Privacy Policy
Last updated: May 31, 2026
Overview
XStickies is a browser extension that lets you add personal notes and tags to X/Twitter profiles. XStickies is local-first: by default everything stays in your browser. Cloud features are strictly optional and only activate if you choose to sign in.
- Without signing in — all notes and tags stay in your browser; nothing is sent to our servers.
- If you sign in with Google (optional) — your notes are synced across your devices through our backend, and we receive basic Google account information to authenticate you (details below).
What We Collect
XStickies only stores data you create or explicitly authorize. There are no analytics scripts, no advertising identifiers, and no third-party trackers.
- Your notes: the note text you write, the X/Twitter usernames you attach notes to, and the tags you create.
- Google account information (only after you choose to sign in for sync): your email address, display name, profile picture URL, and Google account identifier. This is obtained via Google Sign-In.
- Sync metadata: technical information such as timestamps, used to keep your notes consistent across your devices.
XStickies does not collect your browsing history, the content of the pages you visit (beyond the usernames you choose to note), keystrokes, or your X/Twitter credentials.
How Data Is Stored
- Logged out: your notes are stored locally in your browser. If you're signed into Chrome, Chrome may sync them across your devices through your own Google/Chrome account — not through us.
- Logged in: your notes are stored on our servers, associated with your account, and transmitted securely over HTTPS.
- You can export all your data as JSON at any time from the extension's management page.
- Uninstalling the extension removes locally stored data.
How We Use Your Data
- To save and display your notes on X.
- To authenticate you and synchronize your notes across your devices.
We do not sell, rent, or share your data for advertising or any unrelated purpose.
Data Retention & Deletion
- Notes persist until you delete them. When you delete a note it is removed from your devices; any residual deletion records are cleared within 30 days.
- Items in the in-extension Trash are automatically purged 14 days after deletion.
- You can permanently delete your entire server-side account and all associated data at any time using the "delete account" action in the extension — this immediately removes your records from our database.
Google API Limited Use
XStickies's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used solely to provide the sign-in and sync features and is never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
Permissions
- Host access (x.com): to inject the content script that shows note popups on X/Twitter.
- Storage: to save and retrieve your notes and tags.
- Identity: to perform the optional Google Sign-In for cloud sync.
- Alarms: to schedule periodic background tasks such as syncing your data.
- Host access (accounts.google.com, our sync API domain): to sign you in and sync your data when you opt into sync.
XStickies cannot access your data on websites other than X/Twitter.
Third Parties
- We use third-party cloud infrastructure providers to host and operate our backend; they process synced data on our behalf solely to provide the service.
- Google provides the optional sign-in service.
Notes you write may reference third-party X users. You are responsible for the content you record and for complying with applicable laws. There are no ads, no affiliate links, and no monetization of user data.
Children
XStickies is not directed to children under 13, and we do not knowingly collect their data.
Updates
This privacy policy may be updated to reflect changes in the extension. Any changes will be posted on this page with an updated date.
Contact
Questions about this privacy policy? Email us at [email protected].