Privacy Policy
Last updated: August 19, 2026
- We collect: your name, email, and API usage stats, that’s basically it
- We NEVER sell your data to anyone: no advertisers, no data brokers, no exceptions
- We NEVER use your data to train AI models
- Connected X account credentials are encrypted with AES-256-GCM and you can delete them anytime
- We only process PUBLIC Twitter/X data, no DMs, no private accounts
- API logs are kept for 90 days for debugging, then anonymized
- You can export or delete all your data anytime from your dashboard
- We use only essential cookies: no tracking, no ads, no fingerprinting
- EU/GDPR and California/CCPA rights fully supported
1. Introduction
This Privacy Policy explains how XCROP ("XCROP", "we", "us", or "our") collects, uses, stores, and protects your personal information when you use our website, API, dashboard, and related services (collectively, the "Services").
By using the Services, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Services.
2. Information We Collect
We collect information in the following categories:
Account Information: Full name, email address, and optional company name provided during registration.
Usage Data: API call logs, endpoints accessed, request/response timestamps, credit consumption, IP addresses, and error rates.
Device & Browser Data: Browser type and version, operating system, device identifiers, screen resolution, and referring URLs, collected automatically via standard web technologies.
Payment Information: Billing address and payment method details. Cryptocurrency payment records (wallet addresses, transaction hashes) are stored for verification purposes.
Connected Account Data: If you use the Write API, your X/Twitter account credentials are encrypted with AES-256-GCM and stored securely. Session tokens are refreshed periodically and can be revoked at any time via your dashboard.
3. How We Use Your Information
We use collected information to:
- •Provide, operate, maintain, and improve the Services
- •Process payments, manage subscriptions, and send invoices
- •Monitor API usage, enforce rate limits, and prevent abuse
- •Send transactional communications (billing confirmations, security alerts, service updates)
- •Detect, investigate, and prevent fraud, abuse, and security threats
- •Generate anonymized and aggregated analytics to improve service quality
- •Respond to support requests and provide customer assistance
We do NOT use your data to:
- •Sell or rent personal information to third parties
- •Build advertising or marketing profiles
- •Train AI or machine learning models on individual user data
- •Make automated decisions that produce legal effects concerning you
4. Data We Process from Twitter/X
XCROP processes publicly available data from the Twitter/X platform, including:
- •Public tweets, retweets, quote tweets, and replies
- •Public user profiles, display names, bios, and follower/following counts
- •Engagement metrics (likes, replies, retweets, views)
- •Trending topics, hashtags, and community content
- •List memberships and community details
We do NOT access or process:
- •Private or direct messages (DMs)
- •Content from protected or private accounts
- •Data from suspended or deactivated accounts
- •Content that has been deleted (purged from our systems within 24 hours of detection)
5. Data Sharing & Third Parties
We share personal data only in these limited circumstances:
- •Service Providers: Resend (transactional email), Vercel (hosting), and PostgreSQL database providers, all bound by data processing agreements
- •Legal Obligations: When required by applicable law, valid subpoena, court order, or government request
- •Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, with prior notice to affected users
- •With Your Consent: When you explicitly and affirmatively authorize sharing
We do NOT sell, trade, or otherwise transfer your personal information to advertisers, data brokers, or any unaffiliated third parties for their marketing purposes.
6. Data Security
We implement technical and organizational measures to protect your data:
- •TLS 1.3 encryption for all data in transit
- •AES-256-GCM encryption for sensitive data at rest (credentials, tokens)
- •API keys stored as salted bcrypt hashes
- •Database access restricted by role-based permissions and network firewalls
- •Regular security audits, dependency scanning, and vulnerability assessments
- •Automated monitoring, alerting, and incident response procedures
No system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. If you discover a vulnerability, please report it responsibly to [email protected].
7. Data Retention
We retain your data according to the following schedule:
- •Account data: Retained while your account is active, plus 30 days after deletion request to allow for recovery
- •API usage logs: Retained for 90 days for debugging and analytics, then anonymized
- •Billing and transaction records: Retained for 7 years as required by tax and financial regulations
- •Connected X account credentials: Deleted immediately upon disconnection via dashboard
- •Aggregated and anonymized data: May be retained indefinitely as it cannot identify individuals
You may request deletion of your personal data at any time via your dashboard settings or by emailing [email protected].
8. Your Privacy Rights
Depending on your location, you may have the following rights under applicable law (including GDPR, CCPA/CPRA, and similar regulations):
- •Access: Request a copy of the personal data we hold about you
- •Rectification: Request correction of inaccurate or incomplete data
- •Deletion: Request erasure of your personal data ("right to be forgotten")
- •Portability: Receive your data in a structured, machine-readable format
- •Restriction: Request that we limit processing of your data
- •Objection: Object to processing based on legitimate interests
- •Opt-out of Sale: California residents may opt out of any "sale" of personal information (note: we do not sell your data)
- •Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise any of these rights, email [email protected] with your request. We will verify your identity and respond within 30 days (or as required by applicable law). You may also designate an authorized agent to submit requests on your behalf.
9. Cookies & Tracking Technologies
We use minimal cookies and similar technologies:
- •Essential cookies: Required for authentication, session management, and security (cannot be disabled)
- •Functional cookies: Remember your preferences such as theme and language settings
We do NOT use:
- •Third-party advertising or remarketing cookies
- •Cross-site tracking pixels or beacons
- •Browser fingerprinting techniques
- •Social media tracking widgets
You can manage cookie preferences through your browser settings. Disabling essential cookies may impair functionality.
10. International Data Transfers
XCROP is operated from Vietnam. If you access our Services from elsewhere, your data is transferred to and processed in Vietnam, which is not covered by an EU adequacy decision.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914) as the legal mechanism for cross-border data transfers.
We ensure that all data transfers comply with applicable data protection laws and that adequate safeguards are in place.
11. Children's Privacy
The Services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children.
If we become aware that we have collected data from a child without verified parental consent, we will delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via:
- •Email notification to all registered users
- •Prominent notice on our dashboard
- •Updated "Last updated" date at the top of this policy
We encourage you to review this policy periodically. Continued use of the Services after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
For privacy-related questions, concerns, or data subject requests:
- •Privacy inquiries: [email protected]
- •Data Protection Officer: [email protected]
- •Security reports: [email protected]
- •General support: [email protected]
XCROP is operated by Pham Minh Duc, an independent developer based in Vietnam, who is the data controller for the purposes of GDPR and equivalent laws. We answer email, usually within one business day.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.