x frame.
A FRAME. NOT A DISGUISE.

Always know
where you’re going.

The player shows the current destination domain. Experiences remain hosted by their owners. Private browsing opens the original page in a separate temporary browser and streams its pixels into X Frame. It preserves the website’s security headers and normal TLS verification. The original-site arrow stays available.

What is saved.

Frame records contain the target URL, domain, extracted title and description, scan results, and timestamps. A URL may contain sensitive query parameters; remove private tokens before submitting it. Saved frames belong to a private browser library. A signed, HttpOnly cookie identifies that library for 30 days. Clearing cookies removes access; it is not a cross-device account.

Private browser sessions.

Each visitor starts with a separate browser profile. Clicks, scrolling, typed input, and browser images pass through the browser service while you use it. X Frame does not save the stream or typed text. Profiles are deleted when the session ends, with a 20-minute maximum and automatic closure after disconnecting. These browsers do not contain your existing logins or extension wallets. Use the original website for local browser features, downloads, or uploads.

Aggregate activity.

We count frame views, launch actions, SDK signals, and reported loading failures by frame and UTC day. Client events are not proof of play or successful load. We do not collect X impression data or use advertising trackers. The hosting provider may maintain its own operational logs.

Abuse prevention.

The inspector accepts public HTTPS domains, validates DNS results, pins public addresses, revalidates redirects, and enforces resource limits. Rate-limit identifiers use a keyed hash instead of storing the visitor’s raw IP address in our application tables. Domain blocklists are configurable. Reports are stored for operator review; they do not instantly adjudicate a website.

Reputation is separate.

Unless a result explicitly says reputation was checked, no third-party reputation provider has evaluated it. The inspector includes an optional Google Web Risk adapter. Passing a compatibility check is not an endorsement of a destination.

Report a frame.

Use “Report this experience” in the launcher to report phishing, malware, or other abuse. The report is retained with its frame so it can be reviewed.