Privacy Policy

Last updated: September 27, 2026

1. Overview

Xpost (xpostapi.com) is an automated index of publicly posted content on X (formerly Twitter). This policy explains what the Service stores, what little information we keep about visitors and account holders, and the choices you have.

By using the Service you agree to this policy. We may update it from time to time; the version on this page is the version in effect.

2. What we index (data about posts, not people)

The Service collects publicly available posts from X on a schedule, using free public sources. For each post we store the post identifier and link, author handle and display name, post text, engagement counts (likes, reposts, replies), posting date, and links to publicly attached photos and videos.

We only index content that was already public on X. We do not access private accounts, direct messages, or deleted posts. We do not profile, track, or attempt to identify the individuals behind indexed accounts beyond the public handle and name that X itself displays.

If you are an indexed author and want your content removed from the index, see our Terms of Service for the takedown process, or contact us with the post URL(s).

3. Information we keep about you

Browsing: the public search pages and API require no account and set no tracking cookies. We do not build advertising profiles.

Accounts: if you create an account, we store your email address and authentication identifiers solely to operate the sign-in and admin features. We do not sell, rent, or share this information with advertisers or data brokers.

Operational logs: we keep minimal operational logs (such as collection run results and aggregate search query text) to keep the Service working and to decide which keywords and accounts to track. Query text is stored in aggregate for index improvement, is not linked to your identity for anonymous use, and is never sold.

4. How we use information

We use indexed data to operate the search Service and API; account data to authenticate you and administer the Service; and operational logs to maintain reliability, detect abuse, and tune collection. That is the entirety of our use. We do not use your data for advertising, and we do not sell personal information.

5. Sharing and processors

We run the Service on managed infrastructure and authentication providers (our hosting and database platform). These providers process data strictly on our instructions to deliver the Service. We may disclose information if required by law or valid legal process, or to protect the rights, property, or safety of the Service, its users, or the public.

Indexed media links may point to servers operated by X or third-party media hosts; when you open a post or media link you leave Xpost and are subject to that platform's own policies.

6. Data retention

Indexed posts remain in the index until they age out, are removed by takedown, or we decide to prune them. Account records are kept while your account is active and deleted within a reasonable period after account deletion. Operational logs are kept for a limited maintenance window.

7. Your rights

Depending on where you live, you may have rights to access, correct, or delete the personal data we hold about you, and to object to certain processing. Since the only personal data we typically hold about you is your account email, these requests are simple: contact us and we will respond within a reasonable period. Indexed content is governed by the takedown process in our Terms of Service rather than this policy.

8. Security

We use industry-standard measures — encrypted transport, access controls, and row-level database permissions — to protect the data we hold. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

9. Contact

Privacy questions or requests: use the contact details published on xpostapi.com.

See also our Terms of Service.