Privacy Policy

HEXA Auto Bot — Chrome Extension

Last updated: July 09, 2026

HEXA Auto Bot runs entirely in your browser. It does not have its own server, does not collect analytics, and does not sell or share your data with advertisers. The sections below list, plainly, every place data goes — including the AI providers and license system the extension talks to directly.

1. What this extension does

HEXA Auto Bot is a Chrome extension for X (Twitter) that can automatically like posts and, optionally, post AI-generated replies — either while scrolling your feed (Feed Mode) or on a specific list of post links you provide (Link Mode). It only runs on twitter.com and x.com pages.

2. Data stored locally on your device

The following is saved using Chrome's built-in storage.local API, inside your own browser. It is never transmitted to us, and is not accessible to any website you visit.

All of this stays on your device and is deleted automatically if you remove the extension, or manually any time via Chrome's extension storage settings.

3. Data sent to other services

The extension talks directly to the following third parties, only when the related feature is switched on, and only over HTTPS:

AI reply generation

If Auto Comment is on, the public text of the post being replied to — together with your own API key — is sent to whichever AI provider you've selected, solely to generate a reply suggestion. No private messages, account credentials, or browsing history are ever included.

ProviderWhat's sentTheir privacy policy
OpenAIPost text, your API keyopenai.com/policies/privacy-policy
AnthropicPost text, your API keyanthropic.com/legal/privacy
Google (Gemini API)Post text, your API keypolicies.google.com/privacy
GroqPost text, your API keygroq.com/privacy-policy
CoherePost text, your API keycohere.com/privacy
OpenRouterPost text, your API keyopenrouter.ai/privacy

You choose the provider and supply your own key — you can turn Auto Comment off at any time to stop this entirely.

License activation Google Firebase

To activate the extension, the license key you enter is sent to our license database, hosted on Google Firebase (Firestore). This is used only to check that the key is valid, unexpired, and not already active on another device. We do not collect your name, email, or any other personal details as part of this check.

Posting actions

Liking a post and posting a reply happen the same way they would if you did it yourself — by interacting with the X (Twitter) page you're already signed into. The extension does not access your X password or session tokens directly; it operates the page's own buttons and reply box.

4. What we don't do

5. Your choices

6. Children's privacy

HEXA Auto Bot is not directed at children and is not knowingly used to collect data from anyone under 13.

7. Changes to this policy

If this policy changes, the "Last updated" date at the top of this page will change too. Continued use of the extension after an update means you accept the revised policy.

8. Contact

Questions about this policy or how your data is handled? Contact our support bot: HEXA Support Bot .