Privacy Policy
Last updated: 24 September 2026
This Privacy Policy explains how TweetStorm (“TweetStorm”, “we”, “us”) collects, uses, shares and protects personal data when you use tweetstorm.ai, the TweetStorm dashboard, our browser extensions, our free logged-out tools, and any related service that links to this policy (together, the “Service”). It also explains the choices and rights you have over that data.
TweetStorm is the data controller for the personal data described here. If you have questions, contact us at support@tweetstorm.ai. This policy does not cover third-party websites we link to, which have their own policies.
What's on this page
At a Glance
- Who we are. TweetStorm is the data controller for the personal data described here. You can reach us at support@tweetstorm.ai.
- What we collect. Your account details, the X account you connect, the content you write or generate with our AI tools, tweets you bookmark, billing details from Stripe, and technical data such as IP address and browser type.
- Why. To run the Service, generate content for you, post and manage content on X on your instruction, take payment, keep the Service secure, and, only with your consent, understand how the site is used.
- Who we share it with. Our AI providers (Azure OpenAI, with OpenAI as fallback), X, Stripe (payments), Google (sign-in, analytics, reCAPTCHA), Microsoft Clarity, and our hosting, storage and email providers. We do not sell your data.
- If you delete your account. Bookmarks go immediately, any subscription is cancelled, sign-in is blocked, and the rest of your account data, including connected X tokens, is permanently erased 90 days later. Receipts are kept for accounting law; section 8 lists every retention period.
1. Information We Collect
1.1 Account Data You Give Us
- Email and password sign-up: your email address and a password. We store the password only as a bcrypt hash and never in readable form.
- Google or X sign-in: your name and email address as returned by the provider. Sign-in fails if the provider does not return an email address. We do not store Google or X login tokens from sign-in.
- Profile settings: your time zone (detected automatically or set by you), posting goal, and preferred X handles for the scheduler and bookmark manager.
- Verification data: short-lived tokens or codes we email to you to verify your address, reset your password or confirm account deletion.
1.2 Connected X Account
Some features (scheduler, bookmark sync, voice profiles, deleting bookmarks on X) need access to your X account. When you connect it, X asks you to authorise TweetStorm with the permissions shown on X's consent screen. We use them to read your bookmarks and remove a bookmark from X when you ask us to (X groups removal under its “write bookmarks” permission; we never add bookmarks), to publish the posts you schedule and upload their media, to read your profile and recent posts, and to keep working while you are away (offline access). We then store:
- your X user ID, handle and profile picture URL;
- the access token and refresh token X issues to us, their expiry time and granted scopes;
- the time zone associated with the account.
We only use these tokens to perform actions you ask for. When you disconnect the account we clear the tokens immediately and stop using them. You can also revoke TweetStorm's access at any time from X's “Connected apps” settings.
1.3 Content You Create and AI Features
- Prompts and generations: the text and options you enter into the tweet, thread, reply, remix, hashtag, bio and handle generators, in the dashboard or through the AI Tweet Generator extension, and the text the AI returns. Signed-in tweet, thread, reply and remix generations are saved to your history for as long as your account exists. Bio, hashtag and handle generations are not saved.
- Scheduled posts and drafts: the body of each tweet or thread, its scheduled time and time zone, any media you attach (with its alt text), posting status, failure reasons, the ID X assigns after posting, and basic engagement metrics we fetch back for you.
- Voice profiles: if you ask us to learn your writing style, we fetch a sample of your own recent public tweets from your connected X account, or use posts you paste in yourself, send them to our AI provider, and keep only the resulting written style summary. The sample posts are discarded after the profile is built.
- Saved searches: the accounts, keywords, locations and other filters you save in the advanced tweet search.
- Screenshot presets and extension settings you save in the dashboard or extensions.
Text you submit to AI features is processed by Microsoft Azure OpenAI Service, or by OpenAI when Azure rate-limits a request, solely to return a result to you. Under our agreements with them, these providers do not use your content to train their models.
1.4 Bookmarks and Other People's Data
When you sync bookmarks through the X API or our bookmark extension, we store a copy of each bookmarked post: its text, author name, handle and profile picture, media URLs, post date, engagement counts and any quoted post. We also store the folders, tags and smart folders you organise them into, and read, archive and delete flags.
