privacy policy · effective 2026-06-10
Privacy, in plain words.
What the extension does
penn AI is a human-in-the-loop reply assistant for X (x.com). It only acts when you click Suggest replies (or press the shortcut). It never auto-posts, never likes, follows, or messages anyone, and never reads pages other than the X tab you are using.
What stays on your device
Your profile (who you are, your products, your writing voice, forbidden phrases, anti-examples, product photos) is stored in Chrome's local extension storage on your computer. We do not keep a copy on our servers.
What is sent to our server, and when
Only when you explicitly request a generation, the extension sends to our API (hosted on Railway): the visible text of the post or thread you're replying to, image URLs attached to that post, your profile fields, your optional note, and, when composing a post with feed grounding on, the visible text of posts in your home feed. Our server forwards this to OpenAI to produce drafts and returns them. We do not store the content of these requests. Server logs contain your account id, route, status code, and timing only, never thread or profile text.
Account data we store
When you sign in with Google we store your name, email address, and avatar URL, plus session records. For billing we store your plan, subscription status, and a daily generation counter. Payments are processed by Polar (polar.sh) as merchant of record; we never see card numbers.
Third parties
OpenAI processes generation requests (per their API data policy, API data is not used to train models). Polar processes payments and invoices. Google provides sign-in. Railway hosts the server and database. There are no ads, no analytics trackers, and we never sell or share data.
Retention and deletion
Usage counters expire naturally. Delete the extension and your local profile is gone. Email [email protected] from your account email to delete your account and billing records; we complete deletion within 30 days.
Chrome Web Store disclosures
The extension requests: storage (save your profile locally), clipboardWrite (copy a draft when you click Copy), tabs (open settings and route the keyboard shortcut to the active X tab), and host access to x.com / twitter.com (show the panel beside the composer) and our API domain (generate drafts for your account).
Contact
Questions: [email protected]