ExTweetsAgentic Twitter Tools
DOC // Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how ExTweets collects, uses, and protects information when you use the service to connect X/Twitter accounts, authorize MCP clients, and use Grok or other provider-backed tools.

Information we collect

We collect account information needed to operate the service, such as your ExTweets user identifier, sign-in provider identifiers, email address if provided by your sign-in provider, connected X/Twitter account IDs, usernames, display names, granted scopes, session records, billing records, usage records, and MCP client authorization records.

When you connect X/Twitter, we receive OAuth tokens from X/Twitter. These tokens let ExTweets perform the actions you approved, such as reading posts, posting, uploading media, managing follows, managing bookmarks, and sending direct messages where those permissions are granted.

When you use tools, we may process tool inputs and outputs, selected account identifiers, target post or user IDs, timestamps, provider response status, provider request IDs where available, usage amounts, and cost or billing metadata. We avoid storing raw OAuth tokens in logs.

How we use information

We use information to authenticate you, maintain sessions, connect X/Twitter accounts, issue and manage MCP client access, execute tool calls requested by authorized clients, refresh OAuth tokens, show dashboard activity, enforce limits, calculate usage and billing, prevent abuse, troubleshoot issues, and improve reliability.

If Grok or xAI-backed tools are used, prompts and related tool parameters are sent to xAI for processing. If X/Twitter tools are used, relevant requests are sent to X/Twitter APIs. If Google sign-in is used, authentication information is processed through Google. If billing is enabled, payment information is processed by Stripe.

Direct messages

If you grant direct message permissions, ExTweets may send direct message requests to X/Twitter when an authorized MCP client requests that action. Direct message tool calls may include recipient identifiers and message text required to complete the request. ExTweets should not be used to send unlawful, unsolicited, abusive, or deceptive messages.

Token storage and security

Long-lived X/Twitter OAuth token payloads are stored encrypted in Cloudflare D1 using a Worker secret. OAuth state used during sign-in or authorization is short-lived. Raw OAuth tokens are not returned to MCP clients, dashboard pages, or normal tool responses.

No system can be guaranteed perfectly secure. We use reasonable technical and organizational measures to protect connected-account credentials, including encrypted token storage, scoped OAuth permissions, short-lived authorization state, and revocation paths.

Sharing

We do not sell connected-account data. We share information with service providers only as needed to operate ExTweets, including Cloudflare for hosting and storage, X/Twitter for connected account API actions, xAI for Grok-backed research, Google for Google sign-in, and Stripe for payments if billing is enabled.

We may disclose information if required by law, to protect the service or users, to investigate abuse or security incidents, or as part of a business transfer such as a merger, acquisition, or asset sale.

Retention

We keep account, connection, billing, and usage records for as long as needed to operate the service, provide auditability, resolve disputes, comply with legal obligations, and prevent abuse. If you disconnect an X/Twitter account, we stop using the stored tokens for that account and may delete or invalidate token records according to the service's retention practices.

Your choices

You can revoke X/Twitter access from your X/Twitter account settings. From the ExTweets dashboard you can disconnect individual accounts, revoke individual MCP clients, change each account's permission tiers, or delete your entire ExTweets account in one action. Account deletion removes your profile and sign-in identities, sessions, connected-account tokens (which are also revoked on X/Twitter's side where possible), MCP client authorizations, usage history, and billing profile, and forfeits any remaining credit balance. We retain payment and transaction records held with Stripe for accounting, tax, and legal purposes, and we retain a minimal record that a given X/Twitter account has already claimed its one-time welcome credit, to prevent repeated claims. The Stripe customer record is retained as part of our financial records.

Audit records for tool calls may include target identifiers, such as the ID of a post that was read, liked, or deleted, or the username a direct message was sent to. Audit records do not store post text or message bodies.

Children

ExTweets is not intended for children under 13, and we do not knowingly collect personal information from children under 13.

Changes

We may update this Privacy Policy as the service changes. The updated version will be posted on this page with the updated date.

Contact

For privacy or security questions, contact the operator of this service through the contact channel published on extweets.com.