AutoBanRobot Privacy Policy
1. Scope and purpose
AutoBanRobot is a browser extension for Chrome and Microsoft Edge. Its single purpose is to help a user identify and block suspected spam or promotion accounts on X (formerly Twitter), based on rules and keywords selected by that user. This policy explains the extension, the optional AutoBanRobot account service, and the public AutoBanRobot Control Room at ban.richccy.com.
2. Data the extension handles
| X page data | While the user is on X, the extension reads post text, account handles, display names, post URLs, and page context needed to apply the user’s selected rules and request a block. It does not read other websites. |
|---|---|
| X session data | The extension reads the X Bearer token and CSRF token available in the user’s active X session only to make the user-requested X mute/block requests. These credentials are kept in Chrome session storage on the user’s device. They are not sent to AutoBanRobot’s server, sold, published, or used to access any account outside the user’s active X session. |
| Local settings | The extension stores user-added keywords, rule switches, whitelisted accounts, a random installation identifier, pending work, cumulative counters, and up to 1,000 recent local block-history records in Chrome extension storage. |
| Confirmed block event | After X confirms a block, the extension sends the blocked account handle and display name, matching reason and keywords, configured keyword list, matched post content, post URL, event time, client event identifier, random installation identifier, and client type to https://ban.richccy.com/api/bans. |
| Device and service data | The extension periodically sends its random installation identifier, browser/platform label, extension version, and a generic device label such as “Chrome on macOS” to maintain anonymous service statistics. The server may derive an approximate city-level location from the request IP address for the public service map. |
| Optional account data | If the user creates an AutoBanRobot account, the service receives the chosen username, password, security-question selection and answer, device binding identifier, account session token, keywords, and whitelist needed for sign-in and cross-device settings sync. Passwords and security answers are stored only as one-way hashes; server-side session tokens are stored as hashes. |
3. How data is used and shared
- We use X page and session data locally to apply the user’s selected rules and to carry out the user-facing block/mute feature.
- We use confirmed block events to operate the live list, rule/keyword analytics, promotion-target-account analysis, de-duplication, and the optional cross-device account features.
- Confirmed block records, including blocked account information, matching reason, content summary or content, post URL, and time, are displayed in the public AutoBanRobot Control Room. Do not use the extension if you do not want confirmed block events to be shared there.
- We do not sell user data, use it for personalized, retargeted, or interest-based advertising, or allow human review of X session credentials. We do not transfer X session credentials to third parties.
- Data is disclosed only to operate the stated service, comply with law, protect security or abuse investigations, or as part of a corporate transaction permitted by applicable law. We do not use data for unrelated purposes.
4. Retention, choices, and deletion
Local extension data remains on the user’s device until the user clears it in the extension, signs out (which removes the optional account session), or removes the extension. The local history is capped at 1,000 records. Server records are retained while needed to operate the public list, analytics, account synchronization, security, and legal obligations; the service does not currently apply a fixed automatic deletion period.
Users may disable rules, remove keywords, clear local history, sign out, or remove the extension at any time. To request deletion of optional account data or server records associated with an installation or account, contact the developer through the support contact shown on the Chrome Web Store listing and include the relevant AutoBanRobot account name or installation identifier where available. We may need to retain limited records where required for security, fraud prevention, or law.
5. Security
AutoBanRobot transmits service data over HTTPS. X credentials used for block actions remain in the browser’s session storage and are not included in AutoBanRobot server requests. No method of transmission or storage is completely secure, but we use reasonable technical safeguards appropriate to the service.
6. Children and changes
AutoBanRobot is not directed to children. We may update this policy when the extension or service changes. Material changes will be posted on this page with a revised effective date and, where required, disclosed in the extension before new data practices begin.
7. Chrome Web Store data use
AutoBanRobot uses data only to provide or improve its spam-account identification, X block/mute, optional synchronization, and safety analytics features. It does not sell user data or use it for advertising. This policy is intended to describe the extension’s compliance with the Chrome Web Store User Data Policy and its Limited Use requirements.
