Last updated: September 2, 2026
PostPilot is a Chrome extension, and now an Android app, that scores your X/Twitter posts in real time. This policy explains what data each app accesses, what it stores, and what it sends over the network. The Chrome extension is covered first; the Android app has its own section below, since it works differently.
PostPilot reads the following from the X.com page you are viewing:
All data is stored locally on your device using chrome.storage.local. This includes:
None of this data is transmitted to PostPilot or any third party, except as described below.
PostPilot Pro sends your license key and instance ID to LemonSqueezy solely to verify that your license is valid. No post content, engagement data, or personal information is included in these requests. LemonSqueezy's privacy policy applies to that interaction.
PostPilot operates one minimal server, used only to generate AI Rewrite suggestions. When you request a rewrite, the following is sent to that server, which forwards the request to Anthropic and returns the result: the text of the post you're rewriting, either an anonymous device identifier (Free) or your license key (Pro), and — for Pro users who've built a Voice Match profile — a compact summary of your writing style (typical sentence length, common vocabulary, and similar signals; never the raw text of your past posts). This server also tracks how many rewrites each device or license has requested that day, solely to enforce daily usage limits — it does not log or retain post content or voice-style data beyond what's needed to generate the response. Scoring, analytics, and voice-profile storage all remain entirely on your device; only an explicit rewrite request reaches this server.
Outside of LemonSqueezy license validation and the AI Rewrite server above, PostPilot does not transmit data to any other third party.
PostPilot requests the following Chrome permissions:
All locally stored data can be cleared at any time by removing the PostPilot extension from Chrome (chrome://extensions). Uninstalling the extension permanently deletes all stored data from your device.
PostPilot Mobile is a standalone Android app: a composer with the same live 0–100 scoring engine as the Chrome extension, plus a draft queue, a hook library, and Voice Match. It is not a browser extension and does not connect to your X account — there is no login, and it never posts on your behalf. When you're ready to post, it hands your text to the official X app or x.com and stops there.
Only the text you type into the app's own compose box. PostPilot Mobile has no access to X, your X account, or any other app's data. If you use Android's share feature to send text into PostPilot from another app, that shared text is the only thing it receives.
All data is stored locally on your device using an on-device key-value store (MMKV), the mobile equivalent of the Chrome extension's chrome.storage.local. This includes your drafts, saved hooks, score history, and Voice Match profile (built from posts you paste in, or optionally import from an X Analytics CSV export). None of it is bundled into a backup or account — it lives only in this app's own storage on this device.
Nothing. PostPilot Mobile makes no network requests at all — no server, no analytics, no crash reporting, no ads. Every feature (scoring, drafts, hooks, Voice Match, CSV-based insights) runs entirely on your device. This is narrower than the Chrome extension, which does call PostPilot's own AI Rewrite server and LemonSqueezy for Pro license checks (see above) — the Android app does not yet have either of those features, and this policy will be updated before it does.
PostPilot Mobile does not request access to your contacts, location, camera, microphone, or files, and does not require an account. The only Android-level integration is the share sheet (so you can send text into the app from other apps to be scored), which is a standard Android intent, not a permission grant.
Uninstalling PostPilot Mobile permanently deletes all data it stored, since nothing is kept anywhere else.
PostPilot is not directed at children under 13 and does not knowingly collect data from minors.
If this policy changes materially, the "Last updated" date above will be revised. Continued use of either app after an update constitutes acceptance of the revised policy.
Questions about this policy can be sent to brianemcgrath@gmail.com.