Privacy Policy — Threads, Instagram, Facebook, X Posts Library & Downloader

Effective date: 18 July 2026 · Last updated: 5 September 2026

The short version: your library stays on your own computer unless you choose an optional AI action or explicitly share a generated file. The developer operates no servers, collects no data, and never sees anything you save. AI categorization sends selected post text directly from your browser to the AI provider you picked using your own API key; selected-post sharing sends a local file only to the person or app you choose through your operating system.

This policy covers Threads, Instagram, Facebook, X Posts Library & Downloader, formerly Post Library and referred to below as Post Library.

What Post Library does

Post Library saves posts from your own logged-in account's Saved list, or original posts from a public Threads profile that you explicitly enter, into a private, searchable library on your device. A public-profile run uses your current browser session and reads only what Threads publicly loads in that run; it skips replies, reposts, private or unavailable content and ambiguous cards, and does not promise the account's complete history.

For Instagram, choose your own Saved list or enter an Instagram public profile; both use the current browser session. Public-profile mode reads only exact-user post/reel links in the main profile grid and checks the detail author before saving. Login, private, unavailable or blocked pages stop without bypass or automatic retry, and the loaded results are not complete account history.

For Facebook, this version supports user-started exact text posts, pure-photo posts/carousels, one /photo/?fbid=… photo and one /reel/<id> Reel. A pasted link may omit https://; official mobile/web aliases are normalised to www.facebook.com. A strict fb.watch short link is used only to navigate until Facebook resolves it to an already-supported exact identity: the extension has no permission to read the short host and injects no reader there. After optional permission is granted, it opens one inactive background tab in the current browser session and checks bounded login/checkpoint, rate-limit, private/unavailable and exact-target signals without taking focus from the dashboard. A successful action closes that tab; a failed action may retain only the inactive tab for inspection. An ordinary post is accepted only when a direct Story's own id or permalink matches the requested post; only its ordered direct Photo attachments are used. Chrome must confirm every carousel photo as complete before one local Library record is written. A Reel progressive file needs the requested id at both nested delivery layers. If an exact Facebook Library write fails, newly accepted files are removed or handed to terminal cleanup; a path already referenced by the previous record is not deleted. Video/shared ordinary posts, conflicting photo groups, adjacent stories and recommendations are rejected without a record. A direct photo uses its HTTPS Facebook-CDN image; a Reel uses an exact progressive MP4, preferring HD. A DASH-only Reel is labelled Partial and may keep proven text/poster without claiming a Library MP4. The separate Photo action downloads only an exact direct photo or pure-photo post/carousel; the separate Video action downloads only an exact progressive Reel. These standalone actions write no Library record or backup.html, never substitute a Reel poster or DASH stream, and count success only after Chrome confirms the file complete. Facebook Saved/Profile scanning is not enabled. The extension never reads or exports Facebook cookies or tokens, replays internal requests, or sends Facebook content to the developer.

For X, choose Bookmarks or Likes and press Start, or paste one exact X /<user>/status/<id> into Save this post, Download photos only or Download videos only. Optional access is requested only from that chosen action. A History run uses your current signed-in browser session and keeps the exact /i/history or /i/history/likes route in one inactive tab. Both History and one-link actions first make one credential-free GET of each exact public status URL, reading at most 4 MiB. The result is accepted only when head metadata proves the canonical username/status id and creator, the exact Tweet root links to its own details and separate counts object, and the complete ordered media_entities2 reference list resolves only to that root's native media rows. A proved native photo/video or an explicit empty native-media list can save without rendering an exact-status tab; external card_img artwork remains a link preview, not an X photo. Private, unavailable or unsupported public shapes fall back to one inactive signed-in exact-status tab. If that fallback is still showing X's loading shell, a temporary no-article result enters a bounded readiness window for the exact outer article before the settled content/media reads; login, rate-limit and wrong-status results still stop immediately, and the tab is not activated. X Bookmarks and Likes skip every status already in Library by default, including older blank and Partial records. Enable Settings → Update existing X posts to refresh existing records on future History runs. Pasting one exact link and saving it explicitly still updates that post. A proved empty media set stores that small marker locally inside the existing forward-compatible record section, and JSON or Full backup/restore preserves it. One immutable status id owns one record, so the same status is updated rather than duplicated. A direct save does not invent a Bookmarks/Likes membership and preserves any real memberships already stored. Outer post text, the exact outer post's public like/reply totals and the requested name=orig variant of pbs.twimg.com/media/ photos stay local. External article-card previews, including CTV-style link previews, remain links and are not copied as native X photos. Photo-only downloads only exact outer photos and never a video poster; both standalone actions leave Library and backup.html unchanged. Reply bodies and quoted-post content/media are not borrowed. For a MediaSource blob: video in History or a tab-backed fallback, one packaged page script is dynamically registered only during that user-started run, only for X, and removed after the owned tab closes; Photo-only does not register it or request webRequest/video-host access. Whether X uses Fetch or XHR, it inspects only X GraphQL JSON responses the exact status page already requested, traverses a bounded number of nodes to locate the exact Tweet, reads only that Tweet's declared extended_entities.media[].video_info.variants, and temporarily exposes at most 20 known progressive-MP4 metadata rows. When that exact video/animated-GIF media row has a generic pbs.twimg.com/media/ poster, the temporary row may additionally carry only that poster URL and numeric media id so the extension can require the id to equal the MP4's CDN asset. It does not make or replay an internal API request and does not retain other response fields. The bounded public exact-status document may also supply literal declared MP4 rows whose media family/id matches its exact poster. A generic poster is accepted only when the same bounded ApiMediaEntity is a video/animated GIF and its own id_str equals the candidate asset; Photo rows, escaped post text, source_status_id_str and arbitrary images cannot substitute. An optional non-blocking response listener is separately restricted to one extension-owned fallback/History tab and video.twimg.com; a proved no-tab one-link action creates no listener. It temporarily retains only a bounded media URL, HTTP status and Content-Type tuple. Every captured row is treated as untrusted. A direct progressive MP4—including X's current codec-labelled form only when exact declarative metadata supplied it—is saved only when its family/asset id or the exact media-object relationship matches the exact status poster and a fresh credential-free request returns one full HTTP 200 response that again passes the exact host/path, MIME and file-signature checks. HLS playlists, /aud/, segments, unknown streams and unmatched or failed files keep only the poster with an explicit Partial reason for a Library save and produce no standalone video file. Login, wrong-route, rate-limit, unreadable and repeated-layout failures stop without bypass or automatic retry. The reader never accesses or exports X page cookies, tokens, request bodies or headers, unrelated response headers or X page local/session storage, clicks Like/Bookmark controls, or calls/replays internal X requests or APIs; no X content is sent to the developer.

