Privacy Policy

How we collect, use, and protect your personal information.

Last updated: 2026-09-12

Introduction

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.

Information We Collect

We collect the following types of information to provide and improve our service:

  1. Account Information — Your name, email address, and other details you provide when creating an account.
  2. Usage Data — Information about how you interact with the service, including features accessed, frequency of use, and interaction patterns.
  3. Device Information — Device type, operating system, and browser type, used to optimize compatibility and performance.
  4. Cookies — Small data files stored on your device to remember preferences and improve your experience.
  5. Payment Information — Billing details handled by trusted third-party payment processors. We do not store full card numbers on our servers.

Extension Data and Authorized Features

The extension collects public-page content from Xiaohongshu or Douyin when you trigger collection or authorize a paired local Agent to collect it. This can include titles, text, media links, account profiles, engagement counts, search results, and comments. The data pool is stored in your browser by default. Sync, AI, extraction, and Agent tasks process or transmit only the inputs needed for the feature you request. The extension does not call chrome.cookies or provide platform login credentials to an Agent.

The extension stores the authorization credential and verification state locally for subsequent requests; unbinding in the extension or browser extension-data clearing removes the local credential. Saved Lark sync-target configuration and sync execution logs are retained by the backend to support later syncs, status queries, and troubleshooting.

AI Analysis and Content Extraction

When you request account analysis, note breakdown, writing, image text extraction, or video transcription, the MediaClaw backend processes the text, comments, image or audiovisual links, extracted text, and instructions needed for that task. It sends necessary inputs to the applicable AI or content-processing service. Depending on the feature and configuration, these services currently include Coze, Alibaba Cloud, OpenRouter and the model providers it routes to, Moonshot/Kimi, or DeepSeek. The AI workspace retains generated research, topics, drafts, and task state for later use. Clearing browser collection data does not delete these workspace assets.

Local Agent Pairing and Data Use

A local host such as Codex, WorkBuddy, or Doubao Work can call the extension only after you enable Agent access and approve the particular device in the extension. Pairing information, device names, and connection state are stored locally. Authorized interfaces can read the data-pool records, local AI workspace assets, and remote workspace assets accessible to your current membership account that are needed for your task. They can also run public-page collection and content extraction within the scope you authorize. These interfaces do not provide activation codes, platform cookies, access tokens, or similar credentials to the Agent.

Results enter the task context of your chosen host, which may send them to its own model service or retain task records according to that service's settings. An approved Agent communicates with the extension through a loopback address on the same computer; this does not give arbitrary public web pages permission to call the Agent. You can disable Agent access or revoke a particular device in the extension. Revocation stops future calls; it does not delete content already retained by the host, which must be managed in that service.

Comment Filtering and Direct Messages

Comment filtering uses the comment text, public nicknames, profile links, and user identifiers you have collected. When you use the extension directly, you confirm the recipients and message text in the extension. When you use a paired Agent, it first shows the sender account, every actual recipient, and the full message text in the conversation. The Agent may request sending only after you explicitly approve that final plan; you can also revise or cancel it first. Text confirmation in the conversation is relayed to MediaClaw by your chosen Agent. Both entry points use the same extension messaging flow to send through the currently signed-in platform account by operating the page.

Recipients, message text, sender account identifiers, execution state, and send times are stored locally to show progress, prevent duplicate sends, enforce intervals, and handle recovery. The message is transmitted to Xiaohongshu or Douyin and the intended recipient. Stopping a task or clearing local records does not recall a message already sent.

The notification center sends a device identifier, any available authorization credential, extension version, and language to the MediaClaw backend. The backend uses account and membership state, days of use, and aggregate counts of successful operations to select applicable notifications. It sends necessary account context and a hashed account or device identifier to the website notification service. Hashing does not mean that this information can no longer be associated with an account.

The website retains notification IDs, subject identifiers, and timestamps for impressions, reads, dismissals, and action-button clicks to maintain unread state, prevent duplicates, and limit repeated reminders. Store-review invitations record notification interactions; they do not read the rating or review text you submit to the store.

When you request your referral link, the backend verifies that your authorization credential belongs to the website account before requesting that account's invitation code and link. Recipients can see the invitation code when you share the link. Referral relationships, discounts, and commissions are handled by the website referral feature. Notification receipts and website referral records are stored on the server and are not deleted by browser-local cleanup.

How We Use Your Information

We use the data we collect to:

  • Provide, maintain, and improve the service.
  • Process transactions and send related confirmations.
  • Send technical notices, security alerts, and support messages.
  • Respond to your questions, feedback, and support requests.
  • Detect, prevent, and address fraud and abuse.

Data Sharing

We do not sell your personal information. We may share data only in these limited cases:

  • With service providers who help us operate the service, under confidentiality agreements.
  • To comply with legal obligations or respond to lawful requests from public authorities.
  • To protect our rights, property, or safety, or that of our users.

Local Storage, Retention, and Cleanup

The "Clear local collection data" action clears the data pool, collection progress, completed execution records, and related caches. Ongoing tasks may need to finish first. It preserves authorization and settings, AI workspace assets, active tasks, and outreach rate-limit and recipient-history records still within their retention windows. Completed execution history is generally retained for 7 days and outreach send events for a 24-hour window; records required by active tasks are preserved. Periodic history cleanup does not automatically delete the collected data pool.

Local cleanup does not delete exported files, Lark content, website server records, or tasks retained by an Agent host. Browser extension-data clearing or uninstalling the extension can remove its browser-local data. Website, cloud-workspace, and Agent-host data must be managed in the respective service or through a request to us.

Browser Permissions

PermissionPurpose
activeTabRead the Xiaohongshu or Douyin page you actively use
scriptingRun collection and confirmed messaging actions on authorized platform pages
storageStore configuration, collected data, authorization state, and execution history locally
unlimitedStorageSave larger local data pools and task records without failures caused by the browser's default storage quota
alarmsWake confirmed outreach tasks and periodically remove expired execution history
offscreenHandle Blob files needed for batch image exports in an offscreen document
downloadsSave exports or attachments when you request a download
sidePanelDisplay extension controls in the browser sidebar
Platform and media host permissionsCollect from authorized Xiaohongshu or Douyin pages, perform confirmed outreach, and read image assets needed for exports
Website and backend host permissionsAuthorization, sync, AI tasks, notification, and referral requests

Data Security

Connections to cloud APIs use HTTPS and server access controls. An approved Agent connects through the loopback address on the same computer. Authorization information is stored in browser extension local storage; Agent data interfaces do not provide the credential. No method of transmission over the Internet is 100% secure.

Your Rights

You have the right to access, update, export, or delete your personal information. You can do this through your account settings or by contacting us at the email address below.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the date at the top of this page and, where appropriate, sending a notice through the service.

Contact Us

If you have questions about this Privacy Policy, please contact us at the email address provided on our website.