AI Toolbox for Grok Privacy Policy
Last updated: October 01, 2026
Notice of changes: We review this policy whenever our data-handling practices, features, or legal obligations change. The date above reflects the most recent revision. For material changes (such as new data categories, new third-party processors, or changes to your rights), we will make reasonable efforts to notify you through the extension or by email at least 14 days in advance.
At AI Toolbox ("we", "us", "our"), operated by Infi Developments, we are committed to protecting your privacy. This Privacy Policy comprehensively explains what data the Grok module collects, how we collect it, how we handle, store, and share it, and your rights, in plain language. The Grok module runs on both Grok surfaces: the X-embedded Grok at x.com/i/grok and the standalone grok.com.
1. Data Controller
Infi Developments is the data controller responsible for your personal data. For any privacy-related inquiries, contact us at [email protected].
2. What Data We Collect
We collect only the minimum data needed to provide our service. Below is a complete list of every category of data the Grok module handles:
2.1 Account identity
Grok has one identity across both surfaces: your X (Twitter) account, expressed as the numeric X user id. Because x.com is password-gated and exposes no email, we identify your Grok account by your X @handle, which you supply at checkout and which we resolve to your numeric X user id to recognize your subscription. On grok.com, which also exposes an email, that email may be used as a fallback identifier when no X link is present. We do not collect your name, password, physical address, or any other personal identifiers.
Handle matching: To recognize your subscription, the X handle you enter at checkout must be the handle of the X account you use for Grok. If it differs or was mistyped, contact us at [email protected] and we will reconcile your entitlement.
2.2 Data stored locally in your browser (never stored on our servers)
The following data is stored on your device and is never stored on our servers. Your Grok conversation content is sent to us only in the situations described in 2.3, each of which you trigger yourself.
- Your Grok conversation content and message text (from both x.com/i/grok and grok.com)
- Your X and grok.com browser session data (used to communicate with Grok on your behalf)
- Extension settings and preferences
- Local search history and recent searches within the extension
- Conversation cache (stored in your browser's IndexedDB for faster search and export)
- Smart Tags computed locally from your cached conversations
2.3 Data synced to our servers
The following data is transmitted over HTTPS and stored on our servers, keyed to your X user id so it follows you across x.com/i/grok and grok.com. We do not store your conversations on our servers; the only message text we keep is the short preview of a message you bookmark:
- Folder names, folder structure, and folder color preferences
- Saved prompts and prompt chains (unless you switch them to device-only storage in Settings)
- Conversation IDs (for folder assignments)
- Message bookmarks: the conversation and message IDs, a short preview of the bookmarked message (up to 300 characters, so the bookmark can be listed and found), and the color you choose
- If you use cross-platform folders (Premium): your All platforms folder tree, meaning folder names, structure, and the conversation IDs in it
- Achievement data: your daily streak length, the dates you were active, which milestone badges you have unlocked, and your streak freeze balance. This is synced so that your streak and badges follow you across your devices
Conversation content processed temporarily (not stored)
Three features send the content of one conversation you choose to our servers. Each runs only when you trigger it, never in the background, and the content is processed in real time and immediately discarded: it is never written to a database, a file, or a log.
- Context Mentions (@@): if the conversation you mention is long (roughly 15,000 characters or more), its messages and title are sent to our server to be summarized. Shorter conversations are inserted into your prompt box entirely on your device and are never sent to us.
- Carry this chat forward: the messages and title of the chat you choose are sent to our server to be summarized, so the summary can start your next chat, on this AI or on another one.
- PDF export: the conversation is sent to our server, which renders the PDF and returns the file. Exports to TXT, Markdown, and JSON are generated entirely on your device and are never sent to us.
Summaries are generated using the OpenAI API. For the two summarization features above, our server passes the conversation text to OpenAI's API to produce the summary and returns it to your browser. Under OpenAI's API terms, data submitted through the API is not used to train their models. If you would rather this never happen, do not use these two features; everything else keeps working.
2.4 Payment data
Payments for the AI Toolbox Grok module are processed by Polar (our payment provider). We do not store your credit card details. At checkout you provide your X @handle in a dedicated field so we can link your purchase to your Grok account; Polar provides us with your payment status and the details you entered so we can verify your subscription. Polar's privacy policy governs how they handle your payment information.
