
- identity — to run the "Sign in with X" OAuth flow
- sidePanel — to show the XReply panel next to X
XReply's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension does not contain or load remote code — all of its logic ships inside the extension package.
5. Where data is stored
- In your browser only: your login session, tone and mode settings, feature toggles, daily reply counts, saved drafts and outreach plans you haven't sent, and the Insights heatmap report. Uninstalling the extension removes these
- On our servers: your account and profile, your writing samples, your scheduled posts and generated content, your outreach conversation history, and usage counts
6. Third parties
We use Supabase for authentication, database storage, and file storage; DeepInfra to generate reply, post, caption, and message text; Vercel to host the website and API; and X's own API to publish posts you schedule, if you connect your X account. Post text and your writing samples are sent to DeepInfra only when you actively ask for something to be generated. These providers process data on our behalf under their own terms; we do not sell or rent your data to anyone.
7. Retention and security
We keep your data for as long as your account is active. Data is transmitted over HTTPS and stored with per-user row-level access controls so one account cannot read another's data. When you delete your account, your profile, writing samples, generated content, and outreach history are deleted.
8. Your choices and rights
- Edit or clear your profile fields anytime from the dashboard
- Turn off automatic mode, the post-check feature, and the Insights scan from the extension's settings
- Disconnect your X publishing authorization from the extension's X connection panel at any time
- Uninstall the extension to stop all local collection and remove everything stored in your browser
- Request access to, correction of, export of, or deletion of your data — including account deletion — by emailing us
9. Children
XReply is not intended for anyone under 13, and we do not knowingly collect data from children.
10. Changes and contact
We may update this policy as the product develops; the "last updated" date above will change when we do. Questions, or any data request, to foundersohan@gmail.com.