XSaved Privacy Policy
Draft for legal review · July 24, 2026
What this policy covers
This policy explains how XSaved ("XSaved", "we", "us") handles information when you use the XSaved iOS app, browser extension, website, optional cloud account and sync, and paid features. XSaved helps you import, search, and organize bookmarks from X.
XSaved is not affiliated with X Corp. Your use of X remains subject to X's own terms and privacy policy. XSaved does not make your private bookmark library public.
Information we handle
The information involved depends on the features you choose to use:
- Account information: identifiers supplied by your sign-in provider and, where available, your name, email address, handle, profile image, and X verification status.
- Bookmark-library information: saved-post text, authors, links, media URLs and metadata, post and save dates, engagement metadata, folder membership, and whether X marks content as potentially sensitive.
- Content you add: folders, tags, private notes, and search queries submitted to cloud search.
- Purchase information: product, transaction, entitlement, renewal, and subscription status. Apple or Stripe processes payment details; XSaved does not receive your complete payment-card number.
- Technical information: app or extension version, device and operating-system type, locale, request timestamps, error information, and network information such as IP address that is necessarily received when a device contacts the website or cloud service.
- Messages you send: your name, email address, feedback, support messages, and beta-waitlist submission when you choose to provide them.
What stays on your device
XSaved keeps a local copy of your library on your device. The iOS app's local search index, image text recognition, image classification, supported video transcription, semantic embeddings, automatic topic organization, and collection summaries use Apple frameworks on the device. Content processed only by these local features is not sent to XSaved or an external AI provider for that processing.
Your X website session cookies are stored in an app-isolated WebKit data store on your device. Authentication credentials issued by XSaved are stored using protected device storage. XSaved never asks for or stores your X password.
Optional cloud sync and cloud AI
In the iOS app, cloud sync and cloud AI are off unless you choose to connect an XSaved cloud account and turn them on. Before the iOS app sends your library for cloud processing, it shows the current processors, their purposes, and the categories of data each receives, then asks for your explicit permission. If you choose not to agree, sync stays off and the app's local library, search, and organization features keep working.
When enabled, XSaved sends your account information, bookmark library, folders, tags, and notes to XSaved's backend so your library can stay consistent across supported devices. Cloudflare Workers AI receives relevant bookmark text, author information, tags, notes, folder names, and generated topic names to create text embeddings used for semantic search and automatic organization. Anthropic receives relevant bookmark text, author information, tags, and folder names to generate cloud AI tags and topic names. XSaved stores resulting vectors, topics, and assignments with your cloud library.
Permission is tied to the disclosed processor set. If that set changes, the iOS app requires you to review and accept the updated disclosure before sync can resume. You can withdraw permission in Settings by turning Sync across devices off. That stops new sync and cloud AI transfers immediately and asks the backend to revoke the saved permission. If the device is temporarily offline, XSaved keeps sync disabled and retries the revocation before sync can be enabled again.
Turning sync off does not delete data already stored in your cloud account or copies already processed by a provider. Use Delete account in the iOS app to delete the cloud account and its associated active cloud data. Cloud services are used to provide search, organization, and sync—not to build an XSaved advertising profile. On-device and cloud processing are distinct.
The browser extension can synchronize a cloud library separately. When a supported client sends sync data without a current cloud AI permission on the account, XSaved can store that sync data but does not start cloud AI indexing or organization work for it.
Potentially sensitive content
X may label a saved post as potentially sensitive. The iOS app uses that label to exclude the post from its visible library, search results, and on-device search or organization indexes. If an older local cache does not contain a reliable sensitivity label, the app keeps that cache out of view until it can rebuild the library from a source that supplies the label.
Because this policy also covers the browser extension and optional cloud service, XSaved may still handle the sensitivity label and an associated bookmark record when another supported client sends it. Deleting your XSaved cloud account removes those account-owned records from XSaved's active systems, subject to the retention limits described below.
Sign-in and access to X
The iOS app uses an embedded X website session to retrieve the bookmark data you ask it to import. X receives the information you enter on its pages under X's privacy policy. XSaved can read the resulting session cookies on your device to make the X requests needed for bookmark and folder features, but does not receive the password you enter on X's sign-in page.
When you create or connect an XSaved cloud account, the sign-in provider supplies XSaved with the profile information described above. A provider access token may be used during sign-in to retrieve that profile; XSaved does not persist the X OAuth access token after the sign-in exchange completes.
