Last updated: August 9, 2026
This Privacy Policy describes how Bot-Hound and its proprietor (“Bot-Hound,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the Bot-Hound service at bot-hound.com (the “Service”). By using the Service, you agree to the collection and use of information as described in this Privacy Policy.
The Service consists of:
This policy covers Bot Check. The sections below say which data applies.
In this policy, “you” refers to anyone using the Service, with or without an account. Most of the Service needs no account: you can run a check, and pay for one, without signing in. A “target account” is the public 𝕏 account being checked. A target account may or may not be a Bot-Hound user.
The Service is intended for users in the United States who are at least 18 years of age. Please review our Terms of Service for eligibility requirements.
𝕏 (Twitter) OAuth. When you connect your 𝕏 account, we receive and store:
To run a Bot Check, we request identity-only access (users.read, tweet.read). This lets us identify your account and nothing more. We do not request access to your followers list, and we do not receive a refresh token — so our access ends when the short-lived access token expires.
Email sign-in. You can instead create an account with an email address. We email you a sign-in link, and we store:
An email account is a place to hold a prepaid balance and your report history. We do not use your email address for marketing, and we do not share it with anyone outside the providers listed in Section 4.
You do not need an account to use the Service. The first check is free, and after that you can pay for a single check without signing in. To make that work we use your IP address:
We do not use IP addresses to build a profile of you, to track you across sites, or to target advertising.
When you make a payment (a Bot Check purchase or prepaid top-up), the following information is collected by Stripe during checkout and shared with us:
We do not receive or store your payment card details. If you add funds to your prepaid balance, we store the balance amount associated with your account.
When you run a Bot Check on a target account, we collect and process publicly available information about that account itself. We do not collect its followers.
A Bot Check may be run by anyone, with or without an account, against any public 𝕏 account. The target account does not need to be a Bot-Hound user and is not notified when it is checked. Protected (private) accounts cannot be checked.
Through the bot classification process, we generate and store:
When you log in, we create a session identified by a cryptographically random token. It is stored as an HttpOnly, Secure, SameSite=Lax cookie named bh_session, set directly by our API server and readable only by it. Sessions expire after 30 days.
If you purchase or run a report, we also set an HttpOnly, Secure, SameSite=Lax cookie named bh_purchaser, which holds random access tokens for the reports you have paid for. It lets you return to those reports without logging in, and expires after 90 days. It contains no personal information. If you have no account, this cookie and the report’s URL are the only things tying you to a report you bought — clear the cookie and lose the link, and we have no way to identify the report as yours.
Both cookies are host-only: they are scoped to the single API hostname that set them and are not shared with any other subdomain. Neither cookie is used for advertising or tracking.
We use Google Analytics and Cloudflare Web Analytics to collect aggregated usage data, including:
_ga, _ga_*) on your device to distinguish unique users and sessions._gcl_au, _gcl_aw) on your device to attribute conversions (such as sign-ups) to specific ads. No personal information from your Bot-Hound account is shared with Google Ads.We use Google Ads conversion cookies solely to measure advertising effectiveness (see Section 4). We do not sell data to third-party advertisers.
To classify accounts as potential bots, we send the following information to xAI’s Grok large language model API:
The data sent to xAI is the target account’s own profile, tweets, and profile image — not its followers, and not the person requesting the check.
xAI’s use of this data is governed by xAI’s privacy policy.
We make API calls to the 𝕏 platform (directly or via a third-party 𝕏 data provider) to fetch a target account’s own public profile and recent tweets for a Bot Check, and we download its public profile image from 𝕏’s image servers.
The Service is hosted on Amazon Web Services (AWS). Your data is processed and stored on AWS infrastructure in accordance with AWS’s privacy practices.
We use Stripe, Inc. to process all payments (Bot Check purchases and prepaid balance top-ups). Stripe collects your payment information and email address directly. Stripe shares your email address with us so we can send billing-related notifications. We do not receive or store your payment card details. Stripe’s use of your data is governed by Stripe’s Privacy Policy.
We attach a small amount of our own metadata to each checkout session so the payment can be matched back to what it bought: the report identifier, the purchase type, your Bot-Hound user ID if you have an account, the IP address the purchase was started from, and your Google Analytics client ID if your browser supplied one. The IP address is included so a disputed or fraudulent payment can be traced, which matters most for purchases made without an account.
We use Google Analytics, a web analytics service provided by Google LLC, to understand how visitors interact with the Service. Google Analytics uses cookies to collect information such as how often users visit the site, what pages they visit, and what other sites they visited prior to coming to the Service. We use the information from Google Analytics only to improve the Service. Google Analytics collects the IP address assigned to you on the date you visit the Service, but we do not combine this with other data we maintain about you.
Purchase events sent from our servers. We also report completed purchases to Google Analytics directly from our backend, using Google’s Measurement Protocol. Your browser is not involved: Stripe redirects you away to pay, and the confirmation arrives at our server, so a browser-side event would miss most sales. Each purchase event contains only:
_ga cookie, which your browser passes to us when you start checkout, so the sale is attributed to the visit that produced it. If we do not have one, a random identifier is generated for that event instead.These events do not contain your name, email address, IP address, 𝕏 account, or the handle you checked.
