Privacy Policy
Last updated: August 30, 2026
This policy explains what data TweetWhale collects, why, and how we protect it. We collect the minimum needed to operate an outreach platform and do not sell personal data.
1. Data we collect
- Account data: your email address, authentication identifiers from our login provider (ZITADEL), plan, and preferences.
- Connected X account data: session cookies/tokens (e.g., auth_token, ct0), optional login credentials and 2FA secrets you choose to store, profile name/handle/avatar, assigned proxy, and account health state. This data is required for the Service to send messages on your behalf and is stored encrypted where applicable (XChat PINs are stored encrypted at rest).
- Proxy configurations: IP/host, port, and credentials for proxies you register.
- Lead lists and campaigns: scraped or imported prospect handles/profiles, message templates, campaign settings, delivery statistics.
- Conversations: messages sent/received through connected accounts so your unified inbox can display them.
- Operational logs: job runs, error records, and administrative audit events.
2. How we use it
- Authenticating sessions and enforcing plan limits.
- Performing logins, sending messages, syncing inboxes, and running campaigns you configure.
- Detecting failures (expired sessions, broken proxies) and keeping accounts healthy.
- Providing support, preventing abuse, and meeting legal obligations.
We do not use your lead lists or conversations to train models or for any other product's benefit.
3. Sharing
- Infrastructure providers that host the application and database.
- Authentication provider (self-hosted ZITADEL) for sign-in.
- Payment processors, once billing is enabled — they receive only what is needed to process payment.
- We may disclose data if required by law or to protect rights, safety, and security.
4. Security
Access to the Service requires authentication; sensitive credentials are stored with encryption and access controls, and all API traffic runs over TLS. No system is perfectly secure — please use unique, strong passwords and restrict who on your team can access the dashboard.
5. Retention and deletion
We keep data while your account is active. Deleting a connected X account removes its stored tokens and credentials. You can request full account deletion at [email protected]; we will remove your personal data within 30 days except where retention is legally required. Operational logs may be retained in aggregate form.
6. Your rights
Depending on your jurisdiction (e.g., EU/UK GDPR, California CPRA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us to exercise these rights.
7. Changes and contact
We'll announce material changes in-app before they take effect. Questions: [email protected].
