Privacy Policy

Last updated: July 23, 2026

This policy explains how BloxPilot handles information when you use the BloxPilot browser extension, website, subscription service, and support channels.

Data stored locally

The extension may store settings, preferred location, server history and notes, watchlists, cached Roblox game or friend information, notification state, diagnostics, locally inferred compatibility sightings for supported Roblox extensions, a randomly generated browser installation ID, the selected Pro access method, a recent Roblox-account match result, and cached subscription status in the browser's local extension storage. Compatibility sightings include a supported extension's name, visible page-signal count, Roblox page type, and first- and last-seen times; they are retained locally for up to 90 days. This information remains in the browser profile unless a feature described below sends a limited request to a remote service.

BloxPilot checks compatibility only through visible changes on Roblox pages that are already open. It does not request browser-wide extension-management access, does not show a complete inventory of installed extensions, and does not include compatibility sightings in product analytics or subscription-service requests.

The website uses local storage for a randomly generated first-party analytics visitor ID and the first-party analytics opt-out preference. It uses session storage for a randomly generated per-tab first-party analytics session ID, a coarse source category, and, when present, a validated campaign tag such as reddit_dod_e03. The source and campaign tags expire with the tab session; campaign tags cannot contain spaces, URLs, or free-form ad content. BloxPilot's first-party analytics do not use cookies. These first-party random IDs do not contain a name, email address, Roblox identity, or advertising identifier. A first-party website visitor ID identifies one browser profile on one device; it is not a cross-device person identity. A phone, laptop, desktop, private-browsing profile, or other browser profile normally has a different ID.

Data processed by the BloxPilot subscription service

When you check subscription status, start Checkout, open the billing portal, connect a Roblox account, or manage authorized browsers, BloxPilot may process a browser installation ID, a derived device identifier, device creation and last-seen times, the selected access method, a verified permanent numeric Roblox user ID, verification and account-change times, access source and expiration records, billing email received from Stripe, Stripe customer and subscription identifiers, price identifier, subscription status, billing period, renewal date, cancellation state, unique external subscription or grant references, and processed webhook identifiers.

BloxPilot uses this information only to provide billing and Pro access, match account-based access, enforce the authorized-browser limit where selected, prevent duplicate grants and abuse, restore access, and support membership questions.

Product and website analytics

BloxPilot records a limited set of events to understand whether people can find, install, start, and successfully use the product. The event categories are:

Website event requests use the random visitor and session IDs stored in the browser. On supported Chromium builds, extension product analytics are off by default and begin only after the user opts in. Those events use a separate random analytics-only installation ID and session ID; the analytics ID is not the subscription installation ID and cannot authorize billing, OAuth, or device-management actions. The analytics service transforms these client identifiers with a secret one-way keyed hash before storing analytics events; the analytics event table does not store the raw client IDs.

Analytics requests reach Cloudflare with ordinary request-layer information such as the source IP address, request headers, user agent, and network, security, or rate-limiting signals. Cloudflare may process that metadata to deliver and protect the service. For website page-view events only, the BloxPilot Worker may derive and retain the country and first-level state, province, or region supplied by Cloudflare's request metadata so website audiences can be viewed in aggregate. Engagement, section, and store-click events are not location-enriched. First-level regions are hidden in the dashboard when a group contains fewer than three distinct website visitors. This location is approximate and can be wrong because of VPNs, mobile routing, or network gateways. BloxPilot does not persist the request IP address, city, coordinates, full user agent, or full request headers in the analytics event table. The website does not request browser geolocation or GPS access and does not send a client-provided location field.

Extension product analytics do not collect or retain user location. They are not enriched with country or region. BloxPilot's existing player-region and server-distance features operate for the user-facing server tools and are not sent to the analytics service. Firefox product telemetry is disabled in this release so no Firefox analytics data-collection permission is added. This analytics update adds no extension location permission or other manifest permission.

