Vanta Circle logo
VANTA CIRCLE
PRIVACY POLICY
X / TWITTER AUTOMATION

Your data, orbiting under control.

Vanta Circle is a Chrome extension for X (Twitter) automation. This page explains exactly what the extension touches, what it stores, and what it never does — in plain language.

Scroll
Effective date: August 23, 2026 Version: 2.0 Applies to: X/Twitter Automation — Powered by Vanta Circle
01 · Data we touch

What the extension reads on X

To auto-like and comment, the extension reads content directly from the X/Twitter page you have open — post text, links, and author handles visible in your feed. This happens locally in your browser tab.

Data typePurposeLeaves your device?
Post text on screenGenerate an AI comment relevant to the postYes — sent to your chosen AI provider only
Link URLs on screenLink Mode targeting & already-commented trackingNo
Extension settingsRemember your toggles, tone, and provider choiceNo — stored in Chrome local storage
License keyVerify your subscription is activeYes — sent to our Firebase project
No passwords collected No DMs read No browsing history tracked Never sold to third parties
02 · AI providers

How comment generation works

You choose which AI provider generates your comments — OpenRouter, Google Gemini, OpenAI, Anthropic, Groq, or Cohere. Whichever you pick receives only the specific post text needed to write a relevant reply, plus your custom tone instructions.

Your API key for that provider is stored locally in Chrome storage on your device. It is never transmitted to Vanta Circle's own servers — it goes directly from your browser to the provider you selected.

Switching providers, or turning automation off, immediately stops any further data from being sent to that provider.
03 · License & account

Firebase-backed license system

Your license key (format VC-XXXX-XXXX-XXXX) is checked against our Firebase/Firestore database each time the extension verifies access. We store the key, its activation status, and a device-bound identifier used only to prevent one key from running on unlimited installs.

  • We do not store your X/Twitter username or password.
  • We do not require you to log in to X through the extension.
  • Admin actions (ban, announce, key generation) are performed by us and are logged for support purposes only.
04 · Chrome permissions

Why the extension asks for these permissions

PermissionReason
activeTab / scripting / tabsRead and interact with the open X/Twitter tab to like posts and insert comments
storageSave your settings, license key, and provider keys locally
sidePanelDisplay bot controls in Chrome's side panel
powerPrevent your device from sleeping mid-session during long automation runs
Host access (x.com, twitter.com)Required for the content script to run automation on the page
Host access (AI provider & Firebase domains)Send requests for comment generation and license verification
05 · Works everywhere you do

Desktop and mobile Chrome

This policy applies identically whether you run the extension on desktop Chrome or on Chrome for Android/mobile browsers that support extensions. No separate mobile-only data is collected — the same local-storage and API-call model described above applies on every platform.

06 · Your rights

Control, delete, or export

  • Uninstalling the extension deletes all locally stored settings and keys from your device instantly.
  • You can request deletion of your license record from our Firebase database by contacting us below.
  • You can switch off automation or revoke an AI provider's API key at any time from the popup.
We never use your data to train AI models, and we never share it with advertisers.
07 · Changes to this policy

How you'll know if this changes

If this policy changes in a way that affects how your data is handled, the "Effective date" at the top of this page will update, and material changes will be announced through the extension's admin announcement panel.