# TrustBadge Privacy Policy

> What TrustBadge collects, what it never collects, and where data goes.

Source: https://www.extensionshop.store/extension/trustbadge/privacy
Markdown: https://www.extensionshop.store/extension/trustbadge/privacy.md

This is the privacy policy for **TrustBadge** — Verified startup revenue on Twitter/X profiles. The extension page is at https://www.extensionshop.store/extension/trustbadge.

## Data collected

| Data | Optional | Purpose |
| --- | --- | --- |
| Twitter/X Handles | No | Handles of profiles you view are sent to the TrustMRR API to fetch startup data |
| Lookup Count | No | Number of lookups per hour stored locally for rate limiting |
| Startup Data Cache | No | Fetched revenue data cached locally for 24 hours to reduce API calls |

## Never collected

- Tweet content or direct messages
- Personal user information beyond your X handle
- Browsing history or activity outside Twitter/X
- Tracking cookies or analytics
- Passwords, tokens, or authentication data

## Third-party sharing

Twitter/X handles are sent to the TrustMRR API (trustmrr.com) to fetch public startup revenue data. License validation requests are sent to LemonSqueezy for Pro users. No personal data is shared with any other third party.

## Encryption

Data is transmitted over encrypted connections.

## Data retention

Lookup counter resets every hour. Startup data cache expires after 24 hours. Your X handle and preferences persist until cleared or the extension is uninstalled. Pro license status is stored with HMAC-SHA256 integrity protection.

## Permissions

| Permission | Why it is needed |
| --- | --- |
| Storage | Saves your preferences, lookup limits, and cached startup data locally |
| Host Access (twitter.com, x.com) | Injects the revenue badge into Twitter/X profile pages |
| Host Access (trustmrr.com) | Fetches verified startup revenue data from the TrustMRR API |

Support: iliasselbarhoumi@gmail.com
