Privacy policy

dioBot.app Token Extract
Last updated: October 5, 2026

This policy describes how the Chrome extension dioBot.app Token Extract handles user data. Contact the developer on Telegram at https://t.me/diobot_app. The name and address shown on the Chrome Web Store listing are the contact details for privacy requests.

Single purpose

The extension has one purpose. When the active tab’s address contains after you click the toolbar icon, it reads that site’s login tokens, encrypts them with the public key bundled in the extension, and shows the ciphertext so you can copy it.

Data the extension handles

The extension does not collect your name, email address, payment information, health information, location, or messages. It does not use analytics and it does not contain advertising.

When this happens

Tab URLs are read in the background so the icon can be enabled or disabled. Tokens are read only after you click the icon on an allowed site. On Thrill and Rainbet, if site access has not been allowed yet, the popup asks you to grant it before any cookie is read. The extension then waits about five seconds so the page can finish loading, and then reads the tokens. If the required values are missing, the popup says that you need to log in and does not create a ciphertext.

How the data is used

The tokens are turned into JSON, Base64-encoded, encrypted with the bundled public key (RSA-OAEP and AES-GCM), and Base64-encoded again. JSON contains accessToken and refreshTokenThe result stays in the popup until you copy it or close the popup. The extension does not write the tokens to disk and does not send them to a server by itself.

The matching private key is held by the developer of dioBot.app. The extension does not transmit the ciphertext. If you copy that ciphertext and paste or send it to dioBot.app, the developer can decrypt it and obtain the tokens described above. That use is limited to operating dioBot.app at your request.

Limited use

Data handled by this extension is used only for the single purpose above. It is not sold. It is not used for advertising, retargeting, credit, lending, or any purpose unrelated to that feature. It is not transferred to third parties except if you choose to send the ciphertext to dioBot.app, if the law requires it, or for security, such as investigating abuse. Humans do not read this data except where you send a specific ciphertext for support, where the law requires it, or for security.

Retention

The popup keeps the ciphertext only in memory while it is open. Closing the popup discards it. The extension does not keep a copy. If you later send the ciphertext to dioBot.app, that service’s retention is limited to providing the feature you requested, and you can ask for deletion through the Telegram contact above.

Remote code

The extension does not download or run remote code. Its scripts and public key are inside the extension package.

Changes

If this policy changes, the date at the top of this page will change. Continued use of the extension after the updated policy is published means you accept the update.