TweetStorm

Privacy Policy

Last updated: 24 September 2026

This Privacy Policy explains how TweetStorm (“TweetStorm”, “we”, “us”) collects, uses, shares and protects personal data when you use tweetstorm.ai, the TweetStorm dashboard, our browser extensions, our free logged-out tools, and any related service that links to this policy (together, the “Service”). It also explains the choices and rights you have over that data.

TweetStorm is the data controller for the personal data described here. If you have questions, contact us at support@tweetstorm.ai. This policy does not cover third-party websites we link to, which have their own policies.

What's on this page

At a Glance

  • Who we are. TweetStorm is the data controller for the personal data described here. You can reach us at support@tweetstorm.ai.
  • What we collect. Your account details, the X account you connect, the content you write or generate with our AI tools, tweets you bookmark, billing details from Stripe, and technical data such as IP address and browser type.
  • Why. To run the Service, generate content for you, post and manage content on X on your instruction, take payment, keep the Service secure, and, only with your consent, understand how the site is used.
  • Who we share it with. Our AI providers (Azure OpenAI, with OpenAI as fallback), X, Stripe (payments), Google (sign-in, analytics, reCAPTCHA), Microsoft Clarity, and our hosting, storage and email providers. We do not sell your data.
  • If you delete your account. Bookmarks go immediately, any subscription is cancelled, sign-in is blocked, and the rest of your account data, including connected X tokens, is permanently erased 90 days later. Receipts are kept for accounting law; section 8 lists every retention period.

1. Information We Collect

1.1 Account Data You Give Us

  • Email and password sign-up: your email address and a password. We store the password only as a bcrypt hash and never in readable form.
  • Google or X sign-in: your name and email address as returned by the provider. Sign-in fails if the provider does not return an email address. We do not store Google or X login tokens from sign-in.
  • Profile settings: your time zone (detected automatically or set by you), posting goal, and preferred X handles for the scheduler and bookmark manager.
  • Verification data: short-lived tokens or codes we email to you to verify your address, reset your password or confirm account deletion.

1.2 Connected X Account

Some features (scheduler, bookmark sync, voice profiles, deleting bookmarks on X) need access to your X account. When you connect it, X asks you to authorise TweetStorm with the permissions shown on X's consent screen. We use them to read your bookmarks and remove a bookmark from X when you ask us to (X groups removal under its “write bookmarks” permission; we never add bookmarks), to publish the posts you schedule and upload their media, to read your profile and recent posts, and to keep working while you are away (offline access). We then store:

  • your X user ID, handle and profile picture URL;
  • the access token and refresh token X issues to us, their expiry time and granted scopes;
  • the time zone associated with the account.

We only use these tokens to perform actions you ask for. When you disconnect the account we clear the tokens immediately and stop using them. You can also revoke TweetStorm's access at any time from X's “Connected apps” settings.

1.3 Content You Create and AI Features

  • Prompts and generations: the text and options you enter into the tweet, thread, reply, remix, hashtag, bio and handle generators, in the dashboard or through the AI Tweet Generator extension, and the text the AI returns. Signed-in tweet, thread, reply and remix generations are saved to your history for as long as your account exists. Bio, hashtag and handle generations are not saved.
  • Scheduled posts and drafts: the body of each tweet or thread, its scheduled time and time zone, any media you attach (with its alt text), posting status, failure reasons, the ID X assigns after posting, and basic engagement metrics we fetch back for you.
  • Voice profiles: if you ask us to learn your writing style, we fetch a sample of your own recent public tweets from your connected X account, or use posts you paste in yourself, send them to our AI provider, and keep only the resulting written style summary. The sample posts are discarded after the profile is built.
  • Saved searches: the accounts, keywords, locations and other filters you save in the advanced tweet search.
  • Screenshot presets and extension settings you save in the dashboard or extensions.

Text you submit to AI features is processed by Microsoft Azure OpenAI Service, or by OpenAI when Azure rate-limits a request, solely to return a result to you. Under our agreements with them, these providers do not use your content to train their models.

1.4 Bookmarks and Other People's Data

When you sync bookmarks through the X API or our bookmark extension, we store a copy of each bookmarked post: its text, author name, handle and profile picture, media URLs, post date, engagement counts and any quoted post. We also store the folders, tags and smart folders you organise them into, and read, archive and delete flags.