Most bookmarked posts are written by other people. We obtain this data from X, on your instruction, and process it only so that you can organise, search and manage your own bookmarks. We do not contact the authors, build profiles of them or share their posts beyond your account. If you are the author of a post held in a user's bookmarks and want to exercise your rights, see section 11.
1.5 Subscription and Billing Data
Payments are handled by Stripe. Your card number never reaches our servers. From Stripe we receive and keep:
- your Stripe customer ID;
- card brand, last four digits and expiry month and year, so you can recognise the card on file;
- subscription plan, status, billing period and cancellation state;
- receipts: amount, tax, currency, date and a link to the Stripe invoice.
We also keep usage counters (credits used, bulk actions, bookmark syncs, scheduled posts) to apply your plan limits.
1.6 Support and Contact Data
If you email us or, while signed in, use the contact form, we receive your email address, subject and message. A live chat widget provided by Tawk.to loads on our pages. When it loads, Tawk.to receives your IP address, browser details and the page you are on, and if you open the chat it also receives what you type there, under Tawk.to's own privacy policy. If the Service hits an error while you are signed in, an automatic report may be sent to our developers containing the page URL, the error and your account email so we can fix the problem.
1.7 Technical and Log Data Collected Automatically
Like most websites, our servers record each request in access logs: IP address, date and time, requested URL, referrer, browser and operating system (user agent) and response status. We use these logs to keep the Service running, detect abuse and investigate faults. They are kept for a short period and are not linked to your account for any other purpose.
1.8 Analytics and Session Analytics Data
With your consent (see section 3) we use Google Analytics 4 to measure page views, traffic sources and feature usage, and Microsoft Clarity to produce heatmaps and anonymised session replays that show how visitors move through pages. IP anonymisation is turned on in Google Analytics. Google Analytics runs only if you accept analytics cookies; Clarity runs only if you accept tracking cookies, and only on public pages, not inside the dashboard.
1.9 Bot and Abuse Protection
Our free logged-out tools and newsletter form are protected by Google reCAPTCHA Enterprise, which analyses browser signals to tell people from bots and is subject to Google's privacy policy. When you first use a free tool we also compute a browser fingerprint in your browser using the open-source FingerprintJS library, combine it with your IP address into a keyed hash, and issue a guest ID stored in the gtn cookie. This lets us recognise the same guest browser and prevent automated abuse without asking you to create an account. Guest tool inputs are processed by our AI provider in the same way as signed-in generations but are not saved to any history.
2. Why We Use Your Information, and Our Legal Basis
Under the GDPR and UK GDPR we need a legal basis for each use of your personal data. The table below lists them.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account, sign you in, verify your email | Account data, verification tokens, session cookies | Performance of a contract (our Terms of Service) |
| Generate tweets, replies, remixes, bios, hashtags and handles with AI | Prompts, source text, voice profile, generation history | Performance of a contract |
| Schedule and publish posts on X, sync your bookmarks, remove bookmarks from X, all on your instruction | Connected X account and tokens, scheduled content, media, bookmarks | Performance of a contract |
| Take payment, apply plan limits, issue receipts | Stripe customer ID, card summary, subscription and usage records | Performance of a contract; legal obligation (tax and accounting law) |
| Send transactional emails (verification, password reset, deletion codes, service notices) | Email address | Performance of a contract |
| Send product news, feature announcements and newsletters | Email address, subscription preferences | Consent, or our legitimate interest in telling account holders about the product; you can unsubscribe at any time via the link in every email |
| Keep the Service secure, prevent bots and abuse, debug errors | Access logs, IP address, guest ID and fingerprint hash, reCAPTCHA results, error reports | Legitimate interest in protecting the Service and its users |
| Understand how the site is used and improve it | Analytics and session-replay data | Consent (cookie banner) |
| Respond to support requests | Contact and chat data | Legitimate interest in helping our users; contract where you are a customer |
| Comply with law, enforce our Terms, defend legal claims | Any of the above as necessary | Legal obligation; legitimate interest |
Where we rely on legitimate interests we have balanced them against your rights and concluded they are not overridden. You can object at any time (section 11).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI-generated text is produced on your request and you decide whether to use it.