Purchases
Apple processes purchases made in the iOS app. RevenueCat receives an app-user identifier that starts as a random anonymous identifier, purchase history, receipt and entitlement information, device and operating-system type, locale, and transaction-related timestamps to validate purchases, restore purchases, unlock Pro features, prevent fraud, and provide subscription analytics. If you connect a cloud account, XSaved links the RevenueCat customer to the pseudonymous XSaved account identifier so an entitlement can work across supported devices.
Stripe processes purchases made through XSaved's web or extension experience. Stripe may receive your name, email address, XSaved account identifier, billing details, and purchase information. XSaved stores Stripe's customer and subscription identifiers and your entitlement status, not your full card details.
Website, feedback, and beta waitlist
You can browse the marketing website without creating an account. Hosting and security providers necessarily receive ordinary request information, including IP address, browser type, requested page, and request time. XSaved does not currently use third-party advertising trackers on the website.
The feedback form and iOS beta waitlist are submitted to Google Forms. Google receives the name, email address, category, and message you choose to submit. The beta waitlist asks for an email address and uses it only for beta-access communication unless you separately consent to something else.
How we use information
- Import, display, organize, search, and synchronize your library.
- Authenticate accounts and keep each account's library separate.
- Validate purchases, prevent fraud, and unlock paid features.
- Answer support requests and send beta access you requested.
- Maintain security, prevent abuse, diagnose errors, and improve reliability.
- Comply with legal obligations and enforce applicable terms.
Service providers and sharing
XSaved shares information only as needed to provide the features you use, operate securely, process purchases, comply with law, or protect rights and safety. The principal providers currently involved are:
- X for sign-in and access to the X content and folders you request.
- Apple for App Store distribution, purchases, and device frameworks.
- RevenueCat for iOS purchase validation and subscription management.
- Stripe for web purchase and subscription processing.
- Cloudflare for website and API hosting, security, workflows, and cloud embeddings.
- Neon for storage of optional cloud-account and library data.
- Anthropic for cloud topic-taxonomy generation and classification.
- Google Forms for feedback and beta-waitlist submissions.
These providers process information under their own privacy terms and our service arrangements. They may process information in countries other than yours, including the United States. We require service providers acting on our behalf to protect information consistently with their obligations and applicable law.
No sale or advertising tracking
XSaved does not sell your personal information, use your bookmark content for third-party advertising, or track you across other companies' apps and websites for advertising. XSaved does not request Apple's advertising identifier.
Retention, deletion, and your choices
Local data remains on your device until you use the relevant in-app removal control or uninstall the app, subject to copies in device backups that you control. Disconnecting X removes that local X connection and its device data. Deleting an XSaved cloud account clears the app's cloud credential and cached cloud-account data, but deliberately leaves the separate X connection in place. Neither action deletes content from X.
Cloud-account information, synchronized library data, consent records, and derived search or organization data are retained while the account is active. Feedback and waitlist submissions are kept until they are no longer needed for the request or communication, or until you ask us to delete them. Short-lived sign-in challenges and one-use security codes expire automatically. Security and diagnostic records are kept only as long as reasonably needed to operate and protect the service.
If you have an XSaved cloud account, you can delete it directly in the iOS app under Settings. After you confirm, XSaved deletes the cloud account and its account-owned bookmarks, folders, notes, tags, AI consent, derived cloud indexes and organization data, devices, identities, passkeys, and sessions from active systems. The app then clears its local cloud credential and cached cloud-account data. Deleting the cloud account does not delete anything from X, disconnect the separate X website session on that device, or cancel an App Store subscription.
You can also request access, correction, export, or deletion of information held by XSaved by emailing the address below. Limited copies may remain temporarily in protected backups until their normal rotation, and information may be retained where required for legal, fraud-prevention, security, accounting, or dispute-resolution obligations. Apple, RevenueCat, Stripe, X, Google, and other providers may retain information under their own policies or legal obligations.
You can turn cloud sync off to stop new sync activity, disconnect an X account to remove its data from a device, revoke XSaved's access through X, or uninstall the app or extension. Where available, export tools let you keep a portable copy of your library.
Children
XSaved is not directed to children under 13. Because the service works with an X account, users must also meet the minimum age required by X and the laws of their country or region.
Security and policy changes
XSaved uses reasonable technical and organizational safeguards, including encrypted network connections, protected device storage, account-scoped access controls, and restricted service credentials. No system can guarantee absolute security.
We may update this policy as XSaved changes. If a change is material, we will provide notice appropriate to the change. The latest version and its effective date will always appear on this page.
Contact
For privacy questions or data requests, email us.
support@xsaved.app