Botfilter
Botfilter flags AI generated text on websites you visit. Filter AI slop in your feeds, AI spam in your inbox, AI generated articles, and more.
- Choose how it looks: "Outline" flags in place, "Collapse" folds a post to a one-line label, "Hide" removes it.
- Choose how much it flags: "Fewer", "Balanced", or "More".
- Flags posts, comments, and emails on X, Reddit, LinkedIn, Gmail, YouTube, and Hacker News. Flags paragraphs on every other website. Disable for any site from the toolbar button.
Botfilter is a free and private alternative to Pangram. It uses a specially trained AI model small enough to run in your browser. Everything runs on your device. No page text, score, or usage ever leaves your browser. No account required.
The model scores English text as a calibrated probability of being AI-written. A score can be wrong and should not be used as proof of authorship.
Each releases/<version>/ directory contains the ONNX model, the WordPiece vocabulary, the calibration settings, and a lockfile with SHA-256 checksums. Use all files from the same version. The extension’s inference implementation defines preprocessing, window aggregation, and calibration; these files do not provide a Transformers pipeline.
minilm-l6-v5-20260928
- Base:
nreimers/MiniLM-L6-H384-uncased(MIT), fine-tuned as a two-class classifier. 22.7M parameters, weight-only int8, 23.6 MB. - Input: text folded with normalizer 2 (plain quotes and dashes, look-alike letters mapped to Latin), then WordPiece tokens in up to two 256-token windows, the start and the end of the text. The score is the mean logit margin across windows.
- Output:
calibration.jsonholds the temperature that turns the margin into a probability, and margin thresholds for three settings, Fewer, Balanced, and More, for texts of 25–80 words and longer texts. Texts under 25 words are not scored.
Training data
Human text: the v4 sources (Common Pile news with per-document CC BY 4.0, Foodista CC BY 3.0, UK Hansard under the Open Parliament Licence, HH-RLHF MIT) plus owner-approved casual pools at pre-ChatGPT trust tiers: webis/tldr-17 Reddit 2006–2016 (CC BY 4.0), Enron email (FERC public record), Common Pile GitHub discussion (permissive repository licenses), and FineWeb pages (ODC-BY 1.0). AI text: 26,227 generations from eight Apache-2.0 or MIT open models run by the project (Qwen3, Phi-4, Mistral 7B and Small 24B, OLMo 2, SmolLM3) and seven API models (GPT-6 Sol, GPT-5.5, GPT-5.6 Terra, Claude Sonnet 5, Claude Opus 5.5, Claude Haiku 4.5, Mistral Medium 3.5), written in the same registers as the human text, including LinkedIn- and X-style posts.
Evaluation
Sealed test split, Balanced setting, measured once after the thresholds were set:
| Text | Flagged as likely AI-written |
|---|---|
| Human news, blog, parliamentary, and chat text | 0.3–0.5% |
| Human Reddit posts | 0.5% |
| Human work email | 1.6% |
| Human GitHub discussion and web pages | 1.2–1.8% |
| AI text from the eight open models | 97% |
| AI text from Granite 3.3 and Gemini 3.8 Flash, never trained on | 99% and 94% |
| AI text from Claude Sonnet 5, Opus 5.5, Haiku 4.5 | 96% |
| AI text from GPT-6 Sol, GPT-5.5, GPT-5.6 Terra | 96% |
The sealed evaluation results, training recipe, and source rights review describe this exact release. The source repository currently requires access; those evidence links are unavailable to anonymous readers.
Limits
AI-written posts under 80 words are harder: 91–96% are flagged at Balanced. Human posts from X and LinkedIn were not available with suitable rights, so false-positive rates there are unmeasured. Text that a person and a model both edited is often missed. Non-English text is out of scope.
minilm-l6-v4-20260928
- Base:
nreimers/MiniLM-L6-H384-uncased(MIT), fine-tuned as a two-class classifier. 22.7M parameters, weight-only int8, 23.6 MB. - Input: text folded with normalizer 2 (plain quotes and dashes, look-alike letters mapped to Latin), then WordPiece tokens in up to two 256-token windows, the start and the end of the text. The score is the mean logit margin across windows.
- Output:
calibration.jsonholds the temperature that turns the margin into a probability, and margin thresholds for three settings, Fewer, Balanced, and More, for texts of 25–80 words and longer texts. Texts under 25 words are not scored.
Training data
Human text: openly licensed news articles from Common Pile (only documents whose metadata records CC BY 4.0), Foodista food blog posts (CC BY 3.0), UK Parliament Hansard debates, and messages crowdworkers wrote in Anthropic's HH-RLHF dataset (MIT). AI text: 6,443 generations from eight Apache-2.0 or MIT open models run by the project (Qwen3, Phi-4, Mistral 7B and Small 24B, OLMo 2, SmolLM3) and seven API models (GPT-6 Sol, GPT-5.5, GPT-5.6 Terra, Claude Sonnet 5, Claude Opus 5.5, Claude Haiku 4.5, Mistral Medium 3.5), written in the same registers as the human text.
Evaluation
Sealed test split, Balanced setting, measured once after the thresholds were set:
| Text | Flagged as likely AI-written |
|---|---|
| Human news, blog, parliamentary, and chat text | 0.1–0.4% |
| Human Reddit posts, never trained on | 0.7% |
| Human work email, never trained on | 1.3% |
| Human GitHub discussion and web pages, never trained on | 2.0–2.2% |
| AI text from the eight open models | 94% |
| AI text from Granite 3.3 and Gemini 3.8 Flash, never trained on | 97% and 88% |
| AI text from Claude Sonnet 5, Opus 5.5, Haiku 4.5 | 82% |
| AI text from GPT-6 Sol, GPT-5.5, GPT-5.6 Terra | 65% |
Limits
AI-written posts under 80 words are harder: 82% of short AI social posts are flagged at Balanced. Human posts from X and LinkedIn were not available with suitable rights, so false-positive rates there are unmeasured. Text that a person and a model both edited is often missed. Non-English text is out of scope.
Attribution
Contains Parliamentary information licensed under the Open Parliament Licence v3.0. Trained on CC BY 4.0 news articles from the Common Pile news collection and CC BY 3.0 posts by Foodista contributors, and on Anthropic HH-RLHF (MIT).
The v5 model also uses the Webis group’s TL;DR corpus (CC BY 4.0), the Enron email corpus (FERC public record), Common Pile GitHub discussions from repositories with permissive licenses, and FineWeb by Hugging Face (ODC-BY 1.0). These casual sources were admitted under their distributors’ licenses or releases with the owner’s approval; upstream author-level terms were not individually cleared. Only trained model files are distributed here.
Model tree for hranesscom/botfilter
Base model
nreimers/MiniLM-L6-H384-uncased