2.5 Install and uninstall information
When you install the extension, a welcome page is opened in your browser. When you uninstall the extension, a feedback page may be opened. No additional data is collected during install or uninstall beyond what is described in this policy.
2.6 Analytics
No third-party analytics run inside the extension. On our website, Google Analytics 4 and Microsoft Clarity load only after you click Accept in the consent banner, and Ahrefs Web Analytics counts page views without cookies or identifying you. We also use Google Analytics on our Chrome Web Store listing page. The details are in the ChatGPT module section of our Privacy Policy.
2.7 Cookies
The extension does not set cookies. Our website uses strictly necessary cookies for signing in and checkout, and analytics cookies only if you accept them in the consent banner. The full list is in the ChatGPT module section of our Privacy Policy.
2.8 Your status handle and the leaderboard
Your extension gives you a randomly generated handle (for example, "SwiftFalcon42") as your status name. It is generated for you; you cannot type your own, so it never contains your name, your email address, or any other personal detail. By default it is shown only to you, and you can replace it with another random handle at any time.
The leaderboard is optional and off by default. If you turn it on in the extension's Settings, your handle and your streak length become visible to other AI Toolbox users. If you never turn it on, you never appear to anyone else.
Your handle and streak length are the only data we store unencrypted, because a leaderboard has to be able to sort by them. Your underlying achievement data stays encrypted as described in 2.3. Your name, email address, conversations, subscription, and every other piece of your data are never on the leaderboard.
Turning the leaderboard off removes you from it and deletes your leaderboard entry. Your handle stays as your private status name, and you can rejoin at any time.
2.9 Approximate location (country)
We store an approximate location as a two-letter country code (for example, "US" or "IN"). It is derived on our server from the IP address of your extension's requests using an offline database; your IP address is not stored and is never sent to any third party for this purpose. We use this country code only to offer region-appropriate discounts by email (sent only to users who have consented to marketing email) and for aggregate regional reporting. Our lawful basis for deriving and storing the country code is our legitimate interest in offering fair, region-appropriate pricing. You can ask us to delete it at any time by contacting us at [email protected].
3. How We Collect Your Data
We collect data through the following methods:
- Session authentication: The extension reads authentication information from your existing X and grok.com browser sessions (via the browser's standard storage and webRequest APIs) to communicate with Grok on your behalf and to derive your X user id. We do not intercept, read, or store the content of your Grok messages on our servers through this mechanism.
- Checkout: You provide your X @handle in the dedicated field at checkout so we can link your subscription to your Grok account.
- Your actions in the extension: When you create folders, save prompts or chains, or bookmark messages, these are stored on our servers as described in 2.3.
4. How We Use Your Data
We use the data we collect for the following purposes only:
- Provide our service: Sync your folders, prompts, chains, and bookmarks across your devices and across both Grok surfaces.
- Authenticate your account: Identify your Grok account by your X user id (resolved from your handle) to provide personalized access to your synced data.
- Verify subscriptions: Check your payment status via Polar to unlock Premium features.
- Respond to support requests: If you contact us, we use your email or handle to respond.
- Improve the extension: Aggregated, non-personal usage patterns help us understand which features are most valuable so we can improve the experience.
5. How We Store Your Data
Local storage (your browser)
Your conversation content, search history, Smart Tags, and settings are stored locally on your device using Chrome's built-in storage APIs (chrome.storage.local) and IndexedDB. Your conversations never leave your browser except for the short preview of a message you bookmark and the three cases described in 2.3, each of which you trigger yourself.
Server storage (our infrastructure)
Synced data (folders, prompts, chains, conversation IDs, bookmarks) is stored on our secure servers hosted on industry-standard cloud infrastructure, keyed to your X user id. Data in transit is protected with HTTPS/TLS encryption. Your Grok conversations are never stored on our servers, apart from the short preview of a message you bookmark.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We share data only with the following parties, and only as described:
- Our backend servers (api.infi-dev.com): Your X user id (for authentication and entitlement) and your synced data (folders, prompts, chains, conversation IDs, bookmarks).
- OpenAI API (summarization sub-processor): When you use Context Mentions on a long chat or Carry this chat forward, our server sends that conversation's text to OpenAI's API to generate the summary, and returns the result to you. Under OpenAI's API terms, data submitted through the API is not used to train their models. No other feature sends your conversations to OpenAI.
