HEXA Auto Bot — Chrome Extension
HEXA Auto Bot runs entirely in your browser. It does not have its own server, does not collect analytics, and does not sell or share your data with advertisers. The sections below list, plainly, every place data goes — including the AI providers and license system the extension talks to directly.
HEXA Auto Bot is a Chrome extension for X (Twitter) that can automatically like
posts and, optionally, post AI-generated replies — either while scrolling your
feed (Feed Mode) or on a specific list of post links you provide (Link Mode).
It only runs on twitter.com and x.com pages.
The following is saved using Chrome's built-in storage.local API,
inside your own browser. It is never transmitted to us, and is not accessible
to any website you visit.
All of this stays on your device and is deleted automatically if you remove the extension, or manually any time via Chrome's extension storage settings.
The extension talks directly to the following third parties, only when the related feature is switched on, and only over HTTPS:
If Auto Comment is on, the public text of the post being replied to — together with your own API key — is sent to whichever AI provider you've selected, solely to generate a reply suggestion. No private messages, account credentials, or browsing history are ever included.
| Provider | What's sent | Their privacy policy |
|---|---|---|
| OpenAI | Post text, your API key | openai.com/policies/privacy-policy |
| Anthropic | Post text, your API key | anthropic.com/legal/privacy |
| Google (Gemini API) | Post text, your API key | policies.google.com/privacy |
| Groq | Post text, your API key | groq.com/privacy-policy |
| Cohere | Post text, your API key | cohere.com/privacy |
| OpenRouter | Post text, your API key | openrouter.ai/privacy |
You choose the provider and supply your own key — you can turn Auto Comment off at any time to stop this entirely.
To activate the extension, the license key you enter is sent to our license database, hosted on Google Firebase (Firestore). This is used only to check that the key is valid, unexpired, and not already active on another device. We do not collect your name, email, or any other personal details as part of this check.
Liking a post and posting a reply happen the same way they would if you did it yourself — by interacting with the X (Twitter) page you're already signed into. The extension does not access your X password or session tokens directly; it operates the page's own buttons and reply box.
x.com/twitter.com — it has no access to any other site.HEXA Auto Bot is not directed at children and is not knowingly used to collect data from anyone under 13.
If this policy changes, the "Last updated" date at the top of this page will change too. Continued use of the extension after an update means you accept the revised policy.
Questions about this policy or how your data is handled? Contact our support bot: HEXA Support Bot .