AutoBanRobot Privacy Policy
1. Scope and purpose
AutoBanRobot is a Chrome/Microsoft Edge browser extension and an iPhone application. Its purpose is to help a user identify and block suspected spam or promotion accounts on X (formerly Twitter), based on rules and keywords selected by that user. This policy explains the extension, the iPhone app, the optional AutoBanRobot account service, and the public AutoBanRobot Control Room at ban.richccy.com.
2. Data the extension handles
| X page data | While the user is on X, the extension or iPhone app reads post text, account handles, display names, post URLs, and page context needed to apply the user’s selected rules and request a block. It does not read other websites. |
|---|---|
| X session data | The extension or app uses the X Bearer token and CSRF token available in the user’s active X session only to make the user-requested X mute/block requests. These credentials remain in browser session storage or the app’s active WebKit session on the user’s device. They are not sent to AutoBanRobot’s server, sold, published, or used to access any account outside the user’s active X session. |
| Local settings | The extension or app stores user-added keywords, rule switches, whitelisted accounts, a random installation identifier, pending work, cumulative counters, and up to 1,000 recent local block-history records in browser extension storage or iPhone app storage. |
| Confirmed block event | After X confirms a block, the extension or app sends the blocked account handle and display name, matching reason and keywords, configured keyword list, matched post content, post URL, event time, client event identifier, random installation identifier, and client type to https://ban.richccy.com/api/bans. |
| Device and service data | The extension or app periodically sends its random installation identifier, platform label, version, and a generic device label to maintain service statistics. The server may derive an approximate city-level location from the request IP address for the public service map. |
| Optional account data | If the user creates an AutoBanRobot account, the service receives the chosen username, password, security-question selection and answer, device binding identifier, account session token, keywords, and whitelist needed for sign-in and cross-device settings sync. Passwords and security answers are stored only as one-way hashes; server-side session tokens are stored as hashes. |
3. How data is used and shared
- We use X page and session data locally to apply the user’s selected rules and to carry out the user-facing block/mute feature.
- We use confirmed block events to operate the live list, rule/keyword analytics, promotion-target-account analysis, de-duplication, and the optional cross-device account features.
- Confirmed block records, including blocked account information, matching reason, content summary or content, post URL, and time, are displayed in the public AutoBanRobot Control Room. Do not use the extension if you do not want confirmed block events to be shared there.
- We do not sell user data, use it for personalized, retargeted, or interest-based advertising, or allow human review of X session credentials. We do not transfer X session credentials to third parties.
- Data is disclosed only to operate the stated service, comply with law, protect security or abuse investigations, or as part of a corporate transaction permitted by applicable law. We do not use data for unrelated purposes.
4. Retention, choices, and deletion
Local extension or app data remains on the user’s device until the user clears it, signs out, deletes the AutoBanRobot account, or removes the extension or app. The local history is capped at 1,000 records. Server records are retained while needed to operate the public list, analytics, account synchronization, security, and legal obligations; the service does not currently apply a fixed automatic deletion period.
Users may disable rules, remove keywords, clear local history, sign out, or remove the extension or app at any time. A registered iPhone app user can initiate permanent account deletion in Account → Delete account. This deletes the server account, account session, synced keywords and whitelist, device bindings, contribution records, client records, and confirmed block records associated with that account or its linked installation identifiers. The app also clears its local account-related data and rotates its installation identifier. The action cannot be undone. Limited information may be retained only where required by law.
5. Security
AutoBanRobot transmits service data over HTTPS. X credentials used for block actions remain in the browser’s session storage and are not included in AutoBanRobot server requests. No method of transmission or storage is completely secure, but we use reasonable technical safeguards appropriate to the service.
6. Children and changes
AutoBanRobot is not directed to children. We may update this policy when the extension or service changes. Material changes will be posted on this page with a revised effective date and, where required, disclosed in the extension before new data practices begin.
7. Chrome Web Store data use
AutoBanRobot uses data only to provide or improve its spam-account identification, X block/mute, optional synchronization, and safety analytics features. It does not sell user data or use it for advertising. This policy is intended to describe the extension’s compliance with the Chrome Web Store User Data Policy and its Limited Use requirements.
