← Follow Curator

Last updated September 8, 2026

Privacy policy

Follow Curator is made and operated by Sage (@kurorosage). This policy covers the Follow Curator Chrome extension and followcurator.com.

Data used on your device

When you scan X, the extension reads the signed-in account identity and your Following list. It stores profile handles and IDs, names, biographies, avatar URLs, following relationships, public counts, observed checkmark status, and available last-post information in local browser storage. Scan progress, Keep/Later/Unfollow choices, and execution history are also stored locally so you can resume your work.

This account-level library is not uploaded to Follow Curator’s servers or sold. Opening profiles, loading profile pictures, scanning, and applying your approved choices make requests to X and its media services. Those services receive the requests needed to perform these actions and handle them under their own policies.

Your X session

Follow Curator does not ask for or store your X password. The integration uses authorization and CSRF information from your existing signed-in X session inside the X page to make requests you initiate. This session information is held temporarily in memory; it is not included in analytics, exports, or the saved library and is not sent to Follow Curator’s servers.

Waitlist and access updates

If you join the website waitlist, we save the email address and optional X handle you provide, when you joined, your agreement to receive access updates, and your invitation status on our servers. These details are used to manage invitations and send the access and launch updates you request. They are separate from your extension library and are not included in analytics or a public member list.

Joining does not connect a Google or X account, give us access to your inbox, or verify that an email address or handle belongs to you. We retain your request while managing the waitlist and invitations, or until you ask Sage to remove it. You can request removal through @kurorosage on X ↗.

To limit spam, the signup endpoint uses a short-lived, secret-keyed hash of the connection’s IP address and an hourly time window. The waitlist rate-limit table does not store raw IP addresses; expired entries are removed as new signup requests arrive.

Optional usage analytics

Extension analytics are on by default. They use a random installation ID and report the extension version, screens and features used, coarse count ranges, decision categories such as Keep or Later, settings, and success or failure states. They do not include X handles or IDs, profile content, follow lists, the identities of accounts acted on, search text, session credentials, or browsing history outside the extension’s workflow.

You can turn off Optional usage analytics in the extension popup. Do Not Track suppresses normal analytics events. Explicitly switching analytics back on sends a preference event. Turning analytics off stops future events; it does not erase events already received.

The website records page views and interactions, a random browser identifier, campaign parameters, and the referring domain to understand how the product is used. The website’s analytics control and Do Not Track can disable these events. Do not put personal or sensitive information in campaign parameters.

The optional community indicator reports the number of distinct installations with recent product activity. It does not identify users or show who is online on X.

Service providers and retention

The website and analytics endpoint run on OpenAI Sites and Cloudflare infrastructure. These providers process requests to operate the service and may handle ordinary connection information such as IP addresses in their infrastructure logs. The application’s analytics records do not add IP addresses to event data. PostHog is not enabled in the current production configuration. This policy will be updated before an additional analytics provider receives data.

Local library data stays until you clear it or remove the extension. The website’s event database removes records older than 90 days as new events are recorded. Hosting logs are subject to the providers’ retention settings and may have different retention periods. Contact Sage with questions or data requests; identifying a random browser or installation record may require its identifier.

Your controls

Use Data & privacy in Review to export your library as readable JSON or clear local data. Exports may contain your profile and Following information; keep them somewhere private. Importing an export to restore your library is not currently supported. Disabling or hiding the helper does not delete your library. Uninstalling the extension removes its local extension data.

Purpose and sharing

Data is used to provide the scan, review, and approved unfollow workflow, troubleshoot reliability, and understand aggregate product use. It is not sold or used for personalized advertising. Access by service providers is limited to operating these services. We may disclose information when legally required.

Changes and contact

Material changes to data handling will be reflected here and, where necessary, in the extension before new uses begin. For support or privacy requests, contact Sage · @kurorosage ↗.