X Link previews are separate from X photos. When the exact requested Tweet root proves its own external Card, Post Library stores the safe destination URL, title and site as a labelled Link preview. Its optional image is requested without credentials only from an exact pbs.twimg.com/card_img/ URL, streamed to an 8 MiB limit and kept only after final URL/path, HTTP 200, image MIME and file-signature checks. A failed image becomes a text-only preview. Link-preview artwork is not added to native photo arrays, Pictures/OCR or Download photos only. Its local thumbnail is covered by Library/offline display, text search, JSON and Full backup/restore, and is removed when an exact later save proves that Card was removed or replaced.

Data the developer collects

None. Post Library has no analytics, no tracking, no telemetry, no ads and no developer-operated servers. Nothing you save, type or configure is ever transmitted to the developer.

Where your data lives

Saved-post To dos and reminders

Adding a saved post to your To do list, its due date, snooze state and completion state stay with that post in local extension storage. You can use all of these Library controls without granting notifications. When you first save a due date, Post Library explains the optional system alert before Chrome asks. If you allow it, Chrome receives only a generic local notification request: the extension name as the title and how many saved posts are due. It never includes post text, author, category, media, replies or picture-reading text, and nothing is sent to the developer. A browser or device that was asleep can show the alert later than the due time.

Settings lets you hide reminder controls and the Related posts button independently. These display preferences stay on this device; hiding reminder controls does not cancel existing reminders.

Related posts

Only when you press Related posts on a saved card, Post Library makes a bounded local scan of up to 100,000 saved records already on your device and can show up to five non-duplicate matches with a plain reason. It compares existing categories, tags, post text, picture-reading text and replies; an existing transcript is only a lower-weight local signal. This feature makes no related-post network request and does not write the derived matches into a saved-post record, JSON export or Full backup.

Selected-post sharing

Only after you tick specific saved posts, review the preview and press Create share file, Post Library makes one single local HTML file. By default it includes only the selected posts' author/handle, date, outer post text, complete Threads Article title/body when stored, source URL and safe stored thumbnail or poster bytes. Categories/tags, replies, picture-reading text, transcripts and stored video are separate opt-ins; video also needs its own warning acknowledgement. Tasks/reminders, API keys, tokens, private settings, computer/library paths, unselected posts and derived caches are excluded. Remote media is never embedded. The file has no public link and never goes to the developer. Where your browser supports it, you can deliberately hand the file to a person or app through the operating system's Share sheet; otherwise it stays a local download.

Optional AI categorization

Off by default. If you choose to run it, the text of your selected posts (never media files) is sent directly from your browser to the AI provider you selected — Google Gemini or Agnes AI — authenticated with your own API key. The developer is not part of that connection and cannot see it. The provider's own privacy policy governs its handling of that text. Your API key is stored only on your device and is only ever sent to that provider itself. Pressing Check API sends that provider one short test prompt with your key and classifies its response; it does not send a saved post, call a separate quota service or make a second request to estimate remaining quota.

Reading the text inside pictures

Optional, off by default, and runs entirely on your device using an engine bundled inside the extension. Pictures are never uploaded anywhere, and no network request is made to read them.

