Mastros is a family of read-only Chrome extensions that export data from Telegram Web, WhatsApp Web, LinkedIn, Instagram and TikTok into files on your computer. Safe, for an extension, means four checkable things: it asks only for the permissions its job needs, the data it exports never leaves your browser, it never acts on your account, and it never sees a password. This post lists each of those for each extension, and ends with how to verify them yourself rather than take our word.
I write the software, so read this as a description you can test. The privacy policy for each extension is the legal version; every product page, from the Telegram scraper to the TikTok scraper, repeats the same claims because they are the same architecture.
What permissions does each extension ask for, and why?
Chrome shows the permissions at install. Here is each one, per extension, with the reason.
| Permission | Telegram | TikTok | Why | |||
|---|---|---|---|---|---|---|
| Host access to the one platform site | web.telegram.org |
web.whatsapp.com |
LinkedIn pages | www.instagram.com |
www.tiktok.com |
To read the page and the data the platform's own app already loaded. Nothing else you visit. |
| Platform media hosts | No | No | No | No | TikTok's CDN hosts | To fetch a video you chose to download from where TikTok serves it. |
storage |
Yes | Yes | Yes, plus IndexedDB | Yes | Yes | Settings, quota counters, resumable run state, kept locally. |
downloads |
No | No | No | Yes | Yes | To write media files you asked for to your computer. |
identity |
Yes, returns no email | Yes | Yes, may read the Chrome profile email | Yes, optional | Yes, optional | To recognise your licence across devices. Without it you fall back to an anonymous install ID. |
alarms |
No | No | No | One five-minute timer | Yes | To re-sync plan and quota, and on TikTok to pace long runs. |
| Mastros licence service | Yes | Yes | Yes | Yes | Yes | Account, quota and billing state. Holds counts, never rows. |
What is not on that list matters as much: no access to all websites, no access to your tabs or history, no clipboard, no webcam, no native messaging, no ability to read any site but the one each extension is for.
What leaves your browser?
Three things, and none of them is your data.
- Licence and quota sync. The extension tells the Mastros licence service which plan you are on and how many records you have used this month, so limits and upgrades apply. Counts, not content.
- Billing. If you subscribe, card details go to Stripe directly. Mastros never sees or stores them.
- Anonymised telemetry. Feature usage and error counts go to PostHog's EU region so we can see what breaks. No name, no handle, no message, no row you exported, and no personally identifiable information.
What never leaves: the members, messages, contacts, comments, profiles and media you export. They are read in your browser and written to your disk. There is no Mastros server in the data path, which is why we can say we could not hand your member list to anyone: no copy exists to hand over.
What will it never do to your account?
- Send anything. No messages, no broadcasts, no auto-replies, no invites, no InMails, no comments, no follows or likes. Every extension only reads. Automated sending is what gets accounts limited, and it is designed out rather than left as a setting.
- Ask for a password or cookies. Each extension works inside the session you are already signed into. A tool that asks you to log in inside it has your account; Mastros never does.
- Use an API key. No
api_id, noapi_hash, no developer app. It reads what the platform's own web app loaded for you. - Reveal hidden data. Phone numbers appear only where the platform shows them to your account. It never guesses, buys or verifies an email address.
- Run in the background. Every run is started by you, in a tab you keep open. There is no scheduler.
- Hammer the platform. Telegram's and Instagram's rate-limit responses are honoured by waiting; on TikTok the extension reads the requests the page already made and adds none of its own.
What do the store listings say?
Public Chrome Web Store ratings as of 2 September 2026, the same figures the product pages publish:
| Extension | Rating |
|---|---|
| Mastros for Telegram | 4.9 from 71 reviews |
| Mastros for WhatsApp | 5.0 from 47 reviews |
| Mastros for LinkedIn | 5.0 from 34 reviews |
| Mastros for Instagram | No rating yet; launched 26 August 2026 |
| Mastros for TikTok | No rating yet; launched 30 August 2026 |
Small numbers, stated plainly. A 4.9 from 71 is a signal; a 5.0 from 34 says nobody has been badly disappointed yet and not much more. The listings also carry Google's privacy-practices disclosure, which is the same information as the table above in Google's format.
How can I verify this myself?
Do not take any of it on trust. Four checks, ten minutes.
- Read the permissions at install. Chrome lists them before you confirm. Compare with the table above; anything extra is a reason to stop.
- Watch the Network tab during an export. Open Chrome DevTools (F12), choose Network, run an export, and read the request list. You should see requests to the platform's own domain, one or two to the Mastros licence service carrying counts, and telemetry to PostHog. Click any request to the licence service and read its payload: numbers and identifiers, no rows.
- Check the file lands locally. The CSV or ZIP appears in your Downloads folder, written by the browser. No upload preceded it; the Network tab shows none.
- Read the privacy policy. Each extension's policy on /privacy names every permission, every processor (Cloudflare, Stripe, PostHog, Google) and what each receives.
If any of those four disagrees with this post, that is a bug, and the support page is where to say so.
Who this is not for
- Anyone looking for a tool that automates outreach and wants reassurance that it is safe. No sending tool is safe for the account it runs on, and Mastros is not one.
- Anyone who wants to reach data the platform hides: hidden numbers, private accounts, deleted messages, login emails. Mastros does not, and a tool that claims to is the one to be suspicious of.
- Anyone who needs a signed security assessment for procurement. The architecture is simple enough to audit from the Network tab, but a formal report is not something we publish.
FAQ
Is Mastros safe to install?
It requests host access to one platform site per extension plus storage, identity and, where it downloads media, the downloads permission. It exports in your browser to your disk, never acts on your account, and never asks for a password. The Network tab during an export shows exactly what leaves.
Does Mastros need my password?
No. Each extension works inside the session you are already signed into on the platform's own website. It never asks for a password or cookies, and a tool that does has your account.
Does my exported data go to Mastros servers?
No. Extraction and file writing happen in your browser. The server holds account, quota and billing state, which are counts, and receives anonymised telemetry with no personal data and no exported rows.
Can Mastros get my account banned?
It reads only, sends nothing, and honours the platforms' rate limits. That removes the usual causes of a ban rather than changing the platforms' terms, which you remain responsible for. Mastros is not affiliated with or endorsed by Telegram, Meta, LinkedIn, ByteDance or TikTok.
What does the identity permission do?
It lets the extension recognise your licence across devices. On Telegram and WhatsApp it returns no email address. On Instagram and TikTok it is optional; without it you get an anonymous install ID. On LinkedIn it may read the Chrome profile email to associate the account and restore purchases.
Related reading
- Privacy Policy: the per-extension policy with every permission and processor named.
- Privacy-First Chat Data Extraction: why processing in the browser is the whole argument.
- Telegram Scraper · WhatsApp Scraper · LinkedIn Scraper · Instagram Scraper · TikTok Scraper