3. Cookies, Local Storage and Similar Technologies
When you first visit, a cookie banner lets you accept all cookies, keep only essential ones, or customise analytics and tracking cookies separately. Your choice is stored in the cookie-consent cookie for 12 months. Analytics and tracking cookies are not set until you opt in, and if you later withdraw consent, the cookies those tools set on our domain are expired and the tools stop loading. Cookies set on Microsoft's own domains (section 3.3) are outside our control and can only be removed through your browser settings. You can change your choice at any time using the round cookie button in the bottom-left corner of every page.
3.1 Strictly Necessary
These are required for the Service to work and cannot be turned off.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
next-auth.session-token | First party | Keeps you signed in | 30 days |
next-auth.csrf-token | First party | Protects sign-in forms against cross-site request forgery | Session |
next-auth.callback-url | First party | Returns you to the right page after sign-in | Session |
x_oauth_state | First party | Secures the X account connection flow | 10 minutes |
gtn | First party | Guest ID for the free logged-out tools and abuse prevention | 7 days |
cookie-consent | First party | Remembers your cookie choices | 12 months |
3.2 Analytics (Consent Required)
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
_ga, _ga_* | Google Analytics 4 | Distinguishes visitors and sessions for aggregate usage statistics | Up to 2 years |
_gid, _gat | Google Analytics 4 | Distinguishes users within a day and throttles request rate | Up to 24 hours |
3.3 Tracking (Consent Required)
Accepting tracking cookies turns on Microsoft Clarity and grants Google Consent Mode's advertising storage signal (ad_storage), so Google may store advertising-related cookies alongside the analytics cookies above. We do not run third-party ad networks on the Service. If you reject tracking, this signal stays denied and Clarity never loads.
| Name | Provider | Purpose | Lifetime |
|---|---|---|---|
_clck, _clsk, CLID | Microsoft Clarity | Identifies a visitor and session for heatmaps and session replay | Up to 1 year |
ANONCHK, MR, MUID, SM | Microsoft | Set by Clarity through Microsoft domains to sync identifiers and detect bots | Up to 1 year |
_gcl_* | Attributes visits when advertising signals are granted | Up to 90 days |
3.4 Third-Party Cookies We Do Not Control
- Stripe sets fraud-prevention cookies (for example
__stripe_mid,__stripe_sid) during checkout. - Google reCAPTCHA Enterprise sets
_GRECAPTCHAwhen a protected form loads. - Tawk.to live chat sets cookies (for example
TawkConnectionTime,twk_*) to keep a chat session open. - Images and videos from X that we display in the bookmark manager and other tools are loaded from X's media servers and may carry X's own cookies.
These providers control their own cookies. You can block or delete them through your browser settings, though some features (such as checkout) may then stop working.
3.5 Local Storage
We store a few preferences in your browser's local storage rather than in cookies: your light or dark theme, whether a guest session has been set up, your selected scheduler account, the billing tab you last viewed and recently used emojis. This data never leaves your browser.
4. Free Tools, Plans and Credits
Plan features, credits and prices are described on the pricing page and governed by our Terms of Service. This section covers only what each affects about your data.
4.1 Free Tools Without an Account
The logged-out tweet, remix, hashtag, bio and handle generators need no account. They use the guest ID, fingerprint hash and reCAPTCHA described in section 1.9. Your inputs are sent to our AI provider to produce a result and are not saved to any history on our side.
The advanced tweet search, the video downloader and the post screenshot tool also need no account. The advanced search builds an X search link in your browser and sends nothing to us. When you submit a post URL to the video downloader or screenshot tool, our server fetches that post's public content and media from X to produce the file, then returns it to you. We do not save the URL, the post or the file, beyond the access logs described in section 1.7.
4.2 Free Plan
Signing up gives you a free plan with a limited number of AI credits and access to the dashboard bio, hashtag and handle generators. Dashboard generations are saved to your history; the free bio, hashtag and handle tools are not.
4.3 Paid Plans
Professional, Agency and Elite plans unlock more AI credits, scheduling, bulk-action and screenshot features. The separate Bookmark Manager plans unlock bookmark storage, automatic sync through the X API, bookmark removal on X and export. Paying creates the Stripe records described in section 1.5. Customers who need additional data processing terms may agree them with us in writing; where they conflict with this policy, those terms prevail for that customer.
