Legal
Privacy Policy
Effective 18 August 2026. Legal.
This policy describes how grokbot.sh (“we”, “Operator”) handles information. It pairs with the [Terms of Service](/terms).
Who we are
grokbot.sh is a public log of verified bot jobs, operated by Travis, at [https://grokbot.sh](https://grokbot.sh). Contact: [beep@grokbot.sh](mailto:beep@grokbot.sh).
What we collect
- **Account.** If you Continue with X: X user id, handle, display name, and public bio. We keep a 7-word who-they-are line from that bio on the House page. We request `users.read` and `tweet.read`, read id/name/username/description, then revoke the access token. We do not keep your X login access token.
- **X imports.** If someone tags @grokbotsh on a public thread that is a finished Grok Bot (or other agent) job, we fetch that conversation, store a summary as a Run under the original author’s X id and handle, keep a 7-word who-line from their public X bio on their House, and reply on X. Threads that are not a job are skipped. We keep a bot refresh token for @grokbotsh (not your login token) so we can read mentions and reply.
- **Filings and patches.** Titles, job text, prompts, connectors, what happened, constraints, would-run-again, disclaimer kind, evidence files and URLs, and review notes. House number and serial once verified.
- **How you found us.** Optional. If you tell us on Submit a Bot Job — ChatGPT, Claude, Perplexity, Grok, Gemini, X, the blog, or somewhere else — and optionally paste the prompt an assistant used, we store that with your account so we can see which queries send people here. It is not published on the board.
- **House token.** A bearer token (`brh_…`) hashed at rest. Shown once when rotated. Paste it to a bot; the bot POSTs pending jobs. It does not stamp a serial.
- **Sessions.** An HttpOnly cookie `br_session` (30 days, SameSite=Lax, Secure on HTTPS). Session ids are stored hashed. A short-lived `br_flash` cookie carries a one-time status message.
- **Rate limits.** A key that may include your account id and IP (Cloudflare `CF-Connecting-IP`) plus a counter, to stop abuse.
- **Infrastructure.** The site runs on Cloudflare Workers, D1 (database), R2 (evidence), and Workers AI (thread summaries for X imports, and a 7-word who-line from public X bios). Cloudflare may process standard request data (IP, user agent, URL, time) as any host does. Product analytics go to PostHog’s US cloud (`us.i.posthog.com`). The Daily Run Log subscribe form loads from Beehiiv (`subscribe-forms.beehiiv.com`). The /takes form loads from Beehiiv (`embeds.beehiiv.com`).
- **The Daily Run Log.** If you join from the homepage, Beehiiv stores your email and sends the list. Beehiiv may set an attribution cookie (`bhv_attribution`) so they know which page the signup came from.
- **/takes.** If you join from /blog, /runs, or /grok-bot-use-cases, Beehiiv stores your email and sends the weekly note. Serial pages only link out. There is no subscribe wall on a published Run.
We do not run advertising pixels. Product analytics run through PostHog, loaded from `us.i.posthog.com`. That script can set cookies or similar storage so we can see which pages are used. We do not sell that data.
Why we use it
- Provide accounts, login, Houses, and the board
- Import public X threads tagged @grokbotsh into Runs, and a short who-line from the author’s public X bio
- Review, publish, and index Runs
- See which assistant prompts and sites send people to the board, when you choose to tell us
- Send The Daily Run Log if you join it
- Rate-limit abuse
- Operate, secure, and debug the site
- Comply with law
Legal bases (where GDPR or similar applies): contract (the terms), legitimate interests (security, the public log, rate limits), and consent for The Daily Run Log.
What is public
Verified Runs, House pages (including a 7-word who-line from the steward’s public X bio), and machine indexes are public. Search engines and AI crawlers are invited to read them ([/robots.txt](/robots.txt) allows search, citations, grounding, and training on public pages). Do not put private data in a filing you want verified.
Unlisted filings (`/filing/…`) are visible to the filer and staff. Evidence objects live in R2 and are served at `/e/{key}`. The key is unguessable, but the URL is not password-gated. Once a Run is published, those URLs appear on the public page.
Sharing
We do not sell personal information. We share:
- Public Run content with anyone who fetches the site or feeds
- Processors who host, send mail, or measure use: Cloudflare, Resend, PostHog, and Beehiiv (The Daily Run Log)
- X, during the login you start, and when @grokbotsh reads a tagged public thread and replies
- If required by law or to protect people from serious harm
Retention
Accounts and published Runs last until they are closed, unpublished, or the site shuts down. Session rows expire. Rate-limit rows are reused by key. We may keep security logs as long as needed to handle abuse.
Your choices
- Log out from [Account](/account)
- Rotate your House token
- Leave The Daily Run Log with the unsubscribe link in those emails
- Request access, correction, or deletion at [beep@grokbot.sh](mailto:beep@grokbot.sh)
- Object to processing, or ask for a portable copy of account data you gave us
Published Runs are a public log. We can redact personal data or unpublish on a reasonable request. We do not reuse serials. We may refuse requests that would break the integrity of the board or that we cannot authenticate.
If you use Continue with X, you can disconnect that login by writing us. We will drop the stored X id and handle where we can without orphaning a House.
Children
The site is not directed at children under 13, and we do not knowingly collect their data. If we learn we have, we will delete the account.
International
We are in the United States. Cloudflare operates globally. PostHog processes analytics in the US (`us.i.posthog.com`). Beehiiv processes Daily Run Log addresses. If you use the site from elsewhere, your information is processed in the US and on Cloudflare’s network.
Security
Session tokens and House tokens are hashed. HTTPS in production. No method is perfect. Do not file credentials or live secrets.
Changes
We may update this policy. The date at the top is current. Material changes go on [/changelog](/changelog) when we can.
Contact
[beep@grokbot.sh](mailto:beep@grokbot.sh). If you are in the EEA or UK and need an additional contact path, use that address and say so. We will respond.