Privacy Policy
Last updated: September 2, 2026
1. What Spy Agent Does
Spy Agent is a Chrome extension that scans reply threads on X (Twitter) to check whether specific usernames have engaged with a tweet. You provide a list of usernames; the extension reads publicly visible replies on the page and tells you who replied and who did not.
2. Data We Do Not Collect
The developer of Spy Agent does not collect any data from users. Specifically, we do not collect:
- Your name, email, or any personally identifiable information
- Your browsing history or the URLs you visit
- The usernames you enter into the extension
- Scan results, found or missing usernames
- Any usage analytics or telemetry
- Your IP address or location
3. Data Stored Locally on Your Device
Spy Agent stores the following data locally on your device only using Chrome's built-in chrome.storage API:
- Usernames you enter into the scan input
- Saved username presets
- Scan history (last 4 scans)
- Extension settings (speed, notification preferences)
- Active session state (for resume functionality)
- Your Access ID (if you use the optional Supabase team feature)
This data never leaves your device unless you explicitly use the optional Upload Results feature described below.
4. Optional Supabase Integration
Spy Agent includes an optional feature for teams using a shared Supabase backend. This feature is completely optional and only activates if you:
- Enter an Access ID in Settings provided by your team administrator
- Manually click "Fetch Task" or "Upload Results"
When these actions are triggered, the extension communicates with your team's own Supabase project — not any server operated by the extension developer. The developer has no access to this data.
5. Permissions Explained
Spy Agent requests the following Chrome permissions, used solely for the extension's core function:
- storage — Save your settings and scan data locally
- tabs — Check if you are on a valid tweet page before scanning
- scripting — Inject the scanner into X pages when triggered
- notifications — Show scan completion alerts (optional, can be disabled)
- alarms — Schedule daily engagement reminder notifications
- contextMenus — Add a right-click "Scan this tweet" option on X
- sidePanel — Open the scanner as a docked side panel
- host access to x.com / twitter.com — Read reply usernames from tweet pages
- host access to *.supabase.co — Optional team feature only, when explicitly triggered
6. Third-Party Services
Spy Agent does not use any third-party analytics, advertising, or tracking services. The extension does not load any external scripts.
7. Children's Privacy
Spy Agent is not directed at children under the age of 13 and does not knowingly collect any information from children.
8. Changes to This Policy
If this privacy policy changes, the updated version will be published at this URL with a new "Last updated" date. Continued use of the extension after changes constitutes acceptance of the updated policy.
9. Contact
For any questions about this privacy policy, contact: yeapifad@gmail.com