BloxPilot's first-party analytics do not include session replay, cursor coordinates, clicked-element details, key values, scroll position, page text, query strings, a full referrer or complete browsing URL, Roblox usernames, Roblox user IDs, place or server IDs, friend graphs, passwords, authentication cookies, or .ROBLOSECURITY values. The website keeps only a recent-activity timestamp in memory so an idle visible tab is not counted as engaged time. BloxPilot does not sell these first-party analytics events or use them for targeted advertising.

BloxPilot uses these events to measure acquisition and activation, identify onboarding failures, compare aggregate channel, page, and website-audience geography performance, prioritize fixes, detect duplicate events or abuse, and operate the private analytics dashboard.

Website analytics status: Checking this browser

Website analytics is on by default unless this browser profile has stored an opt-out. This control applies only to this browser profile. Turning website analytics off stops future website analytics requests and removes the local random visitor ID, per-tab session ID, and session source and campaign tags. The extension has a separate product-analytics control in its Privacy settings; extension analytics are off by default and Firefox telemetry remains disabled.

Your website owner-exclusion ID: Checking this browser

Use this only if you operate BloxPilot and want this browser excluded from the private dashboard. Repeat this on every owner-controlled browser profile and device.

Roblox account authorization

Optional BloxPilot features use Roblox OAuth only after the user chooses to connect an account. Account-based Pro access receives the permanent numeric Roblox user ID needed to match access. Its OAuth state and verification records are short-lived and bound to the requesting browser installation. OAuth access or refresh tokens are not stored in the subscription database and are revoked or discarded after the user ID is retrieved.

Community discovery identity

When a user connects Roblox to contribute game ratings, reviews, tags, nominations, or reports, BloxPilot requests the openid and profile scopes. The identity service uses the Roblox OAuth subject to recognize the same authorized account and uses the account-creation time to apply contribution-eligibility protections. It does not retain the Roblox username, display name, avatar, profile image, raw OAuth subject, access token, IP address, user agent, friend graph, game-play history, or general page-view history for this community identity.

The raw OAuth subject is transformed with a secret keyed hash before storage. BloxPilot assigns a separate random community actor ID and stores the keyed subject mapping, Roblox account-creation time, verification time, identity status and revision, the first verified Discovery session time, the first qualifying return at least 24 hours later, an encrypted rotating Roblox refresh credential, and hashed device credentials with expiration and revocation times. Community contributions are associated with the random actor ID rather than being displayed with a Roblox identity.

This information is used to keep one current rating or review per connected actor and game, limit duplicate tag votes and coordinated promotion, enforce account-age and contribution-maturation rules, reconnect an intentionally unlinked account safely, issue short-lived signed credentials to the Discovery service, and respond to abuse or deletion requests. Unlinking revokes the Roblox refresh credential and BloxPilot device credentials but retains the keyed account mapping so unlinking and reconnecting cannot create a fresh voting identity. Deleting the community identity removes that mapping and queues deletion of actor-linked Discovery contributions. Discovery may retain a compact tombstone containing only the random actor ID and identity revision for up to seven days so an already-issued short-lived credential cannot recreate deleted data.

Roblox and browsing activity

BloxPilot runs on supported Roblox pages and requests Roblox endpoints needed for user-facing server discovery, joining, game information, friend cards, presence, watchlists, and notifications. The extension may read the current Roblox game or page context to provide these features. BloxPilot does not use this access to build an advertising profile or sell browsing activity.

Roblox passwords, browser cookies, and .ROBLOSECURITY values are not collected or stored by BloxPilot and are not sent to the BloxPilot subscription service. Friend names, avatars, game presence, and similar Roblox information are displayed and cached locally for the requested social features; BloxPilot does not upload a user's friend graph to its subscription database.

Payment data

Payments are handled on Stripe-hosted Checkout and Customer Portal pages. BloxPilot does not receive or store complete card numbers, card security codes, or bank credentials. Stripe may provide BloxPilot with billing email, customer and subscription identifiers, payment status, invoices, and subscription dates needed to provide Pro access.

