BotFriendly.xyz

>_privacy --policy

Short version: we collect the minimum needed to run a directory.

>_ accounts

Creating an account (email-based, via Supabase) is only needed to submit and manage listings or buy ad slots. We store your email address, display name, and the listings you manage. We never sell or share account data, and we don't send marketing email.

>_ payments

Ad-slot payments are processed entirely by Stripe Checkout. Card details never touch our servers; we keep only the Stripe session reference needed to activate and expire the promotion you bought.

>_ api usage

The public API requires no account. IP addresses are used in-memory for rate limiting (100 requests/min; 6/min on the site checker) and are not written to a database. Anonymous usage counters (which endpoints get called) may be tracked in aggregate to plan capacity.

>_ analytics & cookies

Human-facing pages load Google Analytics (gtag.js), which sets its own cookies and collects usage data under Google's policies. The API, llms.txt, MCP server, and other machine endpoints carry no analytics and set no cookies. Auth cookies (Supabase) are set only when you sign in.

>_ the site checker

/check and GET /api/v1/check fetch only public, well-known paths of the URL you submit (homepage, robots.txt, llms.txt, sitemap, discovery manifests). We don't store the fetched content or the report after the response is sent, and we never probe private networks.

>_ your rights & contact

Want your account, submission, or listing data corrected or deleted? Email hi@botfriendly.xyz from the address on the account and we'll handle it within 30 days. This policy was last updated August 2026; material changes will be noted here.