4.4 Browser Extensions
Our browser extensions run inside X in your browser. The bookmark extension reads the bookmarks page you are viewing and sends them to your TweetStorm account using your signed-in dashboard session. The AI Tweet Generator extension sends the prompts and posts you ask it to write or reply to, together with an extension API key generated in your dashboard, to our servers; these generations use your plan's credits and are saved to your history like dashboard generations. The Mass Tweet Deletions extension performs deletes, unlikes, unfollows and similar actions locally in your browser on your instruction and reports only the count of actions run, using the same API key, so we can apply your plan limits. Extensions do not collect browsing data from other websites. Each extension's store listing describes its permissions.
5. Cancelling a Subscription
You can cancel any subscription from the billing page. When you do:
- the subscription stays active until the end of the period you have already paid for, and you can resume it before then;
- after that date your account moves to the free plan; your account, generations, bookmarks and scheduled content are kept unless you delete them or your account;
- Stripe retains the transaction records it is legally required to keep; we keep receipts as described in section 8.
Refunds, if any, are handled according to the Terms of Service.
6. Who We Share Your Information With
We do not sell personal data, and we do not share it with third parties for their own marketing. We share it only with the providers below, each acting on our instructions under a data processing agreement, or where the law requires.
| Recipient | Why | What they receive |
|---|---|---|
| Microsoft Azure OpenAI Service; OpenAI (fallback) | AI text generation and voice profiles | Prompts, source text, sampled tweets, voice profile summaries |
| X Corp. (X API and public endpoints) | Connecting your account, posting, bookmark sync, removing bookmarks, fetching metrics, fetching public posts for the video downloader and screenshot tool | Your X tokens, the content you schedule, bookmark read and removal requests, post URLs you submit to the downloader and screenshot tool |
| Stripe | Payments and subscription management | Email, plan, payment details entered on Stripe pages |
| Wasabi (object storage) | Storing media you attach to scheduled posts | Uploaded images and videos, keyed by your user ID |
| Postmark | Transactional email delivery | Email address and email content |
| Our newsletter service (built on Ghost) | Holding the subscriber list for the weekly blog digest and feature announcements | Email address and the streams you are subscribed to |
| Amazon Web Services (Simple Email Service) | Sending the weekly blog digest and feature announcement emails | Email address and email content |
| MailerLite | Product news and marketing emails to account holders | Email address, added when you verify your email address |
| Google (Analytics, reCAPTCHA Enterprise, sign-in) | Usage analytics (with consent), bot protection, Google login | Analytics events, browser signals, Google account email and name at sign-in |
| Microsoft Clarity | Heatmaps and session replay (with consent) | Page interactions with sensitive fields masked |
| Tawk.to | Live chat support | IP address, browser details and page visited when the widget loads; chat messages if you use it |
| Hosting, database and Redis infrastructure providers | Running the Service | All data stored by the Service, under access controls |
We may also disclose personal data if required by law, court order or a lawful request from a public authority, to enforce our Terms, or to protect the rights, property or safety of TweetStorm, our users or others. If TweetStorm is involved in a merger, acquisition or asset sale, your data may transfer to the new owner, who must honour this policy.
7. International Transfers
Our providers, Microsoft (Azure OpenAI and Clarity), OpenAI, X, Stripe, Google, Amazon Web Services, Wasabi, Postmark, MailerLite and Tawk.to, operate globally, so your data may be processed outside your country, including in the United States. Where data leaves the EEA or the UK, transfers rely on the European Commission and UK adequacy decisions where they apply, or on Standard Contractual Clauses with additional safeguards. You can ask us for details of the mechanism used for a specific transfer.