Google’s ability to use and share information collected by Google Analytics about your visits to the Service is restricted by the Google Analytics Terms of Service and the Google Privacy Policy. You can learn more about how Google collects and processes data at How Google uses information from sites or apps that use our services.
Opting out. The Google Analytics Opt-out Browser Add-on, and browser-level analytics blocking, stop the browser-side collection described above. They do not stop the server-side purchase event, because it is sent from our backend rather than from your browser. With analytics blocked there is no _ga cookie for us to read, so the event is sent under a random identifier and is not linked to your browsing. The event is not sent at all when a payment is refunded immediately because the check could not be started.
We use Google Ads conversion tracking, a service provided by Google LLC, to measure the effectiveness of our advertising campaigns. When you visit Bot-Hound after clicking a Google ad, Google Ads may set cookies on your device to attribute your visit or sign-up to that ad. The information collected is aggregated and does not include your Bot-Hound account data, 𝕏 credentials, or follower information. Google’s use of this data is governed by the Google Privacy Policy. You can opt out of personalized advertising by visiting Google Ads Settings.
We use Cloudflare Web Analytics, a privacy-first analytics service provided by Cloudflare, Inc. Cloudflare Web Analytics does not use cookies or collect personally identifiable information. It collects aggregated, anonymous data about page views and visits. Cloudflare’s use of this data is governed by Cloudflare’s Privacy Policy.
Bot-Hound maintains a shared cache so that an account already analyzed does not need to be re-analyzed. The cache is shared across all users: a verdict produced for one user’s check may be reused when serving another user’s request, and vice versa. Cache entries are keyed only to the analyzed 𝕏 account — they do not record who requested the analysis.
There is one cache: the Bot Check verdict cache — stores the verdict for a checked account (bot probability, confidence band, reasons, avatar description, display name, and profile image URL), keyed by username. Entries expire automatically after 7 days, after which the account is re-analyzed if checked again.
If you are the owner of an analyzed account and want its cached classification removed, contact us at [email protected].
Bot Check analyzes publicly available data from public 𝕏 accounts. When a target account is analyzed:
A Bot Check produces an AI-generated verdict — including a bot probability score and written reasons — about the target account itself, and that verdict can be viewed by anyone with the report’s URL (see Section 7). Verdicts are automated estimates and may be wrong.
There is no automatic opt-out for public accounts, as we process only data that is already publicly available on 𝕏. However, every completed Bot Check verdict links to our X account, @BotHound_: to dispute a verdict about your account or request a takedown, tag or DM @BotHound_, or email us at [email protected]. If we take a report offline, the public report page then shows only an “under review” notice, with no score, band, or reasons. You may also contact us at [email protected] to request permanent removal of a report about your account, or deletion of its cached classification. We review such requests in good faith. Taking a report offline affects only the report page we host; we cannot remove copies cached elsewhere, such as a social-media link preview or a screenshot already posted.
Reports are associated with the purchaser via a purchaser token stored in the bh_purchaser cookie, and with a Bot-Hound account if the purchaser had one. Reports may be accessed by:
Completed Bot Check verdicts are public to anyone holding the URL. No login, account, or purchaser token is required to view a finished verdict — the report page displays the checked account’s username, display name, profile image, bot probability, confidence band, and the AI-generated reasons. Report URLs contain a long random identifier and are not listed or indexed by us, but they are not otherwise access-controlled. Treat a report URL as a shareable link: anyone you send it to can read the verdict, and so can anyone they forward it to.
We log access to reports for security and abuse prevention purposes. We do not control how purchasers distribute report URLs and are not responsible for downstream use of shared report data.
We implement the following security measures to protect your information:
While we take reasonable measures to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of your data.
| Data type | Retention period |
|---|---|
| Bot Check verdict cache | 7 days (automatic expiry) |
| Session data | 30 days (automatic expiry) |
| Email sign-in link tokens (hashed) | 15 minutes, or until used — whichever comes first |
| Free-check claim (IP address) | Indefinite — deleting it would re-issue the free check |
| Rate-limit counters (per IP) | 2 hours (automatic expiry) |
| Daily free-check counter | 48 hours (automatic expiry) |
| Account data and preferences | While your account is active |
| Purchaser email and payment identifier from Stripe | Stored on the report; follows report retention below |
| Prepaid balance records | While your account is active |
| Developer API usage counters | While your account is active |
| Bot Check verdicts | Retained indefinitely, and remain reachable at their URL, until deleted upon request |
Session cookie (bh_session) |
30 days |
Purchaser cookie (bh_purchaser) |
90 days |
| Target account data | Classification data enters the shared cache (see Section 5); report data follows report retention above |
(a) All users
(b) Target accounts
If you are the owner of an 𝕏 account that has been checked or analyzed, you may contact us at [email protected] to:
While we analyze only publicly available data, we review these requests in good faith.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected information from a person under 18, we will take steps to delete that information promptly.
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with certain rights regarding your personal information:
To exercise these rights, please contact us at [email protected].
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or our data practices, please contact us at [email protected].