English 中文

Privacy Policy

Last updated: June 29, 2026

This Privacy Policy describes how the Refreshing browser extension ("the Extension," "we," "us") collects, uses, stores, and shares user data. The Extension is designed for use on X (formerly Twitter) and provides AI-generated replies, batch unfollow, following/blocked-list export, keyword monitoring with auto-follow, and spam-account detection.

By installing and using the Extension, you consent to the data practices described in this Privacy Policy.

1. Data We Collect

1.1 Data You Provide

1.2 Data Automatically Collected

1.3 Data Read from X (Twitter)

2. How We Collect Data

3. How We Use Data

4. Data Storage

4.1 chrome.storage.sync (synced via your Google account across devices)

NVIDIA API key, persona list, model ID, preview count, keyword monitoring configuration (follow mode, AI filter mode, AI model, follower thresholds, scroll count, delays, rate limits, browse time, panel mode, keyword selections, keyword text), UI language preference, AI button position, risk acknowledgment flag.

4.2 chrome.storage.local (persistent on this device only)

Keyword monitoring state/stats/logs/accumulated data/rate queue/intercepted user data/session token, batch unfollow progress and pending configuration, export panel states, MXGA spam-detection data (blocked ID sets, blocklist records, per-user verdict cache, block queue, whitelist, skip status, stats), XVM settings and status.

4.3 chrome.storage.session (cleared when browser closes)

X Bearer token, keyword-monitor panel window ID, global X write-operation timestamps for rate limiting.

4.4 IndexedDB (service worker context)

Persona list database — stores persona names, version number, and last-check timestamp for the persona update mechanism.

4.5 localStorage (on x.com pages)

XVM panel position/minimize state, MXGA block-timing state, MXGA onboarding flag.

4.6 In-Memory Only (not persisted)

X CSRF token, X user ID, tweet text/images for AI processing, device fingerprint, intercepted GraphQL response bodies (after processing).

5. Data Retention

6. Data Sharing with Third Parties

The Extension shares certain data with the following third parties. We do not sell user data. All data sharing is strictly for functionality purposes.

6.1 NVIDIA AI API (integrate.api.nvidia.com)

TriggerData SentPurpose
AI Reply (via Cloudflare Worker)Tweet text, author usernames, tweet images (base64), AI persona name, your NVIDIA API key (or built-in key if none configured)Generate AI-suggested replies
Keyword Monitor AI Filtering (direct connection)Candidate user's display name, bio/description, tweet text, your NVIDIA API keyEvaluate whether a user matches content criteria before auto-following

NVIDIA Privacy Policy: https://www.nvidia.com/en-us/about-nvidia/privacy-policy/

6.2 Cloudflare Worker (ai-server-worker.ai-refreshing.workers.dev)

Our self-operated Cloudflare Worker acts as a proxy between the Extension and NVIDIA's API. When you use the AI reply feature, the Worker receives the full request payload (tweet text, usernames, images, persona name, API key), reads the persona prompt from Cloudflare Workers KV, and forwards the request to NVIDIA. The Worker does not log or store your request data beyond transient processing.

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

6.3 DuckDuckGo (lite.duckduckgo.com)

When the AI reply agent determines that a web search is needed, the Extension sends a search query (generated by the AI model from the tweet context, not your direct input) to DuckDuckGo Lite. No personal information or X account data is included in the search request.

DuckDuckGo Privacy Policy: https://duckduckgo.com/privacy

6.4 xhunt KOL Ranking (kb.cryptohunt.ai)

When you export your following or blocked list and opt in to the "Include xhunt ranking" option, the Extension sends the list of X screen names (public usernames), the current page URL, and a random per-session device fingerprint to the xhunt ranking API to retrieve KOL ranking data.

Data SentPurpose
X screen names (from your exported list), page URL, random device fingerprint, request signatureRetrieve KOL ranking scores for exported accounts

6.5 MXGA Edge Service (x.zuoluo.tv)

The spam-detection module communicates with the MXGA Edge service for two purposes:

6.6 Cloudflare Pages (ai-server-page.pages.dev)

The Extension downloads the persona list and version information from Cloudflare Pages. This is a download-only operation; no user data is uploaded.

