Privacy Policy — Rispost
Effective date: Aug 28, 2026 Contact: mateovogt@proton.me
This policy describes what data Rispost (“the App,” “we,” “us”) collects when you connect your X (Twitter) account, and how we use it.
What we collect
- OAuth access token — When you authorize Rispost via X’s OAuth 2.0 flow, we receive and store an access token tied to your X account. This token lets us act on your behalf for the features you’ve enabled (see below). We do not collect your email address, password, or X login credentials.
- Post impression statistics — We read impression and engagement metrics for your posts via the X API.
- List subscriptions (optional) — If you choose to use this feature, we use your granted write permission to subscribe your account to specific X Lists on your behalf. This only happens when you explicitly trigger it — we never post, message, or modify your account without your action.
What we don’t collect
- We do not request or store your email address.
- We do not store the raw content of your posts. We compute derived statistics from impression data; we do not retain the underlying raw metrics beyond what’s needed to produce those calculations.
How we use your data
- Impression statistics are processed to generate the analytics/scoring features of the App.
- Some derived (calculated, non-raw) statistics may be sent to third-party AI providers — currently OpenAI and xAI — to power reply-worthiness scoring. These are numeric values only; we do not send your handle, post content, or any other identifying information alongside them.
- Per OpenAI’s API terms, data submitted via their API is not used to train their models by default, and is retained for up to 30 days for abuse-monitoring purposes.
- xAI does not train on API customer data by default. Official docs state: “xAI never trains on your API inputs or outputs without your explicit permission.”
Data retention
- We retain your OAuth token for as long as your account is connected to the App. You can revoke access at any time via X’s Connected Apps settings, which immediately invalidates our stored token.
- Derived statistics are retained indefinitely.
Data sharing
We do not sell your data. We share derived, non-identifying statistics with OpenAI and xAI solely to power App features, as described above. We do not share data with any other third party.
Your rights
You may revoke Rispost’s access to your X account at any time via X’s settings. You may request deletion of any data we hold about you by contacting mateovogt@proton.me. If you are located in the EU/EEA, you have rights under GDPR including access, correction, and erasure of your personal data.
Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected here with an updated effective date.