GrowthX Pro — Privacy Policy
Engage · Create on X
Overview
GrowthX Pro helps you draft on-brand replies (Engage) and posts (Create) on X from text you select. Workspace data — signals, brand kit, drafts, and BYOK API keys — stays on your device. Sign-in and billing run through Supabase and Stripe. Cloud AI runs through our hosted proxy; we do not store prompts long-term. We do not scroll timelines or study accounts.
Account and billing
- Email — used for magic-link / OTP sign-in via Supabase Auth.
- Subscription status — stored in our database; synced from Stripe (Cloud plan, credit top-ups, trial end, renewal date). Not sold to third parties.
- Cloud credit usage — we record credit debits (operation type and balance) for billing and abuse prevention; we do not retain full prompt text in our database.
- Card data — handled only on Stripe hosted checkout and customer portal. Card data never passes through the extension.
- Session tokens — stored in chrome.storage.local; sent only to our Supabase project for auth and entitlement checks.
Data on your device
- Signals, brand kit, prompts, drafts, calendar, preferences, and BYOK LLM API keys — chrome.storage.local.
- When you use Engage or Create with BYOK: reads only text you highlight or paste; sends excerpts and prompts directly to providers you configure.
- When you use Cloud model: the extension sends prompts to our Supabase edge proxy, which forwards them to our LLM providers (e.g. Google Gemini, OpenAI) using server-side keys.
LLM providers
- BYOK — API keys stored locally in chrome.storage.local; sent only to providers you configure: OpenAI, DeepSeek, MiniMax, Google Gemini API, Anthropic Claude.
- Cloud — prompts transit our llm-proxy service and are forwarded to hosted providers. We do not sell prompt content; we do not keep full prompts in our database after the request completes.
- We never send BYOK API keys to our billing or Cloud proxy servers.
Feedback
The side panel feedback form may send category, email, message, and extension version to https://www.boteam.ai/api/feedback. Used for support only — not sold. Replies come from hi@boteam.ai when you leave an email.
Page context (content scripts)
- x.com / twitter.com — injects the ✦ Engage overlay when you select text; reads only your highlighted selection and nearby visible context for drafting. From the overlay you can Copy a draft, or open a reply/post composer and tap Fill to insert a draft you chose — always after your explicit tap. You edit and send yourself. We never auto-post.
- gemini.google.com, grok.com, grok.x.ai — optional prompt-picker helpers when you visit those sites. You review and send yourself.
What we never do
- Scroll timelines or bulk-read profiles
- Auto-post or auto-send replies without your action
- Fill or post on your behalf without your explicit tap on each draft
- Send BYOK API keys to our billing or Cloud proxy servers
- Sell personal data
- Store your X password
Clear and delete data
- Local extension data — Chrome → Extensions → GrowthX Pro → Remove extension, or clear site data / extension storage.
- Account and billing deletion — email hi@boteam.ai.
Third parties
Supabase (auth and entitlement), Stripe (payments), your chosen LLM provider, and Boteam (feedback API) each have their own privacy policies.
Privacy questions: hi@boteam.ai · Back to GrowthX · Boteam company privacy (waitlist)