- Polar (payment processor): Payment processing and subscription management. They receive your payment details and the X handle you entered at checkout directly. We only receive your payment status and the details you entered from them.
- X / xAI (x.com/i/grok) and grok.com: The extension communicates with Grok's existing interfaces using your active browser session to provide its features (e.g., fetching conversations for search and export). This is the same data your Grok account already has access to, so we do not send any additional personal data to X or xAI. We also perform a lookup to resolve your X @handle to your numeric X user id.
- Google Analytics: Anonymous, aggregated usage data on our Chrome Web Store listing page only. No analytics are collected within the extension.
- Other AI Toolbox users (only if you turn on the leaderboard): The leaderboard is off by default. If you turn it on in Settings, your randomly generated handle and your streak length become visible to other AI Toolbox users. Nothing is shared until you turn it on, your name and email address are never shown, and turning it off removes you and deletes your entry. See 2.8.
- Legal obligations: We may disclose data if required by law or in response to a valid legal request from a government authority.
We do not share your data with any other third parties, advertisers, data brokers, or AI model training services.
7. Legal Basis for Processing (GDPR)
We process your data based on the following legal grounds under GDPR Article 6:
- Contract performance: Processing necessary to provide the services you signed up for (e.g., syncing folders across devices, identifying your Grok account, verifying your subscription).
- Legitimate interest: Processing necessary for the operation and improvement of our services (e.g., aggregated usage analytics to improve features), provided it does not override your rights.
- Consent: Where applicable, we process data based on your explicit consent (e.g., enabling cloud sync, appearing on the leaderboard). You may withdraw consent at any time by disabling the relevant feature or contacting us.
8. Data Security
We take the security of your data seriously and implement multiple layers of protection:
- Encryption at rest: All synced data stored on our servers is encrypted, including your achievement and streak data. The keys are held by our infrastructure, so this protects your data against unauthorized access to our database rather than being zero-knowledge encryption. We do not read the content of your folders, labels, bookmarks, or achievements. The only exception is the leaderboard handle and streak number described in 2.8, which have to be stored unencrypted so the leaderboard can be sorted, Your handle is shown only to you until you turn the leaderboard on.
- Encryption in transit: All communication between the extension and our servers uses HTTPS/TLS encryption.
- Minimal data collection: We follow the principle of data minimization. We only collect what is necessary to provide our service.
- Local-first architecture: Your conversation content stays in your browser and is never stored on our servers, apart from the short preview of a message you bookmark, reducing exposure risk.
- Secure infrastructure: Our servers are hosted on industry-standard cloud infrastructure with regular security updates.
- No conversation content on our servers: We never store the content of your Grok conversations on our servers.
9. Your Rights
Under GDPR and applicable data protection laws, you have the following rights. To exercise any of these rights, contact us at [email protected]:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate data (for example, a mistyped X handle).
- Right to erasure: Request deletion of your personal data from our servers.
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: You can delete any folder or prompt at any time, which removes it from our servers, and you can ask us to delete all your server-side data, to stop data transmission to our servers. For other consent-based processing, contact us.
- Right to lodge a complaint: You have the right to file a complaint with your local data protection authority.
We will respond to all data rights requests within 30 days.
10. Data Retention
We retain your synced data (folders, prompts, chains, conversation IDs, bookmarks) for as long as your account is active.
- Local data: Data stored in your browser persists until you clear your browser data or uninstall the extension.
- Server data: Synced data is retained until you request deletion or your account is removed.
If you wish to have your server-side data deleted, contact us at [email protected] and we will remove all associated data from our servers within 30 days.
Uninstalling the extension removes all locally stored data from your browser immediately. Server-side data requires a separate deletion request.
11. International Data Transfers
Our services are available worldwide. Your data may be processed in countries outside your country of residence. Where we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in compliance with GDPR requirements.
12. Children's Privacy
Our free extension does not have age restrictions. However, purchasing a paid plan requires a valid payment method (credit card or Apple Pay), which is limited to individuals of legal age in their jurisdiction. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we will make reasonable efforts to notify you via the extension or email.
14. Contact Us
If you have any questions about this Privacy Policy, your data, or your rights, contact us at: [email protected]