6.7 X (Twitter) First-Party API

The Extension makes requests to X's own API endpoints using your active session (Bearer token + CSRF cookie) for the following purposes: exporting your following/blocked lists, blocking accounts (spam detection), and triggering Bearer token re-capture. These requests are made as your own authenticated session and do not pass through any Extension-operated server.

7. How Third Parties Use Your Data

Each third party listed in Section 6 processes data according to their own privacy policies (linked in each subsection). We do not control how NVIDIA, Cloudflare, DuckDuckGo, xhunt, or the MXGA Edge service process data after receipt. We encourage you to review their privacy policies.

8. Data Security

9. Your Choices and Controls

10. Children's Privacy

The Extension is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. X's own Terms of Service require users to be at least 13 years old. If you believe a child under 13 has provided personal information through the Extension, please contact us so we can take appropriate action.

11. Sensitive Information

The Extension reads X user bios (profile descriptions) and tweet content, which may contain sensitive personal information (including health conditions, political views, religious beliefs, sexual orientation, or other sensitive self-descriptions). When AI features are used, this content is transmitted to NVIDIA for processing. If you do not want sensitive tweet or bio content transmitted to NVIDIA, do not use the AI reply or AI content filtering features.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.

13. Contact Us

If you have questions or concerns about this Privacy Policy or the Extension's data practices, you can contact us on X (Twitter): @ThanksuTrump


隐私权政策

最后更新:2026 年 6 月 29 日

本隐私权政策描述了 Refreshing 浏览器扩展(以下简称"本扩展"、"我们")如何收集、使用、存储和共享用户数据。本扩展适用于 X(原 Twitter)平台,提供 AI 生成回复、批量取关、关注/屏蔽列表导出、关键词监控自动关注和垃圾账号检测等功能。

安装并使用本扩展即表示您同意本隐私权政策中所述的数据处理实践。

1. 我们收集的数据

1.1 您主动提供的数据

1.2 自动收集的数据

1.3 从 X (Twitter) 读取的数据

2. 我们如何收集数据

3. 我们如何使用数据

4. 数据存储

4.1 chrome.storage.sync(通过 Google 账号跨设备同步)

NVIDIA API 密钥、人格列表、模型 ID、预览数量、关键词监控配置(关注模式、AI 过滤模式、AI 模型、粉丝阈值、滚动次数、延迟、速率限制、浏览时间、面板模式、关键词选择、关键词文本)、界面语言偏好、AI 按钮位置、风险确认标记。

4.2 chrome.storage.local(仅本机持久存储)

关键词监控状态/统计/日志/累计数据/速率队列/拦截的用户数据/会话令牌、批量取关进度和待执行配置、导出面板状态、MXGA 垃圾检测数据(已拉黑 ID 集、拉黑记录、每用户判定缓存、拉黑队列、白名单、跳过状态、统计)、XVM 设置和状态。

4.3 chrome.storage.session(浏览器关闭时清除)

X Bearer 令牌、关键词监控面板窗口 ID、全局 X 写操作时间戳(用于速率限制)。

4.4 IndexedDB(Service Worker 上下文)

人格列表数据库 — 存储人格名、版本号和上次检查时间戳,用于人格更新机制。

4.5 localStorage(在 x.com 页面上)

XVM 面板位置/最小化状态、MXGA 拉黑计时状态、MXGA 引导完成标记。

4.6 仅内存(不持久化)

X CSRF 令牌、X 用户 ID、用于 AI 处理的推文文本/图片、设备指纹、拦截的 GraphQL 响应体(处理后即丢弃)。

5. 数据保留期限

6. 与第三方的数据共享

本扩展与以下第三方共享特定数据。我们不出售用户数据。 所有数据共享严格用于功能实现。

6.1 NVIDIA AI API (integrate.api.nvidia.com)

触发场景发送数据用途
AI 回复(经 Cloudflare Worker)推文文本、作者用户名、推文图片(base64)、AI 人格名、您的 NVIDIA API 密钥(未配置则使用内置密钥)生成 AI 建议回复
关键词监控 AI 过滤(直连)候选用户昵称、简介/描述、推文内容、您的 NVIDIA API 密钥在自动关注前评估用户是否符合内容标准

