BlockAI · Chrome Extension

GeniusX Extension Privacy Policy

Last updated: 10 June 2026

The 30-second summary

  • We never see your X (Twitter) password or cookies. The extension uses your already-logged-in browser session to act on x.com — exactly as if you clicked the buttons yourself.
  • We send our servers: a random per-install device ID, the X handle you're growing, the target topic you typed, and the handles you followed / unfollowed.
  • If you upgrade to Pro, Stripe captures your email at checkout — we use that email as your account key. You can restore Pro on a new install by typing the same email.
  • We do not sell or share your data with third-party advertisers or data brokers.

What the extension reads from x.com

The extension's content script runs only on https://x.com and https://twitter.com. It reads:

  • Your logged-in handle (from the sidebar "Account menu" button) so the popup can show which account it's growing.
  • The presence and state of the "Follow", "Following", and "Follows you" buttons / badges on profile pages we navigate to.
  • Public profile statistics (follower count, following count, tweet count, account age, verified status) of accounts the extension is considering — used only for the follow-back prediction quality of future recommendations.

We do not read your direct messages, your feed/timeline contents, other users' private data, or any X authentication cookies/tokens.

What the extension sends to our servers

The extension talks to https://www.blockmm.ai over HTTPS. Each request includes:

  • Your device ID: a random UUID generated once on first install, stored locally. Lets us rate-limit the free tier and track Pro entitlement.
  • Your X handle (the account you're growing).
  • Your target topic (the text you typed in the popup, e.g. "crypto traders").
  • For each follow / unfollow: the target handle, whether it succeeded, the recommendation ID we issued, and the public profile snapshot (described above).
  • Your email: only after you upgrade to Pro (Stripe collects it at checkout) — used as your account key for tier entitlement + reinstall recovery.
  • Your payment: handled entirely by Stripe. We never receive or store your card number, CVC, billing address, or any other payment data.

What's stored locally (in your browser)

The extension uses chrome.storage.local for:

  • Your device ID, target topic, daily follow counters.
  • A small cache of pending follow candidates (so the extension doesn't need to hit the server on every action).
  • Scheduler state: when the next follow/unfollow attempt is allowed, last outcome, rate-limit strike count.
  • Your email (only if you upgrade to Pro) so we don't need to ask again.

All of this is erased when you uninstall the extension. None of it leaves your device unencrypted.

Data retention

  • Daily activity logs (follow / unfollow / outcome rows) are retained for 180 days for the smart-unfollow feature, then aggregated and anonymised.
  • Email + Pro entitlement records are retained while your subscription is active, plus 7 years for tax/accounting compliance with HMRC requirements.
  • You can request deletion of all your data by emailing privacy@blockmm.ai. We'll honour the request within 30 days, retaining only the bare minimum required for the legal compliance window above.

Third parties

  • Stripe (payments) — captures your email and card details if you upgrade. See stripe.com/privacy.
  • Anthropic (Claude) — your target topic is sent to Anthropic's Claude model so it can suggest relevant X accounts. We don't send your email, device ID, or X handle to Anthropic. See anthropic.com/legal/privacy.
  • MongoDB Atlas (database) — encrypted at rest, Vercel-hosted region.
  • Vercel (hosting) — see vercel.com/legal/privacy-policy.

We do not work with advertising networks, data brokers, or any third party whose primary business is reselling user data.

Your rights (UK GDPR / EU GDPR)

You have the right to access, correct, delete, port, or restrict the processing of your personal data. Email privacy@blockmm.ai with your request. We'll respond within 30 days. If you're unhappy with our response, you can complain to the UK Information Commissioner's Office (ico.org.uk).

Changes to this policy

We may update this policy as the extension evolves. Material changes (new data types collected, new third parties, changed retention) will be announced via the extension's popup at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

Questions, concerns, or data subject requests: privacy@blockmm.ai. General support: hello@blockmm.ai.