Privacy policy
Last updated 2026-09-18. The controller is the company named on your invoice; contact hello@xdataapi.io.
What we store about you
| Data | Why | Kept |
|---|---|---|
| Email address | Sign-in codes, invoices, notices about the service | While the account exists |
| API keys (hashed) and their names | Authentication | Until revoked, then the hash 30 days |
| Usage events: endpoint, status, item count, credits, cache state, timing, request id | Billing, rate limits, abuse detection, the dashboard | 13 months |
| Ledger: grants, charges, expiries | Your balance and its history | Accounting retention, at least 7 years for paid packs |
| Payment records: Stripe session id, pack, amount, status | Proof of purchase, refunds | Accounting retention |
| Server logs with IP address and user agent | Security and debugging | 30 days |
We do not store the query strings or the X data returned to you beyond a short response cache (minutes) shared by all customers. We do not sell data and we do not use your usage for advertising.
Who processes it for us
- Hetzner (Germany): API servers.
- Supabase (EU, Frankfurt): database and sign-in.
- Vercel: this website and the dashboard.
- Stripe: payments. Your card details go to Stripe only; we never see them.
- Resend (EU): transactional email such as sign-in codes.
- Umami (EU): page analytics without cookies. It records the page, referrer, country, browser and screen size, not your IP address or identity.
Legal basis
Contract, for everything needed to run your account and bill you. Legitimate interest, for security logs and abuse detection. Legal obligation, for accounting records. We do not use consent-based tracking; this site sets only the cookies needed to keep you signed in.
Your rights
You can see your keys, usage and ledger in the dashboard at any time. Write to hello@xdataapi.io to export or delete your account. Deletion removes the email and keys at once and keeps only what accounting law requires. If you are in the EU/EEA or UK you can also complain to your data protection authority.
About the X data itself
The API returns public content that X users published. We act as a processor of that content on your instruction: we fetch it, cache it for minutes, and return it. What you do with it afterwards is under your responsibility as described in the terms. A person who wants their public content not to be returned by this API can write to hello@xdataapi.io.
Changes
The date at the top changes with every edit. Customers with credits get an email for material changes.