Privacy Policy
Last updated 3 August 2026
This explains what xpush.app stores when you use the service, who processes it on our behalf, and how to get rid of it.
What we store
- Account — the email address from your Google sign-in, your display name, and your plan.
- X connection — your X user id, handle, and the OAuth access and refresh tokens for the account you connect. Tokens are encrypted at rest (AES-256-GCM) and are used only to publish posts you scheduled and to read metrics for your own posts.
- Your content — drafts, scheduled posts, any images you attach, your brand profile and voice settings, and notes you write about accounts you follow up with.
- Chrome extension — the post text, optional author handle, and reply angle you explicitly submit for generation. A revocable browser credential is stored in Chrome local storage; our database stores only its SHA-256 hash, last-used time, and revocation state.
- Public X data — posts and profile details of accounts you choose to track or reply to. This is public information, fetched on your behalf.
- Usage — credit spend, what each action cost us, and anonymous product analytics about which steps of sign-up people complete.
We do not store card numbers. Payment details are handled entirely by Polar.
Who processes it
- Supabase — database and authentication.
- Vercel — hosting, plus Web Analytics and Speed Insights: page views, referrers, and how fast pages loaded for you. Both are measured without cookies and without following you across other sites.
- Polar — subscriptions and payments.
- Google (Gemini), Anthropic (Claude) and Groq — AI generation. The text you ask us to write or improve is sent to one of these when you press generate.
- X — publishing to your connected account.
- twitterapi.io — reading public posts and profiles.
These are the only parties we share data with, and only to the extent each needs to do its job. We do not sell your data, and we do not use your content to train AI models.
How long we keep it
Your account data stays while your account exists. Public X data we fetched on your behalf is cached and refreshed as you use the product. Records of what actions cost are kept for billing and accounting. Extension credentials remain until you disconnect that browser, delete your account, we revoke them for security, or their 90-day lifetime expires. One-time connection codes expire after 60 seconds and are removed during credential cleanup.
Chrome Web Store Limited Use
The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to authenticate the browser, show the account’s subscription and credits, generate the reply the user requested, secure the service, and measure reliability and cost.
We do not use extension data for advertising or profiling, and we do not sell it. We transfer it only to processors needed to provide the feature, or where required for security or law. A person reads user content only with the user’s consent for support, when necessary to investigate abuse or security, or when required by law.
Your choices
- Disconnect X at any time from the Profile page. We delete the stored tokens immediately and can no longer publish for you. You can also revoke access from X’s own connected-apps settings.
- Disconnect the extension from its Settings screen. This revokes that browser credential.
- Delete your account by contacting us through the Support page. This removes your account, your content, and your X and extension credentials.
- Ask for a copy or a correction of what we hold about you through the Support page.
Security
X tokens are encrypted before they are written to the database. Website sessions are signed, HTTP-only cookies. Chrome extension credentials are random, revocable, and stored only as hashes on our server. Access to production data is limited to the people who operate the service. No system is perfect; if we ever discover a breach affecting your data we will tell you.
Changes and contact
If we add a service that processes your data, this page changes with it. Questions or requests can be sent through our Support page.
