Xnnoying
Privacy Policy
Last updated: Oct. 2, 2026
Xnnoying (“the Extension”) is a Chrome extension that adds quick block and mute buttons directly on posts on x.com and twitter.com, and keeps a history of your Home feed. This privacy policy describes what data the Extension accesses, how it is used and how it is protected.
What Data the Extension Accesses
The Extension accesses the following data while you use x.com or twitter.com:
- Authentication cookie: The Extension reads your existing session cookie (ct0 CSRF token) from the browser to authenticate block and mute requests with 𝕏’s API on your behalf.
- Website content: The Extension reads usernames (screen names) from the posts displayed on the page to identify which account to block or mute when you click a button.
- Home history: On your Home timeline, the Extension records the ID, author and a short text snippet of posts you scroll past, plus the furthest post you reached, so you can find your place again after 𝕏 reloads the feed.
- Home feed data: To restore a feed 𝕏 replaced, the Extension keeps a copy of the Home feed data 𝕏’s own servers send to your browser.
How the Data Is Used
Accessed data is used only to perform the block or mute action you initiate and to keep and restore your Home history. Specifically:
- Your CSRF token is included in the request headers sent to 𝕏’s own API endpoints (blocks/create and mutes/users/create) so the action is performed under your authenticated session.
- The screen name is included in the request body sent to those same 𝕏 API endpoints.
Data for block and mute is used transiently at the moment you click a button and is not stored.
Home history is stored only in your browser’s local extension storage (chrome.storage.local) on this device. It is limited to the 10 most recent feeds of up to 300 posts each, older entries are discarded automatically, and it is removed when you uninstall the Extension. It is never sent anywhere.
Home feed data is held only in the tab’s memory (the last 5 feeds, about 40 MB at most) and is discarded when the tab is closed or reloaded. When you choose to restore a feed, that feed is placed in the tab’s session storage just long enough to reload the page and hand it back to 𝕏, then removed. It is never sent anywhere.
Data Sharing and Transfer
The Extension does not transmit any data to the developer or to any third-party server. All network requests are sent exclusively to 𝕏’s own API on the same domain you are already browsing (x.com). No data is sold, shared or transferred to any third party.
Data Security
All requests to 𝕏’s API are made over HTTPS. Apart from Home history in local extension storage, and a restored feed held briefly in the tab’s session storage during a restore, the Extension does not store any user data locally or remotely.
Permissions
The Extension requires host access to x.com and twitter.com, and the storage permission to keep Home history on your device. It uses no other browser permissions and has no background scripts, analytics or tracking of any kind.
Limited Use Disclosure
The Extension’s use of data received from 𝕏 complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. The Extension only uses data to provide its blocking, muting and Home history features and does not use or transfer data for advertising, creditworthiness or any unrelated purpose.
Changes to This Policy
If this policy is updated, the revised version will be posted at this page with an updated date.
Contact
If you have questions about this privacy policy, you can reach the developer through the Extension’s support page on the Chrome Web Store.