Privacy
Shadowban Radar is operated by TheFactory Labs, a company registered in France. Controller for the data below.
What we collect
- Your email, only if you choose to give it to unlock the detailed results. We use it to send you the recovery protocol and product updates, nothing else. Our emails carry a tracking pixel and tracked links, handled by Resend: we learn whether an email was opened and which link was clicked, to measure which emails are worth sending. That is all we do with it.
- Your subscriber account, if you pay for monitoring: the email you sign in with, the handle being monitored, and the check history, which keeps every full audit and every confirmed change the agent records on that handle. Payments are handled by Stripe; we never see your card number, only the subscription status Stripe reports back.
- Your personal report, generated after a pass purchase: up to 20 short excerpts (300 characters each) of your own public posts, kept with the report so the evidence behind it stays checkable. It is sent to you by email and stored against your account until you ask us to remove it (see Your rights below).
- A hash of your IP address, to enforce the daily limit of free checks. It is salted and one way: we cannot recover the address from it.
- Usage analytics, through Vercel Web Analytics and PostHog (hosted in the EU): page views, which steps of the check you reach, the verdict and score of a check you run, whether you opened the payment page, the site that referred you, approximate location derived from your IP, and session replays where everything you type is masked. Your email address is never part of these events. In the EU, EEA, UK and Switzerland this only runs with cookies if you accept the consent banner; if you decline, you are counted anonymously with no replay, and the only thing kept on your device is that refusal. Elsewhere it runs by default. A second tool, DataFast, counts page views and connects a payment to the visit that led to it; it sets its own first-party cookies (listed below) wherever you are.
- What you write in the suggestion box under a result, if you choose to send one. It reaches our team with the handle that was on screen and nothing else: no email, no account. Keep personal details out of it, we do not need them.
- Public X data about the handle being checked, fetched at scan time and cached for one hour.
What we do not do
We never sell or rent your email. Checking an account does not notify anyone, and we never post on your behalf: Shadowban Radar has no access to your X account.
Advertising
The free checker is funded by advertising served by Google AdSense on public pages (never in the dashboard or on payment pages). Google and its partners may use cookies and similar identifiers to show ads and measure them. In the EU, EEA, UK and Switzerland this only happens if you accept the consent message shown on your first visit; if you decline, ads are shown without personalisation and without those cookies. You can manage Google's use of your data at policies.google.com/technologies/ads. Your check results never depend on ads or on this choice.
Affiliate links
Some links to third-party tools on a result page are affiliate links: we may be paid if you subscribe, and it never changes what you pay. Clicking one goes through a redirect on our own domain, where we record the program, the spot the link was in, and the verdict shown on the page. No personal identifier is stored with it: no IP address, no email, no account. Once you land on a partner site, that company applies its own privacy policy and its own cookies, which we neither set nor read.
Cookies
Nine functional or technical cookies set by Shadowban Radar itself:
- sbr_details remembers that you unlocked the detailed results.
- sbr_locale remembers the language you picked for the site, for 1 year.
- sbr_recent_purchase is a signed, technical receipt confirming a payment you just made, so this browser can be sent to the right place if it comes back before you sign in. It expires after 30 days and holds no personal data (a session identifier, the account handles it covers, and an expiry date).
- sbr_capture is the identifier of the email you gave us, so the payment page can be prefilled and a checkout you left can be resumed. It never contains the address itself.
- sbr_checkout lets you resume a payment session you opened and did not finish. It expires after 2 hours and 30 minutes.
- sbr_seen lists the accounts whose result you viewed in the last 24 hours (at most 10 handles), so the result page can tell you when this is your second check of the day. Nothing else is stored in it.
- monitor_handle keeps the account you asked us to monitor while you sign in, for 30 days.
- The Supabase session cookie keeps you signed in to your dashboard if you subscribe.
- sidebar_state remembers whether you collapsed the dashboard sidebar, for 7 days.
PostHog's analytics cookies depend on where you are: in the EU, EEA, UK and Switzerland they are only set if you accept the consent banner; elsewhere they are set by default to measure how the product is used. DataFast sets its cookies (datafast_visitor_id, datafast_session_id) wherever you are, to count visits and attribute payments. Advertising cookies are described in the Advertising section above and, in the EU, EEA, UK and Switzerland, are only set with your consent.
Your rights
Under the GDPR you can ask for a copy of your data, its correction, or its deletion. Write to hello@shadowbanradar.com and we handle it within 30 days, including deleting your subscriber account and its history entirely. Emails are kept until you ask us to remove them. Each scan record keeps the handle you check, a timestamp, a salted hash of your IP, the visibility score and verdict we computed, and that account's public display name and profile picture: the hash enforces the daily limits, the score and verdict let us publish aggregate figures such as the share of checked accounts that are restricted, and the handle and picture may appear in the public recent-checks strip on the homepage. Data is hosted in the European Union (Supabase and Vercel); Stripe processes payments and Resend delivers our emails.
Two other providers receive data when you use the product. The handle you check is sent to TwitterAPI.io, the provider we use to read what X shows publicly about that account; nothing about you personally is sent with it. And our own operations feed posts one line per event (a check, a signup, a payment) to a private Discord channel in the United States, where email addresses are masked: we see the first letter and the domain, never the full address.
If a result page exists for your X account and you want it gone, email us at hello@shadowbanradar.com with the handle. The page is taken down within 72 hours and the handle is excluded from future checks.
Shadowban Radar is not affiliated with, endorsed by, or sponsored by X Corp. X is a trademark of X Corp.
Back to the check