8. How Long We Keep Your Data
| Data | Retention |
|---|---|
| Account data | While your account is active, then per section 9 |
| Generation history | Until your account is deleted |
| Saved searches, drafts, scheduled posts | Until you delete them or your account is deleted |
| Connected X tokens | Until you disconnect the account, when they are cleared immediately, or 90 days after you delete your account |
| Voice profile | Until you delete it, or 90 days after you delete your account; paused while its X account is disconnected and restored if you reconnect |
| Bookmarks, folders, tags | Until you delete them; removed immediately when you delete your account |
| Scheduled post media | While your account exists, then erased with it 90 days after deletion; files rejected by X are deleted within about a week |
| Receipts and subscription records | Up to 7 years after the transaction, to meet accounting and tax obligations |
| Verification, reset and deletion codes | Email verification links 2 hours, password reset links 1 hour, account deletion codes 24 hours; expired codes are rejected and replaced when you request a new one |
| Accounts that never verify their email address | Deleted by a nightly job, normally within 24 hours of sign-up |
| Support and contact emails | Up to 2 years after the matter is closed |
| Server access logs | Rotated on a short cycle, normally no more than 30 days |
| Guest ID, IP address and fingerprint hash (free tools) | Guest cookie 7 days; server records kept only as long as needed for abuse prevention and then deleted |
| Cookie consent record | 12 months |
| Analytics and session-replay data | Per Google and Microsoft retention settings, at most 14 months |
9. Deleting Your Account
You can delete your account from your profile page. Password accounts confirm with the password; Google and X sign-in accounts confirm with a code we email you. When you delete:
- any active subscription is cancelled and your Stripe customer record is deleted;
- bookmarks, folders, tags and smart folders are deleted immediately, and your credit balance is cleared;
- you can no longer sign in, and your extension API key stops working;
- the rest of your account data, including connected X accounts and their tokens, scheduled posts, voice profiles, media and generation history, is scheduled for permanent deletion 90 days after your request. During that window we keep it only to handle disputes, fraud and legal obligations, and to let you recover the account by contacting us if the deletion was a mistake. To cut TweetStorm's access to your X account sooner, disconnect it on your profile page before you delete, or revoke it from X's “Connected apps” settings;
- Stripe keeps transaction records it is legally required to retain, and we keep receipts as set out in section 8;
- analytics data already collected is anonymous and cannot be linked back to you, so it is not deleted.
Deleting your TweetStorm account does not delete anything on X. Posts we published on your behalf remain on X unless you remove them there.
10. Security
- All traffic to the Service is encrypted with HTTPS.
- Passwords are hashed with bcrypt and never stored in plain text.
- Session and guest cookies are httpOnly and secure, so scripts on the page cannot read them.
- Card details are handled entirely by Stripe, a PCI DSS Level 1 provider.
- Access to production systems is limited to staff who need it and protected by key-based authentication.
- Media uploads go directly from your browser to storage using short-lived signed URLs scoped to your account.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authority where the law requires, without undue delay.
11. Your Rights (GDPR and UK GDPR)
If you are in the European Economic Area, the United Kingdom or another place with similar laws, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate data. Most account data can be edited on your profile page.
- Erase your data, subject to legal exceptions (section 9).
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Port data you provided to us in a machine-readable format. Bookmark Manager plans that include export let you download your bookmarks from the bookmark manager; for anything else, or if your plan has no export, ask us and we will send you a copy.
- Withdraw consent for analytics and tracking cookies and marketing emails at any time, without affecting earlier processing.
- Complain — lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
To exercise a right, email support@tweetstorm.ai from the address on your account, or include enough detail for us to verify you. We respond within one month, extendable by two months for complex requests, and free of charge unless a request is manifestly unfounded or excessive. Authors of posts held in users' bookmarks may also contact us; we will explain what we hold and act on valid requests.
12. Your Rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to. Sections 1, 2 and 6 describe these. In the last 12 months we collected identifiers, commercial information, internet activity and user-generated content as described above.
- Delete your personal information (section 9).
- Correct inaccurate personal information.
- Opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising. Rejecting tracking cookies in the banner prevents the advertising signals described in section 3.3.
- Limit use of sensitive personal information. The only sensitive information we hold is your account login credentials, used solely to provide the Service.
- Non-discrimination for exercising any of these rights.
Submit requests to support@tweetstorm.ai. We verify requests by matching the email on your account and respond within 45 days, extendable once by a further 45 days with notice. You may use an authorised agent if they provide signed permission from you.
13. Children
The Service is not directed at children. You must be at least 13 years old to use it, or 16 where local law sets that age for consenting to online services without a parent. We do not knowingly collect personal data from children below those ages. If you believe a child has created an account, contact us and we will delete it.
14. Changes to This Policy
We may update this policy as the Service or the law changes. The date at the top shows the latest version. For material changes we will give notice in the dashboard or by email before the change takes effect. Continuing to use the Service after that date means you accept the updated policy; this does not reduce any right you have under applicable law.
15. Contact Us
Privacy questions and rights requests: support@tweetstorm.ai. Signed-in users can also use the contact form. See also our Terms of Service and pricing.