XGrowthKit extension privacy
Updated 3 October 2026. This extension has one purpose: connect your signed-in X account to XGrowthKit so you can publish replies you write and approve in Engage.
Data collected and consent
Only after you click “Agree and connect X”, the extension requests access to x.com and reads three cookies: auth_token, ct0, and twid (your X account ID). These are authentication information and give access to act as your signed-in account beyond OAuth. Your X account must match your XGrowthKit account. We do not collect your password, other websites’ cookies, browsing history, or private messages.
Use and sharing
The extension sends the cookies and account ID over HTTPS to xgrowthkit.app using a single-use token that expires after five minutes. XGrowthKit encrypts saved auth_token and ct0 values in its database. When you click Reply, XGrowthKit sends those cookies, your reply text and the target post ID to TwitterAPIs.com to publish your reply. This extension does not post automatically. TwitterAPIs.com processes the data under its own policies.
Retention and control
The extension temporarily stores the connection token in browser session storage, never the X cookies. Connection tokens expire after five minutes. Saved X cookies remain in XGrowthKit until you disconnect in Engage, delete your account, or the provider reports the session expired. Uninstalling the extension does not delete the saved server connection. Disconnect first to remove it. Revoking your X session in X also invalidates that session.
Limited use
Data is used only for the connection and replies you request. It is not sold, used for advertising, or transferred for unrelated purposes. Human access is limited to security or legal requirements. The extension’s use of data complies with the Chrome Web Store User Data Policy, including Limited Use requirements.
Contact
For access or deletion questions, contact [email protected].