Why each permission is needed

PermissionUsed for
storage, unlimitedStorageKeeping your library (which can include videos) on your device.
downloadsSaving post media, a separately owned X Link-preview thumbnail, the offline backup page and a user-started Full backup archive into your Downloads folder; restoring archived media under Downloads; removing a superseded exact X link_preview.jpg when a later save proves its Card changed; and — for other post files — removing them only when you tick that box while deleting.
alarmsKeeping one local wake-up for the earliest due saved-post reminder. It does not upload data or create automatic scraping.
notifications (optional)Only after you choose it following the due-date explanation, so Chrome can show a generic due-post count. Declining leaves the in-app To do working.
scripting, access to threads.comOpening your Threads Saved list or a public profile you entered and reading its loadable posts in your current browser session — only when you press Start. A public-profile run stops on login, private/not-found, soft-block or rate-limit pages and does not bypass or automatically retry them.
Access to instagram.com (optional)Not requested at install. Only if you press Instagram Start is Chrome asked for it, and only then can the extension open your own Instagram Saved list or a public profile you entered and read the matching posts. Saved-list mode can also read the names of your collections when Collections → categories is ticked, so each post can be filed under the name you gave it; the same access lets you paste a single Instagram post link to save just that post. You can withdraw it at any time in Chrome's extension settings, and nothing about Threads is affected.
Access to facebook.com (optional)Not requested at install. Chrome asks only after you paste a recognised Facebook exact/share link and press Save this post, Download photos only or Download videos only. Official mobile/web aliases are opened through the same www.facebook.com permission. An fb.watch URL can be opened only for its normal redirect; no reader is injected until the final URL is an exact supported www.facebook.com identity. One matching ordinary Story with text/direct Photos, one exact /photo/?fbid=… image or one /reel/<id> progressive MP4 may be read for that action. Save requires every ordinary-post photo to complete first. Standalone Photo/Video writes only the requested supported media and leaves Library unchanged; Reel posters, DASH-only video and ordinary-post video are not substituted. Declining opens no page, and you can withdraw access at any time.
Access to Instagram/Facebook CDN domainsDownloading the images and videos belonging to selected Threads/Instagram posts and the exact direct photos, image, Reel MP4 or Partial poster belonging to a supported Facebook save or standalone download.
webRequest and access to x.com / www.x.com / pbs.twimg.com / video.twimg.com (optional)Not requested at install. Chrome asks only after you start X Bookmarks/Likes, X Save this post or X Download videos only. X Download photos only requests just X and pbs.twimg.com, without webRequest or video-host access. History uses one inactive tab. A one-link action first reads at most 4 MiB from its public exact-status URL without credentials and requires the same canonical username/status id, creator and exact Tweet Relay media prefix. A proved Photo/Video, or Save with complete exact text, opens no source tab. Private or unsupported public-document shapes fall back to one inactive exact-status tab. A packaged X-only page script is registered only for History or a video-capable tab fallback, observes only X GraphQL JSON the exact status page already requested, and temporarily keeps at most 20 progressive-variant metadata rows from the matching status object; a generic pbs.twimg.com/media/ video poster additionally needs that same exact video/animated-GIF media row's numeric id to equal the MP4 asset. It makes/replays no internal API request and retains no other response fields. The non-blocking webRequest listener is created only for an owned History/fallback tab and filtered to that tab plus exact video.twimg.com. It keeps only a bounded URL/status/Content-Type tuple long enough to match and revalidate a direct progressive MP4. The listener and page capture are removed after the owned tab closes. None of these paths inspect request bodies/headers, cookies, tokens, unrelated response headers or page storage, and they do not accept playlists, /aud/, segments or unmatched streams. Declining opens no tab, and you can withdraw access at any time.
X pbs.twimg.com/card_img/ access (optional)Only after an exact user-started X save proves its own external Card, one credential-free image request may create a local Link-preview thumbnail. The final host/path, HTTP 200, MIME, signature and 8 MiB streamed limit must all pass. It is excluded from native X photos, Pictures/OCR and Photo-only.
Optional AI provider domainsRequested only if you use optional AI setup or categorization, to let your browser call the provider you chose with your own key. Check API uses one short provider request and no separate quota request.

Data sharing and selling

Post Library does not sell user data and does not send any user data to the developer. The developer holds no user data. When you deliberately run optional AI categorization, the selected post text and your API credential are sent directly to the AI provider you chose. When you deliberately use selected-post sharing, the generated local file goes only to the person or app you choose through the operating system; it is not uploaded to a developer server and has no public link. Otherwise the extension does not share your library data.

Deleting your data

You are in full control.

Chrome Web Store User Data Policy

Post Library's use of information received from browser APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

Children

Post Library is not directed at children under 13.

Changes to this policy

Any change will be posted at this page with a new effective date.

Contact

Questions about this policy: support@yaka310.com