Privacy policy
Your data, plainly explained.
Last updated: August 29, 2026
1. What the extension does
Grok Automation is a Chrome extension that automates batch image and video generation on Grok Imagine. It lets you enter or import prompts, optionally add reference images, run those prompts through the Grok page open in your browser, monitor generation, and download finished images or videos to your computer.
2. User data collected or handled
| Data category | What is handled | How it is used | Where it is stored | Who receives it |
|---|---|---|---|---|
| Authentication information | Email address, Firebase user ID, Firebase ID token, email-verification state, and the basic profile returned for Google sign-in. For email/password sign-up, Firebase handles the password; the extension developer does not receive the plaintext password. | To sign you in to the extension, keep the extension session active, verify email status, and recognize the same extension account across sessions. | Google Firebase Authentication systems and browser IndexedDB used by the Firebase Web Extension SDK. | Google Firebase Authentication and Google OAuth services. |
| Personally identifiable information | Email address and, when Google sign-in is used, the display name and profile image URL returned by Google. | Only for extension sign-in and displaying the signed-in account in the side panel. | Google Firebase Authentication systems and browser IndexedDB. | Google Firebase Authentication and Google OAuth services. |
| User-provided and website content | Prompts typed into the side panel, prompts imported from supported files, optional reference images, generated media URLs, and generated images or videos returned by Grok. | To submit the generation jobs you request, monitor progress, associate outputs with prompts, create a local run report when enabled, and download results. | Prompt, queue, and imported-file content is handled locally by the extension while needed for the workflow. Generated downloads are stored in the browser download location you choose. | grok.com receives prompts and selected reference images when you start a run. Generated media is downloaded from Grok or its media hosts through your browser session. |
| Extension settings and local activity state | Selected mode, output settings, pacing and retry choices, wait limits, folder and filename preferences, interface language, welcome preference, resumable queue state, download recovery state, and cached compatibility configuration. | To remember your preferences, resume interrupted work, avoid duplicate downloads, and keep automation compatible with the current Grok page. | Browser extension storage on your device, including chrome.storage.local and temporary chrome.storage.session data. |
Settings and run state are not sent to the extension developer. Compatibility configuration requests go to the developer-operated Cloudflare Pages endpoint and do not attach prompts, files, generated media, email addresses, Firebase IDs, Grok credentials, or browsing history. |
| Current Grok tab and page state | The active Grok tab URL, Grok route, visible generation controls, progress indicators, and generated asset information. | To find or open the Grok Imagine tab, perform the workflow you start, detect completion, recover after Grok changes page, and download the correct outputs. | Processed locally in the browser. Temporary recovery state may be stored in extension storage. | Not sent to the extension developer. The extension does not collect general browsing history or inspect unrelated websites. |
3. Data not collected
- The extension does not collect general browsing history or monitor websites outside grok.com.
- The extension does not use analytics, telemetry, advertising SDKs, tracking pixels, or third-party behavioral tracking.
- The extension does not request, store, or transmit your Grok password or sign in to Grok on your behalf.
- The extension does not send prompts, reference images, generated files, settings, or download logs to a developer-operated analytics service.
- The extension does not collect location, health, financial, or personal communications data.
4. How data is collected
- Extension sign-in: you enter an email/password or start Google sign-in. Google Firebase Authentication and Google OAuth handle authentication.
- Prompt entry and import: you type prompts or select a supported prompt file. The extension reads the selected file locally to extract prompt text.
- Reference images: you select local images for workflows that use them. The extension stages those images on Grok only for the generation run you start.
- Grok automation: when you start a run, the extension applies your chosen settings, prompts, and images to grok.com using your existing browser session.
- Settings: when you change extension settings, they are saved in extension storage on your device.
5. User consent and control
Data handling begins only after you take the corresponding action: signing in, importing a prompt file, selecting reference images, changing settings, or starting a run. You can stop a run from the extension interface. Removing the extension stops further data handling by the extension.
6. How data is used
- Authentication information is used only to operate extension sign-in and maintain that session.
- Prompts, imported files, and reference images are used only for the Grok generation workflow you request.
- Grok page and generated asset information is used to monitor completion and identify the correct outputs.
- Folder and filename preferences are used only to organize generated files in your browser downloads.
- Settings, resume state, download-attempt state, and cached selector configuration are used only to operate the extension reliably.
7. Storage and retention
- Firebase Authentication: Firebase retains authentication records while the associated extension account exists, unless deleted earlier.
- Browser IndexedDB: Firebase stores a local sign-in session so you do not need to sign in every time.
- Extension storage: settings, preferences, resume state, and compatibility cache stay on your device until reset, extension data is cleared, or the extension is removed. Temporary session records expire when the browser session ends or when the extension clears them.
- Queue and run records: active and resumable run state is retained locally only as needed to operate or recover the workflow and can be cleared by removing extension data.
- Downloads: generated files remain in your chosen download location until you delete them.
8. Sharing and disclosure
The extension shares data only as needed to provide its stated functionality:
- Google Firebase Authentication and Google OAuth: receive authentication information when you sign in, create an extension account, sign out, verify email, reset a password, or refresh the session.
- grok.com: receives the prompts and reference images you choose to run and returns generated media under your existing Grok session.
- Developer-operated hosting: Cloudflare Pages serves this public privacy policy, the extension guide, and validated selector configuration data. Requests do not deliberately attach prompts, images, generated media, email addresses, Firebase IDs, Grok credentials, or browsing history. Like an ordinary HTTPS hosting provider, Cloudflare may process standard request metadata such as IP address, user agent, timestamp, and requested URL for security and delivery.
- Public disposable-email blocklist: the extension may download a plain-text list of disposable email domains from GitHub's raw-content service to validate extension account registration. Your email address is checked locally and is not sent to GitHub.
The extension does not sell or transfer user data to advertising networks, data brokers, analytics providers, or unrelated third parties.
9. Network requests
- Requests to grok.com, driven by the generation workflow you start in your existing Grok browser session.
- Requests to Google Firebase Authentication and Google OAuth hosts for extension sign-in and session management.
- Requests to grok-automation.pages.dev for versioned selector and compatibility configuration. This is JSON data, not executable code.
- Requests to raw.githubusercontent.com to retrieve a public plain-text disposable-email domain list. User email addresses are not included in these requests.
- Requests to www.deepakthapa.dev only when you choose to open the developer's public website.
10. Google API Limited Use disclosure
Grok Automation's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Security
- Network requests made by the extension use HTTPS.
- The extension does not put prompts, authentication tokens, or user identifiers in URLs sent to developer-operated endpoints.
- The extension does not execute remote code. Remote compatibility configuration is validated JSON data, and the disposable-email blocklist is plain text.
- Privileged automation and download actions are restricted to the extension's authorized run context.
12. User access and deletion
- You can sign out from the extension side panel.
- You can remove local settings and run state by clearing extension storage or removing the extension.
- You can delete generated files from your download location at any time.
- For access to or deletion of Firebase Authentication records associated with your extension account, contact the developer below.
13. Children's privacy
Grok Automation is intended for users aged 18 and older and does not knowingly collect personal information from children.
14. Changes to this policy
Changes to this policy will be posted at this URL with an updated effective date.
15. Contact
Questions, privacy requests, or account-deletion requests can be sent to thapadeepak726@gmail.com.