Winnow privacy

Effective 27 August 2026

Winnow's single purpose is to identify and locally collapse low-effort, automated-looking replies on X. It does not ask for an X password, read X cookies, call X APIs, or act on an X account.

What stays in this browser

Winnow scores public reply text and account metadata that X already delivered to the open page. Local extension storage may hold settings, user-created handle lists, correction feature vectors, local template hashes, aggregate and private daily counts, a random trial install ID, licence state, up to six 70-character diagnostic previews, and—on Pro—up to 300 review entries containing a handle and at most 400 reply characters.

Free mode and the no-card trial need no Winnow account or server. Local data remains until a bounded limit evicts it, you clear it in Settings, you reset Winnow, or you uninstall the extension. Trial timestamps and the anonymous install ID also use Chrome sync storage so a normal reinstall in the same browser profile does not restart the trial; reply content, handles, review entries, corrections, and licence keys are not synced there.

What Pro activation sends

Only when you press Activate or Check again, Winnow asks for optional access to Polar and sends the licence key you entered plus Winnow's public Polar organization UUID. Polar returns the licence status and, when present, an expiry time. No X content, handle, post ID, install ID, review entry, custom rule, correction, or insight is included.

Ordinary network infrastructure and Polar may process the request IP address, time, user agent, and response status for security and operation.

Payments and sharing

The Subscribe button opens Polar-hosted checkout. Polar processes account, purchase, and payment details under its own policy. The extension does not receive or store card details, email addresses, billing addresses, or Polar customer records.

Winnow shares only the activation payload above with Polar. It does not sell data or use it for advertising, data brokerage, credit decisions, or unrelated analytics. A person receives X content only if you explicitly copy a redacted diagnostic report and choose to send it to support.

Your controls

Settings lets you clear diagnostics, learning data, local template memory, counts, review queue, licence, or all local data. Chrome/Google account settings control the minimal synced trial marker. Polar retains purchase and licence information under Polar's policies.

Permissions and security

Winnow uses storage, unlimitedStorage, sidePanel, and alarms, with required host access limited to x.com and twitter.com. Optional access is limited to https://api.polar.sh/* and is requested only from an activation action. Winnow does not request cookies, webRequest, identity, tabs, all-URL host access, or access to other websites.

Polar activation uses HTTPS. A last valid licence can remain active for up to 14 days only during an unreachable-network failure; an explicit rejection or known expiry is not extended. Winnow contains no remote executable code and follows the Chrome Web Store Limited Use requirements.

Contact and changes

Material data-practice changes will be disclosed before they take effect. For privacy questions, email winnow.official.desk@gmail.com. The public policy is available at winnow.sbintekamal06.chatgpt.site/privacy.