Services BloxPilot communicates with

Retention

Local extension information remains until it is cleared, replaced, or the browser removes the extension's storage. Membership, verified Roblox user ID, grant source, expiration, Stripe, and authorized-browser records are retained while needed to provide access, handle billing or support, prevent duplicate grants or fraud, and satisfy applicable recordkeeping requirements. Community identity and contribution records are retained while the community account remains connected or while needed to display contributions, prevent manipulation, enforce moderation decisions, or handle a deletion request. Short-lived OAuth state, one-time result records, device-code records, and Checkout bindings expire automatically. Community device credentials expire or are removed after revocation; encrypted Roblox refresh credentials are replaced during verification and revoked or removed when the identity is unlinked or deleted. Records that are no longer required may be deleted or de-identified.

Raw BloxPilot first-party event-level analytics records are retained for 180 days and then deleted. Aggregate totals that can no longer be connected to a hashed browser identifier may be retained longer for year-over-year product measurement. The website's first-party random visitor ID remains in local storage until analytics are turned off or site storage is cleared; the session ID and coarse source and campaign tags remain only until the tab session ends or session storage is cleared.

Your controls

You can change extension settings, remove watchlist entries and server history, choose account-based or authorized-browser Pro access, revoke an authorized browser, manage or cancel billing through Stripe, and uninstall the extension. A connected Roblox account for Pro can be replaced subject to the displayed 30-day change limit. Community identity controls allow the connected account to be unlinked or deleted; deletion also queues removal of actor-linked Discovery contributions. You may contact BloxPilot to request access to or deletion of membership or community records associated with your verified account. Some transaction records may need to be retained for legal, accounting, fraud-prevention, duplicate-receipt prevention, or dispute purposes.

BloxPilot first-party website analytics is on by default per browser profile and can be turned off with the control above or by clearing this site's local and session storage. Extension product analytics are off by default on supported Chromium builds and can be turned on or back off in the extension's Privacy settings; turning them off clears queued analytics and does not affect features, billing, or subscription access. Firefox product telemetry stays disabled. Because BloxPilot first-party analytics identifiers are one-way transformed and are not connected to a name or email address in the analytics event table, BloxPilot may not be able to locate already-recorded events after the local random ID is removed. Turning first-party analytics off stops future collection but does not immediately delete previously recorded events; those events follow the 180-day retention period unless BloxPilot can reliably identify them in response to a verified deletion request. You may still contact BloxPilot with a privacy request using the address below.

The website control and supported Chromium extension builds can display their current analytics-only random ID for BloxPilot's owner to copy into the private dashboard. The extension analytics ID is separate from the subscription installation ID and is not a billing or device-management credential. Copying the ID does not itself transmit it. When an owner-exclusion ID is added, the analytics service stores only its secret-keyed hash and excludes matching historical and future dashboard events until that exclusion is removed. IDs and exclusions are per browser profile or extension installation, not per person, so each owner-controlled phone, laptop, desktop, or profile must be added separately. Clearing website storage or reinstalling in a way that creates a new analytics ID requires excluding the new ID too. Owner exclusion is an administrative reporting filter; it does not change the user's analytics preference or the raw-event retention schedule.

Security and sharing

BloxPilot uses encrypted HTTPS connections and keeps Stripe secret keys and entitlement-signing keys on the Cloudflare backend rather than in the extension. BloxPilot does not sell its first-party analytics events. Information is shared with the service providers described above when necessary to operate requested features, protect the service, process payments, or comply with law.

See Safety & Security for credential boundaries and security-reporting instructions. BloxPilot is independent and is not affiliated with, endorsed by, sponsored by, or officially partnered with Roblox, RoPro, RoGold, Microsoft, Google, Stripe, or another third party.

Changes to this policy

This policy may be updated when BloxPilot's features or data practices change. The updated date at the top of this page identifies the current version.

Contact

For privacy questions or data requests, email BloxPilot by Nealware at zac.nealware@gmail.com. Do not send passwords, full payment-card details, or Roblox authentication cookies.