LockPad for X 路 Chrome extension

Privacy Policy

Effective October 6, 2026 路 Applies to the "LockPad for X" browser extension published by LockPad. The website officiallockpad.com has its own privacy policy.

The short version: the extension reads the posts you're already looking at on x.com inside your browser to find contract addresses (CAs) and $tickers. When you hover one, it asks LockPad's public API about that CA or ticker, and nothing else. It does not collect your browsing history, your posts, your X account, your keystrokes or your wallet. It never holds keys or funds and can't sign transactions.

What the extension handles

DataWhat happensLeaves your browser?
Text of posts and bios on x.comScanned locally to find CAs and $tickers so they can be underlined.No
A CA or $ticker you hoverSent to officiallockpad.com/api/ext/v1 to fetch public coin info (price, LockPad proof, exit liquidity, rewards, automated checks).Yes, only that string. No cookies, account, wallet address, page URL, X handle or post text is attached.
Your settings (on/off, show non-LockPad coins, open buys in a window or tab)Saved with chrome.storage.local.No
Wallet label (optional)If you connect a wallet on officiallockpad.com, the site can send the extension a shortened label such as "Phantom 7xKX鈥sU2" to show in the card. Saved locally; you can remove it in the popup.No (it comes from the site)
Buy statusWhen you click Buy, officiallockpad.com opens. After you sign in your wallet, the site tells the extension "submitted / confirmed / cancelled / failed" and the transaction signature so the card can show the result.No

What our servers see

Like any website, LockPad's servers and our hosting provider receive the IP address and browser user agent of each API request. We use these only to deliver the response, rate-limit abuse and keep the service secure, and we keep request logs for no more than 14 days. We do not build profiles, and we don't link API requests to LockPad accounts or wallets.

What the extension never does

  • Never asks for, reads, stores or sends seed phrases, private keys or passwords. It can't sign anything.
  • Never reads cookies, browsing history, other tabs or other websites. It only runs on x.com.
  • Never reads your clipboard. "Copy CA" only writes the address you clicked.
  • No analytics, no trackers, no ads, no affiliate links.
  • Never sells or shares data, and never uses it for advertising, credit or lending decisions.

Buying

Buy opens officiallockpad.com, where you review the purchase and approve it in your own wallet (for example Phantom or MetaMask). The tokens go to that wallet. To build the swap, the website may ask a routing service for a quote: Jupiter on Solana, and Uniswap on EVM chains. That request comes from the website when you review a buy, never from the extension, and includes the coin, the amount and your wallet address as the recipient. Blockchain transactions are public by nature. The website's privacy policy covers what happens there.

Sharing

We share data only with our hosting and CDN providers, who process API requests for us, and when the law requires it. Nobody else.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Children

The extension isn't for anyone under 18.

Changes

If we change how the extension handles data, we'll update this page and, for material changes, tell you in the extension before the change applies.

Contact

Questions or deletion requests: privacy@officiallockpad.com. Report fake LockPad extensions at officiallockpad.com/security.