NVIDIA 隐私政策:https://www.nvidia.com/en-us/about-nvidia/privacy-policy/

6.2 Cloudflare Worker (ai-server-worker.ai-refreshing.workers.dev)

我们自行运营的 Cloudflare Worker 作为扩展与 NVIDIA API 之间的代理。当您使用 AI 回复功能时,Worker 接收完整请求载荷(推文文本、用户名、图片、人格名、API 密钥),从 Cloudflare Workers KV 读取人格提示词,然后将请求转发至 NVIDIA。Worker 不记录或存储您的请求数据(除瞬时处理外)。

Cloudflare 隐私政策:https://www.cloudflare.com/privacypolicy/

6.3 DuckDuckGo (lite.duckduckgo.com)

当 AI 回复代理判定需要网络搜索时,本扩展向 DuckDuckGo Lite 发送搜索查询(由 AI 模型根据推文上下文生成,非您的直接输入)。搜索请求中不包含个人信息或 X 账号数据。

DuckDuckGo 隐私政策:https://duckduckgo.com/privacy

6.4 xhunt KOL 排名 (kb.cryptohunt.ai)

当您导出关注或屏蔽列表并勾选"包含 xhunt 排名"选项时,本扩展将 X 用户名列表(公开用户名)、当前页面 URL 和随机会话级设备指纹发送至 xhunt 排名 API 以获取 KOL 排名数据。

发送数据用途
X 用户名列表(来自导出列表)、页面 URL、随机设备指纹、请求签名获取导出账号的 KOL 排名分数

6.5 MXGA Edge 服务 (x.zuoluo.tv)

垃圾检测模块与 MXGA Edge 服务通信用于两个目的:

6.6 Cloudflare Pages (ai-server-page.pages.dev)

本扩展从 Cloudflare Pages 下载人格列表和版本信息。此为纯下载操作,不上传用户数据。

6.7 X (Twitter) 第一方 API

本扩展使用您的活动会话(Bearer 令牌 + CSRF cookie)向 X 自身 API 端点发起请求,用于以下目的:导出关注/屏蔽列表、拉黑账号(垃圾检测)、触发 Bearer 令牌重新捕获。这些请求作为您自身的认证会话发起,不经过任何扩展运营的服务器。

7. 第三方如何使用您的数据

第 6 节中列出的每个第三方均根据其自身的隐私政策处理数据(各小节已附链接)。我们不控制 NVIDIA、Cloudflare、DuckDuckGo、xhunt 或 MXGA Edge 服务在收到数据后的处理方式。建议您查阅各自的隐私政策。

8. 数据安全

9. 您的选择和控制

10. 未成年人隐私

本扩展不面向 13 岁以下儿童。我们不会故意收集 13 岁以下儿童的个人信息。X 自身的服务条款要求用户至少年满 13 岁。如果您认为有 13 岁以下儿童通过本扩展提供了个人信息,请联系我们以便采取适当措施。

11. 敏感信息

本扩展会读取 X 用户简介(个人资料描述)和推文内容,其中可能包含敏感个人信息(包括健康状况、政治观点、宗教信仰、性取向或其他敏感自述)。使用 AI 功能时,这些内容会传输至 NVIDIA 进行处理。如您不希望敏感推文或简介内容传输至 NVIDIA,请勿使用 AI 回复或 AI 内容过滤功能。

12. 隐私政策变更

我们可能不时更新本隐私权政策。变更将发布在此页面上,并更新"最后更新"日期。建议您定期查阅此页面。

13. 联系我们

如对本隐私权政策或本扩展的数据处理实践有疑问或顾虑,可通过 X (Twitter) 联系我们:@ThanksuTrump