隐私政策(简体中文)
生效日期:2026 年 8 月 17 日;最后更新:2026 年 8 月 17 日。
1. 适用范围与用途
AutoBanRobot 是适用于 Chrome、Microsoft Edge 的浏览器扩展及 iPhone 应用。它的用途是依据用户选择的规则和关键词,协助识别并在 X(原 Twitter)上屏蔽疑似垃圾推广账号。本政策适用于扩展、iPhone 应用、可选的 AutoBanRobot 账号服务,以及 ban.richccy.com 上的公开控制台。
2. 处理的数据
- X 页面数据:扩展或 iPhone 应用仅在 X 页面读取帖子文字、账号 ID、显示名、帖子链接和规则判断所需页面上下文,不会读取其他网站。
- X 会话数据:扩展或应用在用户当前 X 会话中使用 Bearer Token 与 CSRF Token,仅用于执行用户所需的 X 静音/屏蔽请求。这些凭据只保存在浏览器会话存储或应用当前 WebKit 会话中,不会上传到 AutoBanRobot 服务器、出售或公开。
- 本地设置:关键词、规则开关、白名单、随机安装标识、待处理任务、累计数和最近最多 1,000 条本地屏蔽历史保存在浏览器扩展存储或 iPhone 应用存储中。
- 确认屏蔽记录:X 确认屏蔽成功后,扩展或应用会向服务端上传目标账号 ID/显示名、命中原因和关键词、当前设置的关键词、命中的帖子内容、帖子链接、时间、客户端事件标识、随机安装标识和客户端类型。
- 设备与服务数据:扩展或应用会定期发送随机安装标识、平台、版本和通用设备名称以统计服务使用情况。服务端可能根据请求 IP 推导大致城市级位置用于公开服务地图。
- 可选账号数据:若用户注册 AutoBanRobot 账号,服务会处理用户名、密码、安全问题及答案、设备绑定标识、会话令牌、关键词和白名单,以完成登录和跨设备同步。密码、安全问题答案和服务端会话令牌均以哈希形式保存。
3. 使用与公开方式
- 页面与会话数据仅在本地用于规则判断以及用户可见的静音/屏蔽功能。
- 确认屏蔽记录用于实时清单、规则与关键词分析、推广目标账号分析、去重和可选的跨设备同步。
- 确认屏蔽记录会公开展示在 AutoBanRobot 控制台中,可能包含目标账号、命中原因、内容摘要或内容、帖子链接和时间。若不希望此类记录公开,请不要使用自动上传功能。
- 我们不会出售用户数据,不会用于个性化、再营销或兴趣广告,也不会允许人工查看 X 会话凭据。
- 仅在提供本服务、遵守法律、处理安全/滥用问题或法律允许的公司交易所必需时共享数据,不作无关用途。
4. 保存、控制与删除
本地数据会保留至用户清除、退出账号、删除 AutoBanRobot 账号或移除扩展/应用;本地历史最多保存 1,000 条。服务端记录会在运营公开清单、分析、账号同步、安全和履行法律义务所需期间保存,目前没有固定的自动删除周期。
用户可以随时关闭规则、删除关键词、清空本地历史、退出账号或移除扩展/应用。已注册的 iPhone 应用用户可在账号 → 删除账号中发起永久删除:服务端账号、会话、同步的关键词和白名单、设备绑定、贡献记录、客户端记录,以及与该账号或其绑定安装标识关联的确认屏蔽记录都会被删除;应用也会清除本机账号相关数据并更换安装标识。删除不可恢复。仅在法律要求时,才可能保留有限信息。
5. 安全、未成年人与政策更新
服务数据使用 HTTPS 传输;用于 X 操作的会话凭据不会出现在 AutoBanRobot 服务端请求中。AutoBanRobot 不面向儿童。若产品或数据处理方式发生变化,我们会更新本页;如法律或 Chrome 政策要求,会在新数据处理开始前于扩展内显著说明并取得同意。
6. Chrome 网上应用店数据使用声明
AutoBanRobot 仅为提供或改进垃圾推广账号识别、X 静音/屏蔽、可选同步和安全分析功能而使用数据;不出售用户数据,也不用于广告。本政策说明了扩展对 Chrome 网上应用店用户数据政策及有限使用要求的遵守方式。