Privacy Policy
Last updated: May 17, 2026.
Tweet.md stores the minimum data needed to manage profiles, convert posts, manage credits, prevent abuse, send requested email, and fulfill payments.
Data we process
- X post identifiers and normalized public post data cached for up to 24 hours.
- IP addresses, request metadata, and abuse-prevention signals for conversion and demo traffic.
- Profile names, email addresses, verification status, authentication provider identifiers, sessions, and password hashes when you choose email/password login.
- API key hashes, prefixes, ownership, account balances, usage events, and Stripe checkout references.
- Email delivery history, low-credit reminder state, and product-email preferences. Claim and direct top-up links are not retained in plaintext delivery history.
Secrets
Raw API keys are not stored in plaintext. One-time browser delivery keys are encrypted, short-lived, and purged. Claim, direct top-up, and admin-impersonation tokens are stored only as hashes. Passwords are handled by Better Auth and stored only as password hashes.
Deleting your profile
Deleting your profile removes your sign-in — sessions, password hash, and connected login providers — revokes every API key on it, forfeits any remaining credits, and releases your email address so it can be used to sign up again. Usage events, payments, and the credit ledger are retained for accounting, relabelled as a deleted profile; that label keeps your email address so past payments stay reconcilable.
Contact
Questions and removal requests can be sent to [email protected].