Privacy

When you choose a website language, an essential first-party cookie named mp_lang stores only that language preference for up to one year. It is not used for tracking. Choosing browser language removes it.

Discontinued community rankings

The community ranking feature has been discontinued. No new contributions are accepted or displayed. Any previously submitted contributions expire within 90 days under the scheduled cleanup. You may contact support for earlier deletion; database backup retention still applies.

Updated 2026-09-20

X Media Pocket Privacy Policy
Publisher: twitter_x_media_download
Effective date: 2026-09-20
Privacy and support contact: nafk259@gmail.com

Purpose
X Media Pocket helps users collect, select and download available photos and videos from supported X pages. It is independent of X Corp.

Extension data
The extension processes post text, author usernames, post identifiers, media previews and URLs, and the supported X page or search context. Relevant network responses are observed for media lookup and pagination. Current X request headers are temporarily reused in the X page context for authenticated same-origin requests. X credentials, post content and downloaded files are not sent to our billing server. The extension does not collect unrelated browsing history, keystrokes or X direct messages.

Local storage
Preferences, saved-item records, download jobs, usage counters and a private subscription recovery key are stored in Chrome extension storage. Jobs can contain post text and media URLs. Completed files are saved through Chrome to the user's download folder. Removing the extension does not remove downloaded files or Chrome download history. Local data is not separately encrypted by this extension. Keep the recovery key private: possession of it permits subscription recovery and management.

Subscriptions
When using paid subscriptions, the billing server stores a hash of the installation credential and associated Paddle customer, checkout, transaction and subscription identifiers, verified paid-period end dates and refund/revocation records. Paddle processes payments on its hosted checkout and customer portal. Our extension and server do not receive raw payment card numbers. Paddle and hosting providers process data under their own privacy policies. The server verifies paid subscription access with Paddle. Installation and billing mappings are retained while needed to provide or manage the service and handle support; they have no automatic expiry. Contact us for deletion requests. Cancellation and deletion are separate: cancel recurring billing in the Paddle customer portal. Financial records may need to be retained as legally required.

Operational logs
Our application logs record UTC time, a predefined route category, HTTP status and duration. They do not store IP addresses, query strings, authorization headers, media content or payment request bodies. Logs are limited to 14 days and 10,000 entries, whichever limit is reached first. Connection addresses and installation identifiers are used temporarily in memory to limit requests. The website runs on Cloudflare Workers. Application observability uploads are disabled; Cloudflare may process connection information and platform diagnostics to operate and secure its network.

Retention and backups
Processed Paddle webhook identifiers are normally removed after 30 days by webhook processing or a daily scheduled cleanup. Log cleanup also runs daily and when log entries are recorded. Cleanup may be delayed by platform outages or exhausted service limits. We retain the latest 20 published policy revisions. The cloud database provider offers point-in-time recovery for up to 30 days. Deleted records may remain in that recovery history. Application logs store errors and billing or policy-change events, rather than every successful page visit. Cloudflare processes network requests to operate and secure this service. Deleted data may remain in backups until those backups expire. No automatic deletion of installation or subscription records is currently provided.

Use and sharing
Information is used to provide media downloads, manage subscriptions, prevent abuse and respond to support requests. We do not sell user data, use it for advertising targeting, creditworthiness or lending, or transfer it for purposes unrelated to this service. X receives requests needed to provide its content. Payment and hosting providers receive information necessary to provide their services. X Media Pocket's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including Limited Use requirements.

Your choices
You can stop collection, remove locally stored extension data, uninstall the extension, cancel your subscription through Paddle, and contact the publisher about access or deletion. Do not include X passwords, recovery keys or payment card details in support messages.



Support requests
If you email nafk259@gmail.com, your email address and the contents of your message are received through Gmail and used to respond to your request. Provide only information needed for your question. Support correspondence is retained while needed to resolve requests and related disputes; no automatic deletion period is currently configured. You may request deletion by contacting the same address, subject to any records that must be retained. Gmail processes correspondence under Google's privacy policy.

Google account and saved preferences

When you choose Google sign-in, we receive your verified email address and Google account identifier to create and authenticate your Media Pocket account. We do not receive your Google password. Google access tokens are used temporarily to retrieve this basic account information; we do not store Google access or refresh tokens.

We store your account identifier, email, file naming preferences, download subfolder preference and links to your extension installation credentials and subscriptions in our Cloudflare database. These records have no automatic expiry. Contact the support address on this page for access or deletion requests. Cancelling billing is separate from deleting an account.

An essential secure, HttpOnly session cookie lasts up to seven days. Login state and extension pairing records expire after ten minutes and are cleaned up on subsequent requests or daily scheduled maintenance. Log out to invalidate the current session. Downloaded files, saved post contents and media previews remain in your Chrome installation and are not uploaded to the membership server.

Local post archives retain up to 1,000 posts within a four-megabyte storage budget; older records may be removed when this limit is reached. Export important posts before uninstalling or clearing extension data.

Contact: nafk259@gmail.com