how it actually works

The website is the remote control. The extension is the robot sitting in your own browser. X just sees you.

why a website alone cannot do this

Browsers will not let one website read another. A site on unfollowfa.st cannot reach into a tab open on x.com and read what is there, and a site on x.com cannot reach into ours. That wall is the security model the whole web is built on, not a limitation we ran into.

Which means without something else in the picture, our dashboard is blind. There is no server on our end fetching your following list, no X API being called, no password being asked for, and no account with us to sign up for.

what the extension is for

The extension is the one thing you can install that is allowed to work inside x.com tabs, and ours is written to work only there. When you press scan, the dashboard whispers to the extension over a private channel Chrome itself provides, one that only this website and this extension can use. The extension opens a fresh x.com tab of its own, never one of yours, already logged in as you because it is just your X in your own browser. It scrolls your following page and reads the names and handles off the screen, the same way your eyes would. Then it hands the list back over the same private channel, closes the tab it opened, and brings you back to the dashboard.

The data moves from one tab to another inside your browser. It never goes out over the internet to reach us.

dashboardunfollowfa.st, the page you are on
extensioninstalled in your browser
your x.com tablogged in as you

unfollowing, one click at a time

When you start a run, the extension visits each profile you picked and clicks the same unfollow button you would click yourself, at a human pace: 20 to 50 seconds apart, with a longer break every 10, capped at 600 in any rolling 24 hours per browser profile.

From X's point of view, it is you, clicking, in your own browser, on your own login. That is exactly why the tool never needs your password or an API key, and why it does not post, reply, like, or follow anything on your behalf.

why there are no profile pictures

Avatars live on X's own image servers. Showing them in the dashboard would mean the dashboard requests images from X, and doing that quietly tells X's servers that you are using this tool. So the list shows names and handles only, and the dashboard makes zero requests to X, ever.

what our server sees

It serves the page files, and that is all. Access logging for this site is switched off, so there is nothing else to see even if we wanted to look, because your following list never reaches us in the first place.

what is stored, and where

protect list and counter

Live in your own browser's extension storage. They stay there until you remove them or uninstall the extension.

the scanned list

Saved in your own browser's extension storage, so a page reload does not cost you a rescan. Replaced by your next scan, trimmed as accounts are unfollowed, and deleted if you uninstall the extension. It is never transmitted anywhere.

accounts picked for a run

Kept in extension storage only while that run is in progress, so it survives the page navigations the run itself performs. Cleared when the run ends, when you stop it, when you close the x.com tab, or the next time you start your browser.

the safety rules

human pacing

20 to 50 seconds between unfollows, plus a real break every 10.

rolling cap

600 in any 24 hours per browser profile, not a limit that resets at midnight.

581 of 600 left in the next 24h

protect list

Anyone you protect is never touched, even mid-run.

stop always works

Press stop and the run ends before the next click.

Read the privacy policy for the formal version of all this, or go straight to the dashboard and scan your following list.