Privacy Policy
Last updated: July 11, 2026
1. Scope
This policy covers Twigest accounts, subscriptions, delivery services, and the limited public-source content processed to create monitoring digests. Twigest is independent and is not affiliated with, endorsed by, or sponsored by X Corp.
2. Subscriber Data
We process account email and name, hashed authentication credentials, tracked accounts and keywords, digest preferences, delivery settings, subscription records, IP address, browser/device information, and security logs. Paddle processes card details; Twigest does not store full payment-card numbers.
3. Public-Source Content
To provide digests, we process limited data from public posts: author handle and display name, public post text, source URL, timestamp, language, and public engagement metadata. We do not access protected/private X accounts. Public availability does not remove a person's privacy rights, so the safeguards and objection process below also apply to people who do not have a Twigest account.
4. Purposes and Legal Bases
We use data to operate accounts, collect subscriber-selected sources, create and deliver summaries, process billing, secure the Service, prevent abuse, support users, and comply with law. Depending on the activity and applicable law, our bases are performance of a contract, legal obligation, consent, and legitimate interests. Our legitimate interest in providing limited monitoring is balanced through data minimization, short retention, attribution and source links, short excerpts, access controls, and a free objection/removal mechanism.
5. Providers and International Transfers
Hetzner hosts the Service in Germany. Paddle handles billing. OpenAI receives selected public post text and handles to generate summaries. Configured email, Slack, or Telegram providers deliver digests, and operational providers may process security diagnostics. We do not intentionally include subscriber passwords, payment details, or account email in AI requests; public post text can itself contain personal data. Where required, we use applicable contractual and legal safeguards for international transfers.
6. Retention
Raw public-source posts used for digest generation are automatically deleted after 30 days. A digest may retain a short attributed summary and source link. Account data is retained while the account is active and as required for billing, security, dispute, and legal obligations. Verified suppression requests apply to active records and future collection. Previously delivered email cannot be recalled.
7. Security
We use HTTPS, hashed passwords and API keys, access controls, rate limiting, administrative audit logs, webhook authentication, and sanitization of generated HTML. No online service can guarantee absolute security.
8. Your Rights
Subject to applicable law, you may request access, correction, deletion, portability, restriction, or object to processing and complain to a competent authority. Subscribers can also delete their accounts. People mentioned in public-source content can submit a request at /privacy/third-party-rights without creating an account.
9. Public-Source Restrictions
Twigest does not use public posts to make legal, employment, credit, housing, or similarly significant decisions about their authors. We prohibit stalking, doxxing, harassment, unlawful surveillance, and sensitive-person profiling. Verified account-level opt-outs are checked before storage, AI processing, and future digest delivery.
10. Children
The Service is intended for adults. If we learn that we have knowingly processed a child's data in a manner requiring removal, we will act promptly.
11. Changes and Contact
Material changes will be posted with a revised date. Contact hello@twigest.com for privacy matters and general support.