Seatext library / BotRefund evidence
How BotRefund Protects Privacy While Detecting Bots
BotRefund detects automated browsers using 106 independent checks that rely on anonymized technical and behavioral signals, not personal identifiers. It cross-references these signals so that privacy tools or unusual setups don't cause false flags,...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
What BotRefund collects during browser detection
BotRefund collects data from 106 independent checks spread across four categories: browser, network, device, and behavior. These checks are designed to observe how a browser session behaves, not who the user is. Each check produces a single objective fact about the visit, such as whether a browser API returns a value that automation tools often change.
Browser checks look at the integrity of the browser environment. For example, the Console Debug Evaluator examines the browser's built-in properties, permissions, and rendering contexts. Automation tools often patch or hide these APIs to avoid detection. When those patches break or leave mismatches, the check notices. The window.open Tamper check watches for interference with the window object. Scripts that try to open new windows or manipulate the current one can leave clues. These are technical details about the browser, not about the person using it.
Network checks analyze the connection. They may look at IP address characteristics, proxy usage, and routing patterns. A residential proxy used by a bot might route through a consumer internet provider, which looks different from a typical corporate network. But a single network anomaly is not enough to call something a bot.
Device checks look at attributes of the device reported by the browser, such as screen resolution, installed fonts, and hardware concurrency. These attributes can be spoofed, but when they conflict with other signals, it may indicate automation.
Behavior checks track how a user interacts with the page. They include ghost click detection, which catches click activity that happens without the natural sequence of human intent. Trap behavior checks whether a bot responds to hidden or deceptive page elements. Pointer behavior flags unnaturally straight mouse movements. Motion behavior looks for the absence of humanlike mouse tremor. Speed behavior identifies interactions faster than a person could realistically perform, such as superhuman input speeds under one millisecond. Path behavior detects grid-aligned movement patterns. Engagement behavior highlights sessions with no clicks or scrolling. Session behavior catches visit lengths that are too short, too long, or too uniform to be human.
These checks are independent, meaning no single check determines the verdict. Each one adds evidence.
How the 106 checks are organized
The 106 checks cover four groups: browser, network, device, and behavior. Each group contains many specific checks. The independence of these checks is what makes the system reliable. A browser check might see an anomaly, but the network check might not. The behavior check might see humanlike movement, so the system has conflicting evidence.
BotRefund treats each check as independent evidence. In the process, each signal adds one objective fact about the visit. Then BotRefund cross-checks these facts against other independent signals from the same four groups. Finally, the prediction AI weighs the complete pattern instead of trusting a raw rule. This three-step method -- independent evidence, cross-checked context, and AI prediction -- is how BotRefund achieves 99% accuracy, as claimed.
The organization is important because it allows the system to consider the whole picture. A single anomaly, like an unusual browser property, is never enough to label a visitor a bot. The AI looks for corroboration across categories. If a visitor uses a privacy tool that changes browser API behavior, but their network, device, and behavior all look human, the model will not flag them.
How BotRefund keeps detection data anonymous
BotRefund collects only the technical and behavioral signals needed for detection. It does not collect names, email addresses, phone numbers, or any other personally identifiable information. The data is anonymized by design. Each signal is a technical observation about the session: a timing measurement, a pointer path, a network attribute. None of these can be used to identify a specific person.
The anonymity comes from how the data is used. The system looks at patterns, not identities. It answers the question "does this session behave like a bot?" rather than "who is this?" The AI model never receives personal details. It only sees the aggregate of technical evidence.
By focusing on patterns rather than identity, BotRefund minimizes the personal data footprint. This approach also helps with compliance. Because there is no personal data, regulations like GDPR and CCPA have less to regulate. However, for specific compliance requirements, you should check with BotRefund about your region's regulations.
Why cross-checked signals protect privacy better than raw rules
A raw rule might flag anyone using a VPN or a privacy extension. That would punish real people who simply value their privacy. BotRefund avoids this by requiring corroboration. If a visitor's browser produces an anomaly -- say, a changed API behavior -- the system checks whether other signals support the same story.