Most bookmarked posts are written by other people. We obtain this data from X, on your instruction, and process it only so that you can organise, search and manage your own bookmarks. We do not contact the authors, build profiles of them or share their posts beyond your account. If you are the author of a post held in a user's bookmarks and want to exercise your rights, see section 11.

1.5 Subscription and Billing Data

Payments are handled by Stripe. Your card number never reaches our servers. From Stripe we receive and keep:

  • your Stripe customer ID;
  • card brand, last four digits and expiry month and year, so you can recognise the card on file;
  • subscription plan, status, billing period and cancellation state;
  • receipts: amount, tax, currency, date and a link to the Stripe invoice.

We also keep usage counters (credits used, bulk actions, bookmark syncs, scheduled posts) to apply your plan limits.

1.6 Support and Contact Data

If you email us or, while signed in, use the contact form, we receive your email address, subject and message. A live chat widget provided by Tawk.to loads on our pages. When it loads, Tawk.to receives your IP address, browser details and the page you are on, and if you open the chat it also receives what you type there, under Tawk.to's own privacy policy. If the Service hits an error while you are signed in, an automatic report may be sent to our developers containing the page URL, the error and your account email so we can fix the problem.

1.7 Technical and Log Data Collected Automatically

Like most websites, our servers record each request in access logs: IP address, date and time, requested URL, referrer, browser and operating system (user agent) and response status. We use these logs to keep the Service running, detect abuse and investigate faults. They are kept for a short period and are not linked to your account for any other purpose.

1.8 Analytics and Session Analytics Data

With your consent (see section 3) we use Google Analytics 4 to measure page views, traffic sources and feature usage, and Microsoft Clarity to produce heatmaps and anonymised session replays that show how visitors move through pages. IP anonymisation is turned on in Google Analytics. Google Analytics runs only if you accept analytics cookies; Clarity runs only if you accept tracking cookies, and only on public pages, not inside the dashboard.

1.9 Bot and Abuse Protection

Our free logged-out tools and newsletter form are protected by Google reCAPTCHA Enterprise, which analyses browser signals to tell people from bots and is subject to Google's privacy policy. When you first use a free tool we also compute a browser fingerprint in your browser using the open-source FingerprintJS library, combine it with your IP address into a keyed hash, and issue a guest ID stored in the gtn cookie. This lets us recognise the same guest browser and prevent automated abuse without asking you to create an account. Guest tool inputs are processed by our AI provider in the same way as signed-in generations but are not saved to any history.

2. Why We Use Your Information, and Our Legal Basis

Under the GDPR and UK GDPR we need a legal basis for each use of your personal data. The table below lists them.

PurposeData usedLegal basis
Create and run your account, sign you in, verify your emailAccount data, verification tokens, session cookiesPerformance of a contract (our Terms of Service)
Generate tweets, replies, remixes, bios, hashtags and handles with AIPrompts, source text, voice profile, generation historyPerformance of a contract
Schedule and publish posts on X, sync your bookmarks, remove bookmarks from X, all on your instructionConnected X account and tokens, scheduled content, media, bookmarksPerformance of a contract
Take payment, apply plan limits, issue receiptsStripe customer ID, card summary, subscription and usage recordsPerformance of a contract; legal obligation (tax and accounting law)
Send transactional emails (verification, password reset, deletion codes, service notices)Email addressPerformance of a contract
Send product news, feature announcements and newslettersEmail address, subscription preferencesConsent, or our legitimate interest in telling account holders about the product; you can unsubscribe at any time via the link in every email
Keep the Service secure, prevent bots and abuse, debug errorsAccess logs, IP address, guest ID and fingerprint hash, reCAPTCHA results, error reportsLegitimate interest in protecting the Service and its users
Understand how the site is used and improve itAnalytics and session-replay dataConsent (cookie banner)
Respond to support requestsContact and chat dataLegitimate interest in helping our users; contract where you are a customer
Comply with law, enforce our Terms, defend legal claimsAny of the above as necessaryLegal obligation; legitimate interest

Where we rely on legitimate interests we have balanced them against your rights and concluded they are not overridden. You can object at any time (section 11).

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI-generated text is produced on your request and you decide whether to use it.

