Privacy Policy

Last updated: 2026-09-30

Summary

X Blocker does not collect, transmit, sell or share any personal or usage data with the developer or any third party. It is a local-only Chrome extension: everything it does happens inside your own browser, talking directly to X's (Twitter's) own servers.

What the extension does

It adds a one-click block icon next to posts on x.com and twitter.com, and lets you define keywords and regular expressions to scan the timeline you are already viewing. Matching accounts are added to a candidate list that you review and confirm before anything is blocked; fully automatic mode is opt-in and off by default.

To do that, the extension reads page content that is already visible to you — post text, display names, handles — and calls the same internal endpoints x.com itself uses (POST /i/api/1.1/blocks/create.json and its unblock counterpart) to block or unblock the accounts you choose, using the session you are already signed in with.

Data collection

None. The extension has no backend server, uses no analytics, telemetry or crash-reporting SDKs, and never sends data to the developer.

Data stored on your device

Everything below is stored only on your device using the browser's storage API, mirrored into x.com's own local storage so your settings survive a reinstall:

  • Your keyword filters, regular expressions and allowlist.
  • Your settings: throttling values, which fields to match, and the automation toggle.
  • A local action log — who was blocked or unblocked, when, and which rule matched — used only so you can review and undo actions.
  • A short-lived technical cache of X's internal query IDs and handle-to-account-id lookups, needed to call the block endpoint reliably.

None of this ever leaves your browser. It is deleted if you remove the extension or clear site data for x.com.

Permissions

  • storage — save your filters, settings and log locally in the browser.
  • Access to x.com, twitter.com, api.x.com, api.twitter.com — inject the block icon and the panel into the page, and call X's own block and unblock endpoints on your behalf.

No other permissions are requested: no access to your tabs, no access to other websites, no request blocking and no remote code execution.

Third parties

None. Every network request goes straight from your browser to X's own domains — the same requests x.com already makes when you use its built-in Block button. You are not added to any shared or crowd-sourced blocklist.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a new date.

Contact

Questions about this policy? Email [email protected] or visit the contact page.