Ownfeed Privacy Policy
Last updated: September 9, 2026
Ownfeed is a personal agent that helps a user filter and discover content on X. This document describes the public cloud version of Ownfeed.
Data Ownfeed processes
Ownfeed may process:
- an opaque account identifier derived from the verified identity provider subject;
- X posts and thread context rendered in the user's browser when needed to provide Shield decisions;
- explicit Ownfeed feedback, confirmed X Like / Bookmark state changes, chat messages, Workspace files, receipts and Undo history;
- recommendations, content exposure records and saved items;
- normalized results of X searches performed in an extension-owned background tab, automatically while X is foreground or within a bounded window after the user requests recommendations;
- up to 200 recent X Likes and 200 recent Bookmarks only after the user starts initialization and grants one-time Cookie access;
- bounded operational metadata such as timestamps, request IDs and error codes needed to operate and secure the service.
- optional product-usage events, after the user selects “Agree and log in with X” and successfully authenticates, or explicitly enables “Help improve Ownfeed” in Settings → Data & privacy for that account in that browser.
- optional AI inputs, outputs and tool traces, after the user selects that explicit sharing/sign-in action and successfully authenticates, or separately agrees to enable “AI diagnostics” for that account in settings.
Ownfeed does not collect an X password. The extension may request Chrome's optional Cookie permission only after the user presses Start initialization. It reads only X's auth_token and ct0, immediately releases the permission, then uses those in-memory values inside that browser for one bounded read-only Likes/Bookmarks import. Cookie values, tokens and request headers are never sent to Ownfeed Cloud, Workspace, the model provider, logs or data exports. Only validated, normalized post content is sent to the user's isolated cloud Agent.
Separately enabled trial builds also offer an explicit “Search with this X session” button. This requests one-time Cookie access and access to X's static assets at abs.twimg.com. The extension reads only ct0, releases Cookie permission immediately, and uses the browser's own login session for read-only searches for at most three minutes. Cookie values and authentication headers remain in the browser; normalized search results go to your cloud Agent and model provider for selection. Expiry, sign-out, worker restart or an access error ends the window. This trial is not enabled in the public build and does not change automatic discovery or silently use paid X API access.
How the data is used
The data is used only to provide and improve Ownfeed's user-facing features: real-time filtering, explanations, personalized discovery, conversation, a correctable Workspace, feedback learning, persistence, export and deletion. Ownfeed does not sell user data or use it for personalized advertising.
Social-media text is treated as untrusted content. It cannot directly instruct the Agent or change the user's Workspace. A semantic change must pass Ownfeed's evidence, scope, revision and receipt boundaries.
Service providers
Ownfeed uses Auth0 to provide X sign-in, Cloudflare Workers and Durable Objects to run and store each user's isolated Agent state, and OpenRouter to route Agent requests to a model provider. Browser discovery sends Agent-authored queries to X's search page using the browser's existing login session. It does not extract or upload Cookie values. Normalized result posts return to the user's cloud Agent for selection. There is no automatic fallback to paid X API search. These processors receive only the data needed to provide the requested feature. Agent requests explicitly require providers that deny data collection and support zero data retention; Ownfeed does not enable OpenRouter prompt logging.
Ownfeed personnel do not read a user's posts, conversations or Workspace except when the user explicitly asks for support involving specific data, explicitly enables AI diagnostics for troubleshooting and AI improvement, when required for security or law, or when data has been aggregated and anonymized for internal operations. Access to AI diagnostics is limited to authorized personnel for those purposes.
Your sharing choice at sign-in
The sign-in screen shows a short notice immediately after the privacy-policy link, covering usage statistics and the conversations, posts and preference text processed by AI. Its single “Agree and log in with X” action explicitly authorizes both product analytics and AI diagnostics for the authenticated account after sign-in succeeds. A failed or cancelled authentication grants nothing. There is no separate first-sign-in action to skip sharing. After signing in, you can turn either collection off independently in Settings → Data & privacy and continue using Ownfeed.
The expandable details explain the PostHog (US) destination, troubleshooting and AI-improvement purposes, readable AI content and tool inputs/results, credential exclusions, the different scopes and retention below, and how to turn each option off independently in Settings → Data & privacy. There is no checkbox. Showing the screen, restoring a session or upgrading does not grant consent or re-enable a previously disabled choice. A later click on the explicit agreement is a new authorization, even if one or both options were previously disabled.
Optional product analytics
Product analytics is enabled through the explicit sharing/sign-in action above. After signing in, you can turn it off or explicitly enable it again with its own control in Settings → Data & privacy. Enabling only the product-analytics control never enables AI diagnostics. Both can be turned off independently without losing access to Ownfeed, and updates preserve existing enabled and disabled choices.
Product-analytics consent applies only to the currently signed-in account and browser. Sign-out, a new sign-in or clearing product data resets it. The explicit sharing/sign-in action enables it after successful authentication; otherwise, enabling it again requires an explicit choice in Settings → Data & privacy. A restored session alone does not grant consent.