3. Cookies, Local Storage and Similar Technologies

When you first visit, a cookie banner lets you accept all cookies, keep only essential ones, or customise analytics and tracking cookies separately. Your choice is stored in the cookie-consent cookie for 12 months. Analytics and tracking cookies are not set until you opt in, and if you later withdraw consent, the cookies those tools set on our domain are expired and the tools stop loading. Cookies set on Microsoft's own domains (section 3.3) are outside our control and can only be removed through your browser settings. You can change your choice at any time using the round cookie button in the bottom-left corner of every page.

3.1 Strictly Necessary

These are required for the Service to work and cannot be turned off.

NameTypePurposeLifetime
next-auth.session-tokenFirst partyKeeps you signed in30 days
next-auth.csrf-tokenFirst partyProtects sign-in forms against cross-site request forgerySession
next-auth.callback-urlFirst partyReturns you to the right page after sign-inSession
x_oauth_stateFirst partySecures the X account connection flow10 minutes
gtnFirst partyGuest ID for the free logged-out tools and abuse prevention7 days
cookie-consentFirst partyRemembers your cookie choices12 months

3.2 Analytics (Consent Required)

NameProviderPurposeLifetime
_ga, _ga_*Google Analytics 4Distinguishes visitors and sessions for aggregate usage statisticsUp to 2 years
_gid, _gatGoogle Analytics 4Distinguishes users within a day and throttles request rateUp to 24 hours

3.3 Tracking (Consent Required)

Accepting tracking cookies turns on Microsoft Clarity and grants Google Consent Mode's advertising storage signal (ad_storage), so Google may store advertising-related cookies alongside the analytics cookies above. We do not run third-party ad networks on the Service. If you reject tracking, this signal stays denied and Clarity never loads.

NameProviderPurposeLifetime
_clck, _clsk, CLIDMicrosoft ClarityIdentifies a visitor and session for heatmaps and session replayUp to 1 year
ANONCHK, MR, MUID, SMMicrosoftSet by Clarity through Microsoft domains to sync identifiers and detect botsUp to 1 year
_gcl_*GoogleAttributes visits when advertising signals are grantedUp to 90 days

3.4 Third-Party Cookies We Do Not Control

  • Stripe sets fraud-prevention cookies (for example __stripe_mid, __stripe_sid) during checkout.
  • Google reCAPTCHA Enterprise sets _GRECAPTCHA when a protected form loads.
  • Tawk.to live chat sets cookies (for example TawkConnectionTime, twk_*) to keep a chat session open.
  • Images and videos from X that we display in the bookmark manager and other tools are loaded from X's media servers and may carry X's own cookies.

These providers control their own cookies. You can block or delete them through your browser settings, though some features (such as checkout) may then stop working.

3.5 Local Storage

We store a few preferences in your browser's local storage rather than in cookies: your light or dark theme, whether a guest session has been set up, your selected scheduler account, the billing tab you last viewed and recently used emojis. This data never leaves your browser.

4. Free Tools, Plans and Credits

Plan features, credits and prices are described on the pricing page and governed by our Terms of Service. This section covers only what each affects about your data.

4.1 Free Tools Without an Account

The logged-out tweet, remix, hashtag, bio and handle generators need no account. They use the guest ID, fingerprint hash and reCAPTCHA described in section 1.9. Your inputs are sent to our AI provider to produce a result and are not saved to any history on our side.

The advanced tweet search, the video downloader and the post screenshot tool also need no account. The advanced search builds an X search link in your browser and sends nothing to us. When you submit a post URL to the video downloader or screenshot tool, our server fetches that post's public content and media from X to produce the file, then returns it to you. We do not save the URL, the post or the file, beyond the access logs described in section 1.7.

4.2 Free Plan

Signing up gives you a free plan with a limited number of AI credits and access to the dashboard bio, hashtag and handle generators. Dashboard generations are saved to your history; the free bio, hashtag and handle tools are not.

Professional, Agency and Elite plans unlock more AI credits, scheduling, bulk-action and screenshot features. The separate Bookmark Manager plans unlock bookmark storage, automatic sync through the X API, bookmark removal on X and export. Paying creates the Stripe records described in section 1.5. Customers who need additional data processing terms may agree them with us in writing; where they conflict with this policy, those terms prevail for that customer.