隐私政策(简体中文)
生效日期:2026 年 8 月 10 日;最后更新:2026 年 8 月 10 日。
1. 适用范围与用途
AutoBanRobot 是适用于 Chrome 和 Microsoft Edge 的浏览器扩展。它的唯一用途是依据用户选择的规则和关键词,协助识别并在 X(原 Twitter)上屏蔽疑似垃圾推广账号。本政策适用于扩展、可选的 AutoBanRobot 账号服务,以及 ban.richccy.com 上的公开控制台。
2. 处理的数据
- X 页面数据:扩展仅在 X 页面读取帖子文字、账号 ID、显示名、帖子链接和规则判断所需页面上下文,不会读取其他网站。
- X 会话数据:扩展在用户当前 X 会话中读取 Bearer Token 与 CSRF Token,仅用于执行用户所需的 X 静音/屏蔽请求。这些凭据只保存在浏览器的会话存储中,不会上传到 AutoBanRobot 服务器、出售或公开。
- 本地设置:关键词、规则开关、白名单、随机安装标识、待处理任务、累计数和最近最多 1,000 条本地屏蔽历史保存在浏览器扩展存储中。
- 确认屏蔽记录:X 确认屏蔽成功后,扩展会向服务端上传目标账号 ID/显示名、命中原因和关键词、当前设置的关键词、命中的帖子内容、帖子链接、时间、客户端事件标识、随机安装标识和客户端类型。
- 设备与服务数据:扩展会定期发送随机安装标识、浏览器/平台、扩展版本和通用设备名称(例如“Chrome on macOS”)以统计服务使用情况。服务端可能根据请求 IP 推导大致城市级位置用于公开服务地图。
- 可选账号数据:若用户注册 AutoBanRobot 账号,服务会处理用户名、密码、安全问题及答案、设备绑定标识、会话令牌、关键词和白名单,以完成登录和跨设备同步。密码、安全问题答案和服务端会话令牌均以哈希形式保存。
3. 使用与公开方式
- 页面与会话数据仅在本地用于规则判断以及用户可见的静音/屏蔽功能。
- 确认屏蔽记录用于实时清单、规则与关键词分析、推广目标账号分析、去重和可选的跨设备同步。
- 确认屏蔽记录会公开展示在 AutoBanRobot 控制台中,可能包含目标账号、命中原因、内容摘要或内容、帖子链接和时间。若不希望此类记录公开,请不要使用自动上传功能。
- 我们不会出售用户数据,不会用于个性化、再营销或兴趣广告,也不会允许人工查看 X 会话凭据。
- 仅在提供本服务、遵守法律、处理安全/滥用问题或法律允许的公司交易所必需时共享数据,不作无关用途。
4. 保存、控制与删除
本地数据会保留至用户在扩展中清除、退出账号或移除扩展;本地历史最多保存 1,000 条。服务端记录会在运营公开清单、分析、账号同步、安全和履行法律义务所需期间保存,目前没有固定的自动删除周期。
用户可以随时关闭规则、删除关键词、清空本地历史、退出账号或移除扩展。如需请求删除可选账号数据或与某安装标识/账号相关的服务端记录,请通过 Chrome 网上应用店详情页显示的支持联系方式联系开发者,并提供可识别的 AutoBanRobot 账号名或安装标识。出于安全、防欺诈或法律要求,部分记录可能需要保留。
5. 安全、未成年人与政策更新
服务数据使用 HTTPS 传输;用于 X 操作的会话凭据不会出现在 AutoBanRobot 服务端请求中。AutoBanRobot 不面向儿童。若产品或数据处理方式发生变化,我们会更新本页;如法律或 Chrome 政策要求,会在新数据处理开始前于扩展内显著说明并取得同意。
6. Chrome 网上应用店数据使用声明
AutoBanRobot 仅为提供或改进垃圾推广账号识别、X 静音/屏蔽、可选同步和安全分析功能而使用数据;不出售用户数据,也不用于广告。本政策说明了扩展对 Chrome 网上应用店用户数据政策及有限使用要求的遵守方式。