Privacy Policy
BotFilterX ("we", "us") — website and Chrome extension. This page is the official privacy policy for https://www.botfilters.com.
Last updated: May 2, 2026
1. What we collect
When you use BotFilterX we may collect:
- Account data: Google sign-in gives us your Google account ID, email, name, and profile picture URL so we can create and maintain your account.
- X (Twitter) list data: When you run a scan, we process public profile information visible on follower or following pages (for example usernames, display names, and public counts shown on cards) to compute bot-risk scores and show results in your dashboard.
- Technical data: Standard server logs (for example IP address and user agent) for security, rate limiting, and operations.
- Optional API import: If you use our token-based HTTP import from your own scripts, we associate that traffic with your account using the token you generate in the dashboard.
2. How we use your data
- To authenticate you and keep you signed in (session cookie)
- To run bot-detection analysis on lists you choose to import
- To show audit results, exports, and subscription status in the product
- To process Pro subscription payments through our payment provider
3. What we do not collect
- We do not collect your X password or X direct messages
- We do not collect payment card numbers on our servers (handled by the payment provider)
- We do not sell your personal data
- We do not use your imported lists to train third-party AI models
4. Chrome extension
The BotFilterX extension requests these permissions:
- activeTab, tabs, scripting: to interact with x.com / twitter.com tabs you use when you start a scan, and to run optional automation flows you explicitly start from the dashboard (for example opening profiles in controlled tabs).
- windows: to run those optional flows in a dedicated window when applicable.
- Host access to x.com, twitter.com, and our own website (including www) so the extension can read public list UI on X, call our APIs with your existing browser sign-in session (
credentials: include), and relay messages between the dashboard and the extension where needed.
The extension does not require you to paste an API token for normal use; sign-in happens on our site and the same session is used when sending imports.
5. Third-party services
We use service providers to run the product, including:
- Google — OAuth sign-in
- Hosting (e.g. Vercel) — application hosting
- Database (e.g. Neon PostgreSQL) — storing account and audit data
- PayPal — Pro checkout and subscription payments where enabled
6. Data retention
We keep audit and account data while your account exists and as needed to provide the service. Session cookies expire after a limited period (see cookie settings on the site). You can request deletion of your account and associated data by contacting us as below.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Contact us to make a request.
8. Contact
For privacy questions or data requests, use the contact options on our site: Contacts (section on the home page), or write to us through the same domain: https://www.botfilters.com.