4.4 Browser Extensions

Our browser extensions run inside X in your browser. The bookmark extension reads the bookmarks page you are viewing and sends them to your TweetStorm account using your signed-in dashboard session. The AI Tweet Generator extension sends the prompts and posts you ask it to write or reply to, together with an extension API key generated in your dashboard, to our servers; these generations use your plan's credits and are saved to your history like dashboard generations. The Mass Tweet Deletions extension performs deletes, unlikes, unfollows and similar actions locally in your browser on your instruction and reports only the count of actions run, using the same API key, so we can apply your plan limits. Extensions do not collect browsing data from other websites. Each extension's store listing describes its permissions.

5. Cancelling a Subscription

You can cancel any subscription from the billing page. When you do:

  • the subscription stays active until the end of the period you have already paid for, and you can resume it before then;
  • after that date your account moves to the free plan; your account, generations, bookmarks and scheduled content are kept unless you delete them or your account;
  • Stripe retains the transaction records it is legally required to keep; we keep receipts as described in section 8.

Refunds, if any, are handled according to the Terms of Service.

6. Who We Share Your Information With

We do not sell personal data, and we do not share it with third parties for their own marketing. We share it only with the providers below, each acting on our instructions under a data processing agreement, or where the law requires.

RecipientWhyWhat they receive
Microsoft Azure OpenAI Service; OpenAI (fallback)AI text generation and voice profilesPrompts, source text, sampled tweets, voice profile summaries
X Corp. (X API and public endpoints)Connecting your account, posting, bookmark sync, removing bookmarks, fetching metrics, fetching public posts for the video downloader and screenshot toolYour X tokens, the content you schedule, bookmark read and removal requests, post URLs you submit to the downloader and screenshot tool
StripePayments and subscription managementEmail, plan, payment details entered on Stripe pages
Wasabi (object storage)Storing media you attach to scheduled postsUploaded images and videos, keyed by your user ID
PostmarkTransactional email deliveryEmail address and email content
Our newsletter service (built on Ghost)Holding the subscriber list for the weekly blog digest and feature announcementsEmail address and the streams you are subscribed to
Amazon Web Services (Simple Email Service)Sending the weekly blog digest and feature announcement emailsEmail address and email content
MailerLiteProduct news and marketing emails to account holdersEmail address, added when you verify your email address
Google (Analytics, reCAPTCHA Enterprise, sign-in)Usage analytics (with consent), bot protection, Google loginAnalytics events, browser signals, Google account email and name at sign-in
Microsoft ClarityHeatmaps and session replay (with consent)Page interactions with sensitive fields masked
Tawk.toLive chat supportIP address, browser details and page visited when the widget loads; chat messages if you use it
Hosting, database and Redis infrastructure providersRunning the ServiceAll data stored by the Service, under access controls

We may also disclose personal data if required by law, court order or a lawful request from a public authority, to enforce our Terms, or to protect the rights, property or safety of TweetStorm, our users or others. If TweetStorm is involved in a merger, acquisition or asset sale, your data may transfer to the new owner, who must honour this policy.

7. International Transfers

Our providers, Microsoft (Azure OpenAI and Clarity), OpenAI, X, Stripe, Google, Amazon Web Services, Wasabi, Postmark, MailerLite and Tawk.to, operate globally, so your data may be processed outside your country, including in the United States. Where data leaves the EEA or the UK, transfers rely on the European Commission and UK adequacy decisions where they apply, or on Standard Contractual Clauses with additional safeguards. You can ask us for details of the mechanism used for a specific transfer.

8. How Long We Keep Your Data

DataRetention
Account dataWhile your account is active, then per section 9
Generation historyUntil your account is deleted
Saved searches, drafts, scheduled postsUntil you delete them or your account is deleted
Connected X tokensUntil you disconnect the account, when they are cleared immediately, or 90 days after you delete your account
Voice profileUntil you delete it, or 90 days after you delete your account; paused while its X account is disconnected and restored if you reconnect
Bookmarks, folders, tagsUntil you delete them; removed immediately when you delete your account
Scheduled post mediaWhile your account exists, then erased with it 90 days after deletion; files rejected by X are deleted within about a week
Receipts and subscription recordsUp to 7 years after the transaction, to meet accounting and tax obligations
Verification, reset and deletion codesEmail verification links 2 hours, password reset links 1 hour, account deletion codes 24 hours; expired codes are rejected and replaced when you request a new one
Accounts that never verify their email addressDeleted by a nightly job, normally within 24 hours of sign-up
Support and contact emailsUp to 2 years after the matter is closed
Server access logsRotated on a short cycle, normally no more than 30 days
Guest ID, IP address and fingerprint hash (free tools)Guest cookie 7 days; server records kept only as long as needed for abuse prevention and then deleted
Cookie consent record12 months
Analytics and session-replay dataPer Google and Microsoft retention settings, at most 14 months

