PureAutoLike Privacy Policy
Last updated: July 20, 2026
PureAutoLike is a browser extension and an iOS companion for people who use Pure Web. It can automate likes, provide optional Telegram and iOS notifications, and keep multiple Pure Web accounts in isolated local profiles. PureAutoLike does not sell personal data or use it for advertising or cross-company tracking.
Data Processed In The Browser
PureAutoLike runs content scripts only on https://pure.app/*. Inside that page, the extension may process visible Pure page content, visible profile text, buttons, photo placeholders, chat and match events, and user interaction state needed to operate the extension.
The extension stores settings in browser extension storage. These settings can include feature toggles, local counters, Telegram notification settings, and a locally generated installation id for beta/license checks.
If Telegram notifications are enabled, the Telegram bot token and chat id entered by the user are stored in local browser extension storage and are sent to the Telegram Bot API only to send test notifications or selected Pure event alerts.
If local profile capture is enabled, visible profile status, age, descriptions, capture timestamps, and the current Pure page URL are stored locally in browser extension storage. They are exported only when the user clicks the Markdown export button and can be cleared by the user.
The Pure authorization header can be observed inside the active Pure page at runtime so the hidden photo opener can make Pure API/CDN requests already available to the logged-in web session. This value is kept in page memory for that runtime task and is not stored in extension settings.
Mobile App Data
The iOS app displays Pure Web inside isolated WebKit profiles. Each local Pure account has a separate website data store. Pure cookies, authorization credentials, and web-session state stay inside that profile's app container and are not sent to the PureAutoLike beta-access service merely because the profile is opened.
If the user presses Pure's location button and grants the iOS permission, the embedded Pure page can receive the device's precise foreground location to show nearby profiles. PureAutoLike does not request background location and does not send location to its license, Telegram, or notification services. Pure processes it as part of the user's Pure Web session.
The beta-access service receives a random installation identifier, an installation public signing key, trial timestamps, app version, and release channel. When Telegram is linked, the service associates the installation with that Telegram account only to authenticate the app and check membership in the beta channel.
Telegram registration may process the Telegram user and chat identifiers, display name, username, profile-photo URL supplied by Telegram, and the device's public cryptographic keys. Private device keys and the user's Telegram password never leave the device.
If iOS notifications are enabled, the app sends an APNs device token, a random notification installation identifier, random local Pure-profile identifiers, APNs environment, bundle identifier, and app version to the PureAutoLike notification service. Notification registration does not contain a Pure password, authorization header, or session cookie.
Data Sent To PureAutoLike Services
The extension contacts the PureAutoLike license endpoint to support beta access now and paid access in the future. License requests may include a locally generated installation id, the extension id, the extension version, and the release channel.
If paid access is enabled later, subscription checks may also use an email address or payment customer id that the user provides through the payment flow. PureAutoLike does not process payment card numbers directly.
When the optional hosted Telegram bridge is connected, PureAutoLike services process selected match or message events long enough to deliver them. The relay uses opaque conversation and deduplication identifiers and does not receive the Pure password or raw conversation identifier. Successfully delivered message bodies are not retained in the relay database. Telegram retains delivered messages under the user's Telegram account and Telegram's policies.
The separately consented cloud gateway test can process an encrypted Pure session credential for owner-operated test accounts. The gateway decrypts it only in gateway memory to operate the requested session. This is encrypted transport, not end-to-end encryption, because the gateway must use the credential. It is not enabled for general users.
Data Sent To Third Parties
PureAutoLike sends data to third parties only for requested app functionality: Pure Web and Pure API/CDN endpoints operate the active Pure session, Telegram Bot API supports registration and enabled alerts, Apple Push Notification service delivers enabled iOS notifications, and a payment provider may be used later for paid subscription checkout.
PureAutoLike does not sell user data. PureAutoLike does not use user data for advertising, creditworthiness, lending, or unrelated profiling.
Remote Code
The extension does not execute remote JavaScript or WebAssembly. Extension code is packaged with the browser extension. The iOS app intentionally displays the user-facing Pure Web application in WebKit; Pure's first-party web code runs only inside the selected isolated Pure profile. PureAutoLike service responses are treated as data, not executable code.
User Control
Users can disable notifications and local profile capture, clear locally captured notes, disconnect the hosted Telegram bridge, and remove individual isolated Pure Web profiles. Removing the extension or clearing its storage removes extension-local data.
In the iOS personal cabinet, Delete PureAutoLike account permanently removes the Telegram link, device sessions and public keys, topic mappings, cloud state, encrypted queues, delivery receipts, and the APNs token and Pure-profile bindings from the mobile push registration associated with that PureAutoLike account. To prevent a network request already in flight from recreating a deleted push registration, the service retains only the random notification installation id, its one-way credential hash, and revocation time for up to 30 days; scheduled maintenance then deletes that tombstone. It does not delete the user's separate Pure or Telegram accounts. The anonymous installation's original beta-trial timestamps remain unlinked from Telegram only to prevent repeated trial creation; any subscriber grant is removed. Local Pure Web profiles remain separately removable from the app's Pure account manager.
Contact
For support or privacy questions, use GitHub Issues: github.com/zgnme/pureautolike/issues.