For example, consider a user who enables a strict privacy browser extension. This extension might alter the browser's fingerprint, causing the Console Debug Evaluator to see a mismatch. But if that user also moves the mouse naturally, scrolls through the page, and takes a normal amount of time to read, the behavior signals will look human. The network and device signals may also appear normal. The AI model will weigh the complete pattern and conclude the session is human.
This cross-checking dramatically reduces false positives. It protects the browsing experience for privacy-conscious users. It also catches bots that try to hide under privacy tools. Bots often use headless browsers or residential proxies to look real, but they still fail to replicate human irregularities. The Impossible Tab Speed check, for instance, can catch interactions that happen faster than a person could realistically perform, even if the network looks clean.
The approach aligns with the expert perspective. Marcus Vance, VP of Acquisition at FinTrust, put it plainly: "Enterprise-grade security is in our DNA, but ad fraud happens outside our product walls. BotRefund audit trails are the gold standard that Meta ad reps accept." This shows that a privacy-conscious detection method can still be rigorous enough to satisfy ad platforms.
Here are the key facts about BotRefund's privacy approach:
| Fact | Details |
|---|---|
| Detection method | 106 independent checks across browser, network, device, and behavior data |
| Privacy principle | No single signal is treated as a bot verdict; cross-referencing adds context |
| Accuracy | Reported 99% accuracy through corroboration |
| False-positive handling | Privacy tools, travel, corporate networks, and unusual devices are explicitly considered |
| Free audit | Free bot audit available to see how detection works on your site |
Trade-offs and limitations: when privacy tools can still trigger flags
Even with cross-checking, extreme privacy configurations can sometimes produce enough anomalies to trigger a flag. For example, a user who disables JavaScript entirely will break many standard browser APIs. The Console Debug Evaluator may see a mismatch. If the same user also rotates IP addresses aggressively and uses a non-standard browser build, the evidence can cluster into a bot-like pattern.
BotRefund's answer is to keep each signal as evidence, not a verdict. The AI model weighs the complete picture. But if the evidence clusters strongly enough, a true human can still be flagged. In those cases, site owners can review the flagged activity and adjust detection thresholds or whitelist the user. The system is designed to minimize, not eliminate, false positives.
Another limitation is that the source pack does not specify data retention periods. This means site owners should ask BotRefund directly about how long detection data is kept and how it is eventually deleted. Transparency about data handling is critical for trust.
Frequently asked questions
Does BotRefund store personal information about visitors?
No. BotRefund uses anonymized technical and behavioral signals. It does not collect names, emails, or other personal identifiers to make a detection decision. For example, it might record that a session has a screen resolution of 1920x1080 and that the mouse moved in a straight line, but it never records who you are.
Can BotRefund detect a visitor who uses a VPN or ad blocker?
It may see anomalies, but it won't flag the visit unless other signals agree that the session behaves like a bot. For instance, a VPN changes your IP address and network routing. If the rest of your behavior is human -- you scroll, pause, and move the mouse naturally -- the AI will not label you a bot. Privacy tools alone are not enough for a bot verdict.
How does BotRefund comply with privacy regulations?
By focusing on patterns rather than identity, BotRefund minimizes the personal data footprint. Because it does not collect personal data, many privacy regulations have less to regulate. For specific compliance requirements in your region, check with BotRefund.
What happens if a legitimate user is mistakenly flagged?
You can review the flagged session, see which signals contributed, and adjust settings to prevent future false positives. BotRefund also allows whitelisting trusted users. For example, if a corporate network triggers a false positive, you can add that IP range to a whitelist so it is never flagged again.
How long does BotRefund keep detection data?
The source pack doesn't specify a retention period. Contact BotRefund directly for details on data storage and deletion policies. It is always a good idea to ask vendors about their data lifecycle.
How does the AI model weigh different signals?
The AI model evaluates the complete pattern across all 106 checks. Each signal is weighted based on how strongly it correlates with bot behavior. But the model does not rely on any single signal. It looks for corroboration. For example, a superhuman input speed might be a strong indicator, but if the session also shows humanlike mouse tremor and natural reading time, the model may still classify it as human. The model is trained on real data to balance these factors.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.