9. Deleting Your Account

You can delete your account from your profile page. Password accounts confirm with the password; Google and X sign-in accounts confirm with a code we email you. When you delete:

  • any active subscription is cancelled and your Stripe customer record is deleted;
  • bookmarks, folders, tags and smart folders are deleted immediately, and your credit balance is cleared;
  • you can no longer sign in, and your extension API key stops working;
  • the rest of your account data, including connected X accounts and their tokens, scheduled posts, voice profiles, media and generation history, is scheduled for permanent deletion 90 days after your request. During that window we keep it only to handle disputes, fraud and legal obligations, and to let you recover the account by contacting us if the deletion was a mistake. To cut TweetStorm's access to your X account sooner, disconnect it on your profile page before you delete, or revoke it from X's “Connected apps” settings;
  • Stripe keeps transaction records it is legally required to retain, and we keep receipts as set out in section 8;
  • analytics data already collected is anonymous and cannot be linked back to you, so it is not deleted.

Deleting your TweetStorm account does not delete anything on X. Posts we published on your behalf remain on X unless you remove them there.

10. Security

  • All traffic to the Service is encrypted with HTTPS.
  • Passwords are hashed with bcrypt and never stored in plain text.
  • Session and guest cookies are httpOnly and secure, so scripts on the page cannot read them.
  • Card details are handled entirely by Stripe, a PCI DSS Level 1 provider.
  • Access to production systems is limited to staff who need it and protected by key-based authentication.
  • Media uploads go directly from your browser to storage using short-lived signed URLs scoped to your account.

No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authority where the law requires, without undue delay.

11. Your Rights (GDPR and UK GDPR)

If you are in the European Economic Area, the United Kingdom or another place with similar laws, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate data. Most account data can be edited on your profile page.
  • Erase your data, subject to legal exceptions (section 9).
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Port data you provided to us in a machine-readable format. Bookmark Manager plans that include export let you download your bookmarks from the bookmark manager; for anything else, or if your plan has no export, ask us and we will send you a copy.
  • Withdraw consent for analytics and tracking cookies and marketing emails at any time, without affecting earlier processing.
  • Complain — lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).

To exercise a right, email support@tweetstorm.ai from the address on your account, or include enough detail for us to verify you. We respond within one month, extendable by two months for complex requests, and free of charge unless a request is manifestly unfounded or excessive. Authors of posts held in users' bookmarks may also contact us; we will explain what we hold and act on valid requests.

12. Your Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to. Sections 1, 2 and 6 describe these. In the last 12 months we collected identifiers, commercial information, internet activity and user-generated content as described above.
  • Delete your personal information (section 9).
  • Correct inaccurate personal information.
  • Opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising. Rejecting tracking cookies in the banner prevents the advertising signals described in section 3.3.
  • Limit use of sensitive personal information. The only sensitive information we hold is your account login credentials, used solely to provide the Service.
  • Non-discrimination for exercising any of these rights.

Submit requests to support@tweetstorm.ai. We verify requests by matching the email on your account and respond within 45 days, extendable once by a further 45 days with notice. You may use an authorised agent if they provide signed permission from you.

13. Children

The Service is not directed at children. You must be at least 13 years old to use it, or 16 where local law sets that age for consenting to online services without a parent. We do not knowingly collect personal data from children below those ages. If you believe a child has created an account, contact us and we will delete it.

14. Changes to This Policy

We may update this policy as the Service or the law changes. The date at the top shows the latest version. For material changes we will give notice in the dashboard or by email before the change takes effect. Continuing to use the Service after that date means you accept the updated policy; this does not reduce any right you have under applicable law.

15. Contact Us

Privacy questions and rights requests: support@tweetstorm.ai. Signed-in users can also use the contact form. See also our Terms of Service and pricing.