X Spam Cleaner logo
Product-specific privacy policy ReForge Extensions

X Spam Cleaner Privacy

This policy explains what X Spam Cleaner reads on X and Twitter, what stays inside Chrome, what limited operational information can be sent to ReForge services and how you control the extension

Effective July 25, 2026 Updated July 25, 2026 Item ID bcblicnglpkamhpgbjllmhpgkeeojedb [email protected]
Visible X content is evaluated locally

The extension checks supported post and account-list interface elements in the current X or Twitter page to decide whether a local filter rule matches

Posts and private lists are not sent to ReForge

Post text, direct messages, search terms, account handles, allowlists and muted-word contents are not included in configuration requests or operational events

Remote access is narrow and documented

ReForge endpoints provide product configuration and remote rule JSON, while Aliyun Log receives privacy-minimized lifecycle and explicit user-action events

1. Scope and controller

This policy applies specifically to the Chrome extension X Spam Cleaner, Chrome Web Store Item ID bcblicnglpkamhpgbjllmhpgkeeojedb, operated by ReForge Extensions

X Spam Cleaner adds reversible filtering and user-triggered block helpers to x.com and twitter.com. It is not operated by, endorsed by or affiliated with X Corp

Visible page interface
Local rule evaluation
Collapse, dim or hide
User restore or native X confirmation

2. Page data processed on your device

On supported X and Twitter pages, the content script can read only the currently rendered interface elements needed for filtering and controls

Local processing boundary: this page data is used in memory for filtering, restoring, search enhancement and native X controls. The extension does not save post text as history and does not send post text, search queries, account handles or list contents to ReForge or Aliyun Log

Information the extension does not intentionally access

X Spam Cleaner does not request Chrome permissions for cookies, browsing history, downloads, clipboard access, webRequest interception or all websites. It does not intentionally read direct-message content, passwords, payment details or form entries

3. Chrome permissions

Permission Why it is needed Data boundary
storage Save settings, local statistics, SDK state and the last validated remote-rule cache Post text and browsing history are not stored
alarms Refresh versioned remote rule JSON about every six hours under the Manifest V3 lifecycle The alarm only schedules the refresh and does not read page content
tabs Identify the active supported tab, send user-requested pause or resume commands and open extension pages Tab URLs are not retained as browsing history or added to telemetry
https://x.com/* Run local filtering, reversible placeholders, account allow controls and native block helpers on X Limited to the supported X domain
https://twitter.com/* Provide the same behavior on legacy Twitter URLs Limited to the supported legacy domain
https://api.reforgeextensions.com/* Retrieve product configuration, announcements and validated remote rules through the bundled SDK Requests do not include post text, handles, search terms, allowlists or muted words
https://reforgeextensions.cn-hangzhou.log.aliyuncs.com/* Send limited lifecycle and explicit user-action events Automatic page scans and automatic filter matches are not tracked

The packaged logo file is exposed only to x.com and twitter.com as a web-accessible resource so branded placeholders, overlays, success messages and the review prompt can display it

4. Browser storage and settings files

Chrome Sync storage

Language, global and per-tab behavior, filter sensitivity, filter action, your own account handles, allowlist, muted words, search options, disabled paths, overlay preferences and block-helper settings are saved with chrome.storage.sync. Chrome controls synchronization through your signed-in browser profile

Chrome local storage

Local storage contains aggregate processing and block counts, up to 35 days of daily totals, filter-reason counts, the installed timestamp, the last rule version, validated remote rules, the rule refresh timestamp, update-page state and SDK state such as a stable installation UUID and review-prompt state

Import and export

Settings export creates a JSON file locally in the browser. Settings import reads the JSON file you select and writes validated settings back to Chrome storage. The file is not uploaded by X Spam Cleaner

You can reset settings in the extension, remove individual list entries, clear extension storage through Chrome or uninstall the extension. Chrome may manage synced copies according to your browser-account settings

5. Network services and transmitted information

ReForge API and product SDK

X Spam Cleaner contacts api.reforgeextensions.com for product configuration, announcements and versioned remote-rule JSON. The rule response can include spam terms, duplicate-detection thresholds and community account rules. A validated last-known-good copy is cached locally

The bundled SDK can also support account and subscription operations if those product options are enabled. If you later use an enabled login, checkout or account-management function, the information you submit for that action, such as email and authentication data, is processed by the ReForge API and the relevant payment provider

Aliyun Log operational events

When operational logging is enabled, the SDK can send installation and update events and events for important user actions such as changing settings, switching language, pausing filtering, refreshing rules, restoring a post, adding an account to the allowlist, importing or exporting settings and completing or failing a block action

Each event can include:

Automatic page scanning, automatic filtering and automatic hidden-count increments do not create user-action telemetry. Operational events do not include post text, search terms, target handles, allowlist contents or muted-word contents

6. Sharing, retention and security

ReForge uses service providers only where needed to operate the extension, deliver configuration, process enabled account or payment actions, protect infrastructure, receive operational logs and handle support. These providers process information on ReForge’s behalf or under their own applicable service terms

Local browser data remains until you change or clear it, Chrome removes it or the applicable Chrome storage lifecycle ends. Daily local statistics are limited by the extension to a rolling 35-day detail window while aggregate totals can remain longer. Remote operational and account records are retained only as needed for service operation, security, fraud prevention, support and legal compliance under the applicable provider policies

Network requests use HTTPS. The extension applies input validation to imported settings and downloaded rule JSON, keeps the last known good rules when the service is unavailable and requests only the permissions listed above

ReForge does not sell or rent personal information and does not provide X content or extension telemetry to data brokers

7. Chrome Web Store Limited Use

X Spam Cleaner’s use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements

8. Your choices and controls

To ask about access, correction or deletion of information held by ReForge services, email [email protected]. We may need to verify the request before acting on account-linked or installation-linked records

9. Children, changes and contact

X Spam Cleaner is a general browser productivity tool and is not directed to children under 13. ReForge does not knowingly collect personal information from children through this extension

This policy may be updated when extension permissions, data flows, service providers or legal requirements change. The effective and updated dates at the top of this page identify the current version

Questions about this policy can be sent to [email protected]