PRIVACY POLICY
Your data, orbiting under control.
Vanta Circle is a Chrome extension for X (Twitter) automation. This page explains exactly what the extension touches, what it stores, and what it never does — in plain language.
What the extension reads on X
To auto-like and comment, the extension reads content directly from the X/Twitter page you have open — post text, links, and author handles visible in your feed. This happens locally in your browser tab.
| Data type | Purpose | Leaves your device? |
|---|---|---|
| Post text on screen | Generate an AI comment relevant to the post | Yes — sent to your chosen AI provider only |
| Link URLs on screen | Link Mode targeting & already-commented tracking | No |
| Extension settings | Remember your toggles, tone, and provider choice | No — stored in Chrome local storage |
| License key | Verify your subscription is active | Yes — sent to our Firebase project |
How comment generation works
You choose which AI provider generates your comments — OpenRouter, Google Gemini, OpenAI, Anthropic, Groq, or Cohere. Whichever you pick receives only the specific post text needed to write a relevant reply, plus your custom tone instructions.
Your API key for that provider is stored locally in Chrome storage on your device. It is never transmitted to Vanta Circle's own servers — it goes directly from your browser to the provider you selected.
Firebase-backed license system
Your license key (format VC-XXXX-XXXX-XXXX) is checked against our Firebase/Firestore database each time the extension verifies access. We store the key, its activation status, and a device-bound identifier used only to prevent one key from running on unlimited installs.
- We do not store your X/Twitter username or password.
- We do not require you to log in to X through the extension.
- Admin actions (ban, announce, key generation) are performed by us and are logged for support purposes only.
Why the extension asks for these permissions
| Permission | Reason |
|---|---|
| activeTab / scripting / tabs | Read and interact with the open X/Twitter tab to like posts and insert comments |
| storage | Save your settings, license key, and provider keys locally |
| sidePanel | Display bot controls in Chrome's side panel |
| power | Prevent your device from sleeping mid-session during long automation runs |
| Host access (x.com, twitter.com) | Required for the content script to run automation on the page |
| Host access (AI provider & Firebase domains) | Send requests for comment generation and license verification |
Desktop and mobile Chrome
This policy applies identically whether you run the extension on desktop Chrome or on Chrome for Android/mobile browsers that support extensions. No separate mobile-only data is collected — the same local-storage and API-call model described above applies on every platform.
Control, delete, or export
- Uninstalling the extension deletes all locally stored settings and keys from your device instantly.
- You can request deletion of your license record from our Firebase database by contacting us below.
- You can switch off automation or revoke an AI provider's API key at any time from the popup.
How you'll know if this changes
If this policy changes in a way that affects how your data is handled, the "Effective date" at the top of this page will update, and material changes will be announced through the extension's admin announcement panel.