How it works What you get Limits FAQ Install
Privacy policy · 23 September 2026

Your exports never leave your browser.

The comments you export are read in the tab you already have open and written straight to your Downloads folder. They are never uploaded, never sent to us, and never seen by anyone but you.

Two things do leave your browser, and this page is precise about both: the requests the extension makes to the platform you are exporting from, and — only if you create an account — your email address and whether you have a paid pass.

What it reads

When you export a post, the extension reads the comment data that page is already receiving from its own site — the same responses your browser loads as you scroll. It works only inside your own signed-in session and only on the sites listed in its permissions. It cannot see anything you could not open yourself.

To be exact about where it runs: its reader loads in every open tab on those sites, not only the one you are looking at, because a page's comment responses arrive as you scroll and cannot be captured after the fact. In a tab you never export from, what it sees is held in that tab's memory and goes when the tab does. Exporting, and the run history below, begin only when you start an export.

The comments it reads contain other people's names, profile links and words. That information is assembled in the tab and written to the file you asked for. A copy of your most recent exports is also kept in your own browser, as your run history (below), until you delete it or newer exports replace it. It is never sent anywhere.

What it stores, and where

WhatWhereWhy
Your panel settings — format, replies on or off, speed Your browser's extension storage So the panel opens the way you left it.
Your YouTube Data API key, if you use YouTube Your browser's extension storage It is your key, used to call YouTube directly. It is never sent anywhere but to YouTube's own API.
A resume checkpoint for a long Facebook export Your browser's extension storage So a run interrupted after twenty minutes can continue instead of starting over.
Your run history: your last 10 exports per platform — the post's address, when you exported it, and the comments themselves (authors, profile links, text, replies) Your browser's extension storage So you can download an export again or compare a re-run with the last one. It stays on this machine and is never sent anywhere. Older exports are dropped as new ones arrive; you can delete any of them from the panel.
Your account: email address and a user id Our database (Supabase), and your browser Only if you sign in. It is how a pass is attached to a person. Without an account nothing of yours is stored anywhere but your own machine.
Whether a pass is running, and the date it ends Our database (Supabase) To answer one question the extension asks a few times a day: is this person paid up, and if not, what is their export limit.
A sign-in token, and the last answer about your pass Your browser's extension storage So you are not asked to sign in repeatedly, and so an export still works when the network does not. Signing out deletes both.
The exported CSV or JSON file Your Downloads folder It is the thing you asked for. Nothing sends a copy anywhere.
Extension storage is private to the extension. The web pages you visit cannot read it. Removing the extension removes all of it, and you can clear the run history from the panel at any time.

What it does not do

Network requests it makes

Three kinds, and no others. All of them come from your own browser.

Who else is involved. Signing in uses Google, so Google knows you signed in to this extension — it is told nothing about what you export. Accounts and pass records are held by Supabase on our behalf. Payment is handled by PayMongo, who take your card or e-wallet details directly on their own checkout page; we never see them. What comes back to us is that a payment succeeded, and the date your access runs out.

Why each permission is asked for

PermissionReason
activeTab To act on the tab you pressed the toolbar button from, and no other.
scripting To place the export panel into the tab you launch it in. The reader itself loads in every open tab on the supported sites, as described above, so that a post's comments can be captured as the page requests them.
storage To keep the settings, the YouTube key, the resume checkpoint and the run history described above, all locally.
unlimitedStorage A post with tens of thousands of comments produces a resume checkpoint larger than the default quota; without this the run would fail partway.
Site access to facebook.com, youtube.com, tiktok.com, instagram.com, x.com and twitter.com These are the sites it exports from. It reads the comment responses those pages already receive. It has no access to any other site.
identity To open the Google sign-in window when you choose to create an account. Unused until you press sign in.
Site access to supabase.co Our database: where an account is created and where the extension asks whether your pass is still running.
Site access to googleapis.com To call the official YouTube Data API with your key.

Handling what you export

An export is other people's writing. Each platform's terms govern what you may collect and how you may use it, and this tool does not change them. If you are using the exports for research, the usual obligations apply — consent where required, care with identifying details, and storage appropriate to the sensitivity of what you collected.

Deleting your account

Signing out removes the token and the cached answer from your browser immediately. To have the account itself deleted — your email address and pass record — write to the address below and it will be removed, along with anything attached to it. Exports you have already saved are yours and were never ours to delete.

Changes and contact

If this policy changes, the updated version appears on this page and the date changes with it.

Contact: downthread.support@gmail.com for support, questions about this policy, or to have your account deleted.

Last updated 23 September 2026. Extension version 3.53.0.