Privacy Policy
अंतिम अद्यतन: September 11, 2026
यह दस्तावेज़ केवल अंग्रेज़ी में प्रकाशित है; अंग्रेज़ी संस्करण ही मान्य है।
PostGuard (“we”, “us”) is a product of Xeviora, a brand operated by LIU HU, a sole proprietor, who is the controller of the personal data described in this policy. Contact: privacy@xeviora.com
This policy explains what data the PostGuard browser extension and the PostGuard website (postguard.xeviora.com) collect, and why. The core principle is simple: the posts, comments and communities you read stay on your device, every AI feature is strictly opt-in, and the only thing that ever leaves your browser about your posting without you pressing a button is an anonymous outcome statistic you can switch off.
1. What stays on your device
The extension reads the community rules, your own account data, and the drafts you are writing — all from the session you are already signed into — and keeps them in your browser’s local storage (IndexedDB and chrome.storage). Your post history, the visibility checks we run for you, and the rule summaries we cache are stored there and are never uploaded to us. You can export or delete them at any time from the extension.
Visibility checks are requests your browser makes directly to the site being checked, without your cookies attached (that is what makes them a “signed-out view”). We do not proxy, log, or see those requests.
2. Anonymous outcome statistics (on by default, one click to turn off)
To build the community-measured thresholds the extension shows you, we collect a small statistical event after a post of yours is checked. Each event contains exactly seven fields: the community name, whether it was a post or a comment, the outcome (visible / removed / not public), a coarse account-age bucket (for example “31-90 days”), a coarse karma bucket (for example “1k-10k”), whether the post contained an outside link, and the UTC hour it was published.
It contains no account name, no post identifier, no title, no body text and no links. Nothing in it can be traced back to you or to a specific post. We keep a truncated, daily-salted hash of your IP address purely to rate-limit submissions; it cannot be linked across days and is not used for anything else. You can turn this off in the extension’s side panel (Settings) at any time, and the extension keeps working.
3. AI features (opt-in)
PostGuard has two AI features, and each one only runs when you explicitly press its button. What is sent depends on which one you use:
- Reply drafts. The post title, a truncated excerpt of the post body, up to six truncated comments from the thread, and the short note you typed about what you want to say.
- AI rule review. The title and body of the post you are writing, the domains of any links in it, its flair, the community’s published rules, and coarse account context: an account-age bucket (for example “31-90 days”), a karma bucket (for example “1k-10k”), and how many of your submissions to that community in the last 30 days were self-promotional or removed, as small counts. Your username is not sent.
Our backend forwards this to our AI inference provider (OpenRouter) and returns the result to the extension. We do not use your content to train models, and we do not store or log it; it exists only for the duration of the request.
If you supply your own OpenRouter API key, it is encrypted at rest with AES-256-GCM and is only ever decrypted server-side to make your own requests. It is never sent to the extension or exposed in the browser; the interface only shows its last four characters.
4. Account data
You do not need an account for the pre-flight checks, the account health panel, or a manual visibility check. An account is only required for the AI features, Pro monitoring, and billing. If you sign up, we store your email, name (if provided), and authentication records via our own independent authentication system. Session cookies are host-only to postguard.xeviora.com and are not shared with other Xeviora sites.
If you sign in with Google or GitHub, we receive only the basic profile information needed to create your account (email and name).
5. Credits and payments
AI usage is metered in credits. We keep an append-only ledger of credit grants and usage tied to your account.
Payments are processed by our reseller and Merchant of Record, Paddle.com (“Paddle”). Paddle collects and processes your payment and billing information (such as name, email, billing address, country and payment details) as an independent data controller, in order to process your order, calculate taxes, prevent fraud and meet its legal obligations. We never receive or store your full card details. We receive limited order information from Paddle (such as your email, country, plan and transaction status) to provide the service. See Paddle’s Privacy Notice, and our Refund Policy for how refunds work.
6. Your account on the site we support
PostGuard does not ask for your password on the site it supports and does not use its login APIs or its developer API. It works alongside the session already in your browser, reads the same data that session is served, and never posts, votes, comments, follows, messages, or deletes anything on your behalf, and it does not type into the page for you. AI drafts are shown in the extension with a copy button; you paste, edit and press the button yourself. PostGuard is an independent tool and is not affiliated with, endorsed by, or sponsored by the company that operates the site it supports.
7. What we do not do
- We do not sell your data.
- We do not track your browsing across the web.
- We do not use analytics or advertising trackers inside the extension.
- We do not store the posts, comments or communities you read.
- We do not act on your behalf on any third-party site.
8. Data retention & deletion
Local data lives only in your browser; uninstalling the extension or clearing its storage removes it. Anonymous outcome statistics cannot be deleted individually because they are not linked to you — you can stop contributing them at any time. To delete your account and associated AI/billing records, contact us at the address below and we will remove them, subject to legal and accounting retention requirements.
9. Contact
Questions about this policy? Email privacy@xeviora.com.