隐私说明
更新于 2026 年 10 月 7 日
SuperX 在你的浏览器中运行。你使用自己的 xAI API Key,分析请求直接发送至 xAI;SuperX 没有中转服务器、分析统计或遥测服务。
分析时发送什么
启用分析且 Key 可用时,当前可见的 X 帖子可以触发付费请求。发送的内容包括原帖 URL 和 ID、当前显示的文字及语言标记、作者和时间、媒体信息、最多四个符合条件的 X 图片 URL 和描述,以及已有的引用帖上下文。还会发送你选择的模型、语言、搜索选项及任务指令,包括自定义 prompt。
后台事实求证会附带先前的解读;生成评论会附带已有分析。API Key 仅作为请求身份凭据发送到 api.x.ai。搜索工具可能进一步获取原帖、其他网页或媒体;提供 URL 或缩略图不代表模型已完整阅读或观看该媒体。
分析不限于公开帖子:受保护帖子、回复、喜欢和书签中可见的帖子也可能作为上下文发送。打开不希望发送其内容的页面前,请暂停 SuperX 或清除 Key。私信和独立 Grok 页面不参与分析或历史记录。SuperX 不读取 X 登录 Cookie 或发送 X 会话凭据,也不会发布、点赞、回复或转帖;推荐评论只有你点击后才复制到剪贴板。
保存在本机的数据
- API Key:默认启用“在本机记住 Key”时,用 AES-GCM 加密后保存在扩展本地存储中;随机生成、不可导出的加密密钥单独存放在扩展 IndexedDB。浏览器重启后自动恢复,无需设置密码。关闭记住选项并保存后,仅在浏览器会话中保留 Key。
- 设置:模型、语言、自定义 prompt 和相关偏好在本机保存,不通过浏览器同步。
- 回答缓存:生成文字、评论、来源、模型与 Token 信息保存在浏览器会话缓存中,最多 160 条、约 4 MB;在该会话中最多复用 24 小时。缓存标识也可能包含原帖 URL、有效指令和上下文。
- 浏览历史:默认启用。SuperX 启用时,实际可见的支持帖子会被记录,即使没有 API Key、未生成回答或右栏已收起。历史在本机持久保存,按最近一次查看保留 24 小时,重复帖子合并;最多 1,000 条、约 6 MB,容量限制可能更早移除旧记录。
浏览历史可包含帖子 URL/ID、当前显示文字(最多 12,000 字符)、作者、语言、媒体存在标记、查看时间和次数,以及已有回答(最多 30,000 字符)、最多 20 个来源链接、模型/Token 信息和最多三条评论。历史不会保存图片文件,也不会为了记录历史抓取未显示的全文。
设置、自定义 prompt 和浏览历史没有加密。历史不会作为历史集合上传或同步;搜索、查看和展开已保存回答不调用 API,也不自动加载远程图片。点击原帖或来源链接才会访问相应网站。
Key 的自动加密可降低仅扩展设置或密文泄露的风险,但不能保护完整浏览器配置、同时包含密文与 IndexedDB 的备份,或已受攻击的浏览器和设备。加密密钥不与操作系统凭据或硬件绑定。存储访问仅限可信扩展页面及后台;X 页面上的内容脚本接收公开配置和 Key 是否可用,不接收 Key 或整份历史。
暂停、删除与保留时间
暂停 SuperX 会停止自动分析和新增历史记录;收起右栏会取消待执行任务,已开始的请求仍可能完成。关闭“保存浏览历史”会停止新增记录及回答更新,已有记录保留到过期。历史页可删除单条记录或清空历史;以后再次看到同一帖子可重新记录。
清除或替换 Key 会取消任务并清除旧会话 Key 和回答缓存。清除已保存 Key 也会删除本机密文、独立加密密钥和旧凭据记录。清除缓存不会删除 Key、设置、历史或已显示的回答;这些控制不会撤回已经发送的数据、撤销 xAI 的 Key 或删除服务提供方记录。
历史过期记录不会出现在历史视图中,并在启动、读取、写入及每小时清理时移除;浏览器关闭、调度延迟或存储错误可能延迟实际删除。回答缓存的 24 小时是复用期限,过期数据在后台初始化或后续写入时清理,也可手动清除;会话结束后不主动保留。卸载扩展或删除扩展数据是更全面的本机移除操作,但不能保证备份或存储残留中的法证擦除。
xAI、费用与第三方
xAI API 费用由你的 xAI 账户承担,与 X Premium 分开。后台事实求证是额外请求,搜索和评论可能产生额外费用;SuperX 没有金额或帖子数量上限。已发送的请求即使取消,仍可能计费。
请求设置 store: false,但这不是 xAI 不保留数据、日志或工具输入的保证。xAI 的账号设置及条款仍适用;使用前请查看其 API 数据安全说明、数据处理附录及 API 服务条款。SuperX 不检查或配置提供方的保留要求;普通 Key 或 store: false 不能证明满足所有提供方要求。
帖子内容和相关浏览活动仅用于所述解读、事实求证、评论草稿、本机近期历史及必要缓存,不用于广告、数据销售、信用决策或无关画像,并遵循 Chrome Web Store User Data Policy 及其 Limited Use 要求。
模型 Markdown 在本机解析;不执行模型 HTML、不加载模型提供的图片。主动打开来源、API 控制台或帮助链接适用该网站自己的政策。X 本身继续执行其正常网络请求。
官网与权限
本官网是 Cloudflare 托管的静态页面,不接收你的 API Key 或扩展浏览历史,不使用第三方分析脚本。只在本机保存官网语言偏好。访问官网时,Cloudflare 会按其服务和政策处理常规请求信息(例如 IP 地址和请求元数据)。
扩展使用 storage 存储设置、Key、历史和会话缓存,使用 alarms 清理过期历史,并访问 x.com、twitter.com 和 api.x.ai。它不请求浏览器全局历史或 Cookie 权限。
Privacy notice
Updated October 7, 2026
SuperX runs in your browser. You use your own xAI API Key and send analysis requests directly to xAI. SuperX has no relay server, analytics service or telemetry endpoint.