When enabled, Ownfeed's server sends a small allowlist of events to PostHog's US service: enabling analytics, opening the panel, first-use setup becoming ready after completion or choosing to import later, a completed automatic Shield collapse, successful visible-recommendation receipts, confirmed save or feedback delivery, and the HTTP outcomes of initialization, initialization confirmation, conversation, Workspace decisions and Undo requests. Events contain a separate pseudonymous account identifier, a random account-bound activity-session ID, an event ID and timestamp, Ownfeed version, environment, consent version, event name and HTTP result. Thirty minutes without Ownfeed Cloud activity while analytics remains enabled, or an account switch, starts a new activity session. Events that occurred before consent are not sent later. This is pseudonymous data, not a claim of anonymous data. PostHog also adds SDK and ingestion metadata.
These events contain no X post content or URLs, searches, chat text, Workspace content, names, handles, email addresses, X identifiers, Cookies, access tokens or raw error messages. Ownfeed does not enable automatic page or click tracking, session recording, person-profile processing or automatic exception capture. The extension does not connect directly to PostHog; the server does not forward the user's IP address or request headers to PostHog and disables IP-based geolocation for these events.
Turning off analytics stops future events; a request already sent while consent was enabled may finish. Clearing Ownfeed product data deletes the account's product state but does not automatically erase previously sent PostHog events. For access or deletion of earlier analytics, contact privacy@ownfeed.ai. While signed in, the extension can derive and display the same pseudonymous lookup reference used on matching PostHog events; this happens locally and does not send a new event. No automatic analytics-retention deadline is promised in this version; events remain under the configured PostHog retention settings until expiry or a processed deletion request.
Optional AI diagnostics
AI diagnostics is controlled separately from content-free product analytics. Selecting the explicit sharing/sign-in action and successfully authenticating, or selecting “Agree and enable AI diagnostics” in Settings → Data & privacy, permits Ownfeed's server to send new AI model loops to PostHog (US), including conversation inputs and responses, posts and Workspace preference context included in model calls, and tool arguments and results. Records also include the model, provider request ID, tokens, reported cost, timing, stop reason, task and release identifiers, and the same account lookup reference used by product analytics. Ordinary content remains readable and can contain names, handles or other personal information already present in the model context. Credential filtering and size limits are applied; Cookies, authentication headers, IP addresses and recordings are not intentionally collected. Authorized personnel may use these diagnostics to investigate failures and improve Ownfeed's AI features, not for advertising or unrelated purposes.
Consent applies to the signed-in account's chat and background AI tasks across browsers. Sign-out, restored sessions and updates do not grant or revoke this account-level choice. The explicit sharing/sign-in action is a new agreement that can enable it after successful authentication. Turning AI diagnostics off in settings or clearing product data stops new collection. A request already sent may finish. A model loop that started before consent is not backfilled, although later model calls may naturally include earlier conversation or Workspace context. Product-analytics consent by itself never enables AI content collection.
Standard AI content fields follow PostHog's current 30-day AI-content retention. Model, token, cost, timing and other small metadata follow the project's event retention settings. Turning collection off or clearing product data does not erase earlier PostHog records; access or deletion requests use privacy@ownfeed.ai and the account lookup reference in Data help. OpenRouter Broadcast and OpenRouter prompt logging are not enabled by this feature. The model-provider zero-retention routing policy remains unchanged and does not apply to the optional PostHog diagnostic copy.
Retention and user control
Workspace evidence, explicit feedback, saved items and current Agent state are retained while the user uses Ownfeed so the Agent can remain consistent across browser restarts. Ownfeed periodically bounds the oldest passive browsing observations, Shield decision history, unreferenced content and unreferenced confirmed X-action history; this maintenance does not remove explicit feedback, saved content, active rules, Workspace evidence or in-progress work. The extension provides controls to:
- inspect and correct the current Workspace;
- Undo individual changes and feedback effects;
- export the user's Ownfeed data;
- delete Ownfeed product state for that account (the separate analytics and operational-log handling is explained here);
- sign out and remove locally stored account tokens.
- turn off optional product analytics;
- separately turn off account-level AI diagnostics;
- turn off automatic discovery while retaining manual discovery. Automatic discovery is on by default, operates only while X is foreground, and opens a short-lived background search tab when more recommendations are needed. Search-tab results are not recorded as the user's browsing, exposure or preference signals.
Cloudflare Worker invocation logs are retained according to the active Cloudflare plan and never for more than seven days. The current Auth0 plan retains authentication security logs for one day. Ownfeed does not export either log stream to another analytics provider. These operational records are used only for security and failure diagnosis.
Security
Personal or sensitive data is transmitted over HTTPS. Authentication uses Authorization Code with PKCE; the extension has no client secret. Public API requests require a verified, expiring OIDC token and are isolated by an opaque per-user Durable Object key.
Contact
Privacy and data requests: privacy@ownfeed.ai
Limited Use
Ownfeed's use and transfer of information received from browser permissions adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Such data is used only to provide or improve Ownfeed's single user-facing purpose and is not transferred for advertising, creditworthiness or unrelated purposes.