Last updated: August 7, 2026
This Privacy Policy explains how Eventually (“we”, “us”, “our”) collects, uses, and protects information when you use our browser extension and related services (collectively, the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this Policy.
Eventually is operated by Becomes Tech, LLC, a Delaware limited liability company.
Registered / mailing address:
Becomes Tech, LLCEventually is a personal productivity tool that helps you back up and organize your own bookmarks from X (https://x.com). Becomes Tech, LLC is the data controller for information we collect and process through the Service.
If you have any questions, you can contact us at:
We only collect data that is necessary to provide the Service.
When you sign in with X via our authentication flow (using Supabase and X OAuth), we may receive:
We do not receive or store your X password.
To provide the bookmark backup and organization features, we collect:
These bookmark fields come from X’s internal Bookmarks GraphQL API (x.com/i/api/graphql), which the extension calls directly when you click sync. We do not read, scrape, or parse the HTML or DOM of the bookmarks page; the extension’s content script only displays the Eventually panel on that page.
We only process bookmarks for the X account that you explicitly connect to Eventually.
To call X’s Bookmarks GraphQL API on your behalf, the extension needs the same authentication X uses for your own requests. Using the browser webRequest permission, it observes outbound requests to X’s GraphQL API (/i/api/graphql) while you are logged in on x.com, and copies only these request headers when present: authorization, cookie, x-csrf-token. This data:
chrome.storage.session)We do not store your X password and never upload these session headers to Eventually servers. The extension does not capture headers from other (non-GraphQL) requests or from other websites, and it does not use them outside of syncing your bookmarks.
If you subscribe to reminder emails, payment is processed by Stripe. We may receive limited billing metadata from Stripe (for example, subscription status, customer ID, and plan). We do not store your full payment card number on our servers.
We may collect limited technical information when you use the extension or site, such as:
We do not attempt to track you across other websites.
We collect data in these main ways:
To be explicit about what we do not do:
The extension requests the following permissions:
webRequest: to capture your X GraphQL session headers for sync, as described in section 2.3. This is not general browsing surveillance; it only observes outbound requests to X’s GraphQL API.x.com / twitter.com GraphQL endpoints): to capture session headers and fetch your bookmarks via X’s GraphQL API.storage: to save your Supabase login session (local) and your short-lived X auth headers (session).identity: for the OAuth redirect used to sign in with X via Supabase.tabs: to open or focus the bookmarks tab and clean up the OAuth redirect tab.We use your data for the following purposes:
If you are located in the European Union, EFTA States, or the United Kingdom, we process your personal data under the following legal bases:
You can withdraw consent at any time where consent is the legal basis.
We do not sell or rent your personal data.
We may share your data with:
We do not provide your bookmarks or other X data to advertisers or data brokers.
We keep your data only as long as necessary for the purposes described above:
Depending on your location, you may have some or all of the following rights:
To exercise any of these rights, contact us at support@geteventually.com. We may need to verify your identity before acting on the request.
You also have the right to lodge a complaint with your local data protection authority if you believe we are processing your data unlawfully.
We use reasonable technical and organizational measures to protect your data, including:
No system is perfectly secure, but we work to reduce risks of unauthorized access or disclosure.
If we become aware of a data breach that affects your personal data, we will notify you and relevant authorities as required by law.
Our infrastructure providers (such as Supabase and hosting providers) may process data in countries outside your own, including the United States or other locations.
Where required by law, we rely on appropriate safeguards (such as standard contractual clauses) to protect your data when it is transferred internationally.
Our Service integrates with third-party platforms, most notably X, Supabase, and Stripe. Your use of those platforms is also governed by their own terms and privacy policies (for example, https://x.com/tos and https://x.com/privacy).
We do not control how these third parties process your data once it is in their systems.
The Service is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. If changes are material, we will provide additional notice (for example, on our website or in the extension).
Your continued use of the Service after any changes means you accept the updated Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact: