Privacy Policy
This is the privacy policy for IntentXT B2B Intent Lead Finder (the Chrome extension) and the IntentXT website and dashboard at intentxt.payxt.app. It describes how the product collects, uses, stores, and shares user data.
User data privacy summary. The four sections below — Collection, Handling, Storage, and Sharing — are the required disclosures for this product. Read them first.
Chrome Web Store Limited Use. IntentXT's use and transfer of information received from Google APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Collection
The extension collects the text of public social media posts and the user's customized company profile data.
In practice, IntentXT collects only the following categories:
- Public post text you view or select. On Reddit, LinkedIn, and public Facebook groups, the extension reads the title and text of public posts that match keywords you configure, plus the post URL, platform, optional author display name shown on the page, and a short snippet. It does not collect private messages, private group posts, your social-network passwords, or your general browsing history.
- Company profile data you type. Company name, company or product description, and value proposition used to generate AI reply drafts.
- Monitoring settings you configure. Target keywords, negative keywords, target subreddits, Facebook public group URLs, Auto-Pilot on/off, and related scan preferences.
- Leads you flag or that scans save. Post title, URL, platform (Reddit, LinkedIn, or Facebook), optional author, snippet, matched keyword, timestamps, and pipeline status you set.
- Account data. Email address, display name if provided, and Firebase authentication identifiers when you sign in with email and password or Google.
- Credits and purchases. Plan or entitlement (Free, Pro, or promotional/lifetime), credit balance and usage events (for example an AI draft), and purchase or redemption identifiers needed to unlock that entitlement.
- Optional destinations you enter. A CRM or Zapier webhook URL, a Slack or Discord alert webhook URL, and a Telegram bot token and chat ID, if you turn those features on. These stay on your device until you use the feature.
- Website and support data. On intentxt.payxt.app we collect standard server logs (IP address, browser type, referring page, and access time) and website analytics via Google Analytics and Google Tag Manager. If you use Talk to Us or dashboard chat, we collect the messages you send in that chat. The Chrome extension itself does not include an advertising or analytics SDK.
Handling
Post data is sent to our secure backend API to generate AI replies.
We process the data above only to operate the features you use:
- AI reply drafts. When you request a draft, the selected public post text and your company profile (company name, description, and value proposition) are sent to our backend API. The API sends that prompt to a trusted large language model provider (Google Gemini) to generate the reply drafts you asked for (a public comment, a short inquiry, and a direct-message draft). A successful draft uses one AI credit on your account.
- Optional intent check. If AI intent pre-filter is on, public post title and text plus the matched keyword are sent to the same API and then to Google Gemini to decide whether the post looks like a B2B lead. That check is used only to sort Inbox versus Filtered. It does not spend a draft credit.
- Keyword scans. Reddit matching runs in the extension against public Reddit content. LinkedIn and Facebook scans you start are handled by our API: we send the keyword you entered (and, for Facebook, the public group URLs you configured) to Apify so matching public posts can be retrieved, then save new leads to your account.
- Account, credits, and billing. We use your account email and authentication token to sign you in, enforce plan limits, record credit use, and fulfill Stripe or marketplace purchases and deal-code redemptions.
- Alerts and CRM. Chrome desktop alerts stay on your device. If you configure a Slack or Discord webhook, or Telegram, a short lead alert (title, URL, keyword, platform) is sent only to that destination when a match is found. Send to CRM runs only when you choose it, and posts the lead to the webhook URL you configured.
We do not use public post text or your company profile to train our own models. You are responsible for reviewing any AI draft before you post it.
Those prompts are sent to Google Gemini through the Gemini Developer API (a server API key; not Google Cloud Vertex AI), only to generate the draft or classification you requested.
Storage
Company profile data is stored locally on the user's device. Flagged leads are stored securely in our database.
-
On your device.
Company profile data, keywords, scan preferences, alert and CRM webhook
settings, Telegram bot token and chat ID, and a local copy of your leads are
stored in the extension's local storage (
chrome.storage.local) on your browser profile. We do not sync that profile to Chrome Sync. - In our database. Flagged leads and leads saved from scans are stored in Google Cloud Firestore, tied to your account user ID, so the extension and dashboard can show the same pipeline. Typical lead fields are title, URL, platform, optional author, timestamps, and status.
- Account and credits. Sign-in records are stored in Firebase Authentication. Entitlement, credit balance, and usage events are stored in Firestore.
- AI prompts. Post text and company profile fields are transmitted to our API and then to Google Gemini to produce the draft or classification you requested. We do not keep a separate product archive of every prompt beyond what is needed to return the result, operate the service, and record credit usage.
Sharing
User data is never sold. Data is only shared with trusted large language model providers such as Google Gemini strictly for the purpose of generating the requested reply drafts (and the optional intent classification you enable), and with the processors listed below solely to run the product.
We do not sell, rent, or share user data with data brokers or advertisers for their own marketing. Parties user data is shared with:
- Google Gemini (Google AI) — public post text and company profile fields you submit for a reply draft or intent check, only to generate that result. Google Privacy Policy.
- Google Cloud / Firebase — hosts our API, authentication, and database. Firebase Privacy.
- Apify — the keyword, and for Facebook the public group URLs you configured, when you run a LinkedIn or Facebook scan so public matching posts can be retrieved. We do not send your company profile or CRM settings to Apify. Apify Privacy Policy.
- Stripe — payment details if you buy Pro on our site. We do not store full card numbers. Stripe Privacy Policy.
- Payhip — order email and entitlement data if you purchase through that marketplace, so we can unlock your plan. Payhip Privacy Policy.
- Google Analytics and Google Tag Manager — website usage on intentxt.payxt.app (page views and similar analytics). Extension lead contents are not sent to these tags. Google Privacy Policy.
- Tawk.to — chat messages you send via Talk to Us or signed-in dashboard support chat. Tawk.to Privacy Policy.
- Your CRM or Zapier webhook — data is shared only with the HTTPS webhook URL you configure, and only when you choose Send to CRM. The payload is platform, title, URL, author if available, matched keyword, snippet, and date found.
- Your Slack or Discord alert webhook — a short lead alert is posted only to the webhook URL you configure.
- Telegram — if you configure a bot token and chat ID, the alert is sent to that chat through the Telegram Bot API. Telegram Privacy Policy.
Reddit, LinkedIn, and Facebook are third-party sites you use. IntentXT reads public post text from those pages to provide the lead-finding feature. We do not sell your data to those platforms. Content you later post yourself is governed by their terms and privacy policies.
IntentXT processes public data natively visible via your browser or retrieved via third-party infrastructure (Apify). We are not liable for actions taken by third-party social networks against your account for utilizing automated keyword monitoring tools.
We may also disclose information if required by law, a court order, or to protect the security of the service and our users.
Who we are
IntentXT is operated by DTLA Professional Services, LLC (also doing business as PayXT), 770 S Grand Ave, Los Angeles, CA 90017, USA. For personal data processed in connection with IntentXT, that company is the data controller.
This page covers IntentXT. PayXT invoicing and the PayXT mobile app are described in the PayXT privacy policy.
Cookies and analytics
The IntentXT website uses strictly necessary cookies or similar storage for sign-in, plus Google Analytics and Google Tag Manager to understand site traffic. You can block or delete cookies in your browser. Blocking them may affect sign-in. The Chrome extension does not use advertising cookies. Analytics and advertising identifiers used by the separate PayXT mobile app are not part of the IntentXT extension. Our website does not currently alter its practices or respond to browser "Do Not Track" (DNT) signals because no uniform technological standard has been established.
Retention
- Account data is kept while your account is active.
- Flagged leads and scan configuration stored in our database are kept while your account is active so the pipeline works, then deleted or anonymized with an account-deletion request, subject to short-lived backups and legal holds.
- Company profile and other extension-local settings remain on your device until you change them, sign out (which clears the extension workspace), or remove the extension.
- Purchase records may be kept longer where needed for tax, accounting, fraud prevention, or legal claims.
- Website analytics are retained according to our Google Analytics settings, typically in aggregated or pseudonymized form where practicable.
Your rights and deletion
Depending on where you live, including the EU/EEA, UK, and California, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to opt out of any “sale” or “sharing” of personal information. We do not sell personal information.
To delete your IntentXT account and associated server data, use account deletion in the product where available, or email support-24-7@payxt.app or use payxt.app/contact and identify the product and account email. We delete account data from active systems within about 30 days, subject to legal and tax retention. Local extension data is removed when you sign out or uninstall the extension.
If you are in the EU/EEA or UK, you may also lodge a complaint with your local supervisory authority. Our legal bases for processing are contract (to provide the service you request), legitimate interests (security, fraud prevention, and operating the product), consent where required (for example non-essential website cookies), and legal obligation.
Security and children
We use industry-standard protections for data in transit and at rest, including authenticated API access and Firebase security rules that limit leads to the signed-in account. No online service can be guaranteed 100% secure.
IntentXT is a business tool for adults. It is not directed to children under 16, which is the age boundary we apply for EU/UK GDPR. We do not knowingly collect personal data from children under 13, the US Children's Online Privacy Protection Act (COPPA) threshold, and we do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, contact us and we will delete it.
International transfers
We are based in the United States. If you use IntentXT from another country, your data may be processed in the United States and in other countries where our service providers (including Google and Apify) operate. Where required, we rely on appropriate transfer safeguards such as Standard Contractual Clauses.
Changes
If our practices change, we will update this page and the “Last updated” date. If we make material changes to this policy, we will notify you via the email address associated with your account or through a prominent notice inside the Chrome Extension/Dashboard prior to the change taking effect. Continued use of IntentXT after the updated date means the updated policy applies. The live policy is always at https://intentxt.payxt.app/privacy.
Contact
Privacy questions, access requests, or deletion requests:
DTLA Professional Services, LLC
IntentXT · PayXT
770 S Grand Ave
Los Angeles, CA 90017
United States
Email:
support-24-7@payxt.app
Phone / SMS: (213) 444-2224
Contact form:
https://payxt.app/contact
Related: Refund policy · Terms · Talk to Us.