What analysis sends
With analysis enabled and an available Key, visible supported X posts can trigger paid requests. Requests include the original post URL and ID, currently displayed text and language mark, author and time, media information, up to four eligible X-hosted image URLs and descriptions, and available quoted-post context. They also include your model, language, search options and effective task instructions, including custom prompts.
A background fact check includes the earlier explanation; comment drafting includes the existing analysis. Your API Key authenticates requests to api.x.ai. Search tools may retrieve further posts, pages or media. Providing a URL or thumbnail does not mean the model fully read or watched the media.
Analysis is not limited to public posts: visible protected posts, replies, likes and bookmarks can be sent as context. Pause SuperX or clear your Key before opening content you do not want sent. Direct messages and standalone Grok pages are excluded from analysis and history. SuperX does not read X login cookies, send X session credentials, publish, like, reply or repost. Suggested comments are drafts copied to the clipboard only when clicked.
Data kept on your device
- API Key: Remember Key is on by default for first setup. AES-GCM ciphertext is saved in local extension storage; a separate random, non-extractable encryption key is held in extension IndexedDB. The Key restores automatically after browser restart, with no password step. Turning Remember Key off and saving keeps the credential only for the browser session.
- Settings: model, languages, custom prompts and related preferences remain on the device and are not synced through the browser.
- Answer cache: generated text, comments, sources, model and Token metadata remain in the browser session cache, bounded to 160 entries and about 4 MB, reusable for up to 24 hours within that session. Cache identities can also contain post URLs, effective instructions and context.
- Browsing history: on by default. Supported posts actually visible while SuperX is enabled are recorded even without an API Key, a completed answer or an expanded sidebar. History persists across browser restart for 24 hours after each post's latest view, merges duplicate posts, and is bounded to 1,000 posts and about 6 MB. Storage limits may remove older records sooner.
History can include post URLs/IDs, displayed text (up to 12,000 characters), author, language, media-presence flags, viewing times and counts, existing answers (up to 30,000 characters), up to 20 source links, model/Token metadata and up to three comment drafts. It does not save image files or retrieve unseen full text just to populate history.
Settings, custom prompts and browsing history are not encrypted. History is not uploaded as a history collection or synced. Viewing, searching and expanding saved answers makes no API requests and does not automatically fetch remote images. Original-post and source links visit their websites only when clicked.
Automatic Key encryption reduces the risk from exposure of ciphertext or local-settings storage alone. It does not protect a full browser profile, backups containing both ciphertext and IndexedDB, or a compromised browser or device. The encryption key is not bound to operating-system credentials or hardware. Storage access is restricted to trusted extension pages and the worker; the X content script receives public configuration and Key readiness, not the Key or the saved history collection.
Pause, deletion and retention
Pausing SuperX stops automatic analysis and new history recording. Collapsing the sidebar cancels waiting work; started requests may still finish. Turning Save browsing history off stops new records and answer updates while existing records remain until expiry. History allows deleting one post or clearing all records. A later actual view can create a new record.
Clearing or replacing the Key cancels tasks and clears the old session credential and answer cache. Clear saved Key also removes local ciphertext, the separate encryption key and obsolete credential records. Clear cache does not delete your Key, settings, history or answers already displayed. These controls do not recall sent data, revoke the Key at xAI or delete provider records.
Expired history is excluded from views and removed on startup, reads, writes and hourly cleanup. Browser shutdown, scheduling delays and storage errors may delay physical deletion. The answer cache's 24-hour limit is a reuse expiry: expired entries are pruned on worker initialization or later writes, or removed by manual clearing; they are not deliberately kept after the session ends. Uninstalling or removing extension data is a broader on-device removal step, without a guarantee of forensic erasure from backups or storage remnants.
xAI, costs and third parties
xAI API usage is billed to your xAI account separately from X Premium. Background fact checks add a request; searches and comments may add cost. SuperX has no monetary or post-count cap. Already sent work may still be billed even when cancelled.
Requests set store: false; this does not guarantee that xAI retains no data, logs or tool inputs. Its account configuration and terms remain applicable. Review its API security documentation, Data Processing Addendum and API Enterprise Terms before use. SuperX does not check or configure provider-side retention requirements; a normal Key or store: false does not establish that all provider requirements are met.
Post content and related browsing activity are used only for the described explanations, factual-claim analysis, comment drafts, on-device recent history and necessary caches. They are not used for advertising, data sales, credit decisions or unrelated profiling. SuperX follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Model Markdown is parsed locally. SuperX does not execute model HTML or load model-provided images. Opening a source, the API console or a help link is governed by that website's own policies. X continues its usual network requests independently.
Website and permissions
This website is a static site hosted by Cloudflare. It does not receive your API Key or extension browsing history and does not use third-party analytics scripts. It saves only website language preferences locally. Cloudflare processes ordinary request information, such as IP addresses and request metadata, under its own services and policies.
The extension uses storage for settings, Key, history and session cache, alarms to remove expired history, and access to x.com, twitter.com and api.x.ai. It does not request access to the browser's global history or cookies.