xxxx.fish · Policy
Privacy Policy
How xxxx.fish handles connected X accounts, cached posts, AI processing, and payments.
- Effective
- Last updated
Summary
- xxxx.fish is a U.S.-based service that helps you review and delete posts from your own connected X account.
- We store the account credentials, cached posts, analysis results, conversations, job records, and billing information needed to provide the service.
- Stripe handles card details. AI providers process content only when needed for the features you use.
Who we are
xxxx.fish is a U.S.-based service operated under the xxxx.fish name.
General contact: support@xxxx.fish.
Privacy requests: privacy@xxxx.fish.
Who and what this policy covers
This policy covers the xxxx.fish website and signed-in features, including X sign-in, timeline scanning, semantic search, Deep Context, explanation drafts, conversations, deletion jobs, credits, and billing.
The service is currently offered to United States residents. X, Stripe, Vercel, and AI providers also apply their own privacy terms to their services.
Data we collect and generate
X account data: your X user ID, handle, display name, profile image URL, and the OAuth credentials needed to keep the connection working.
OAuth scopes requested: tweet.read, users.read, tweet.write, offline.access. These allow reading your posts and profile, deleting or un-retweeting your own content with your confirmation, and refreshing tokens while offline jobs run.
Cached X content: post text, timestamps, engagement counts, reply and repost relationships, language, media links, and deletion status. We cache this information so you can review it without repeatedly fetching the same history from X.
AI outputs we generate: heat scores, categories, rationales, embeddings, Deep Context live-fact artifacts and citations, contextual second judgements, explanation drafts, corpus-report style outputs when you run them, and conversation/event history for the assistant.
Service records: scans, saved searches, model preferences, deletion jobs, credit grants and spending, feature suggestions, and operational records used to prevent abuse and control costs.
Billing data: Stripe customer, checkout, invoice, and subscription identifiers; the receipt email entered at Checkout; and records of credits granted after payment. Stripe, not xxxx.fish, collects and stores your full card details.
Session metadata: session token, expiry, and optionally IP address and user agent on the server session record.
Website analytics: Vercel Web Analytics provides aggregate traffic information without advertising cookies. See the Cookie Notice for details.
We do not access your X direct messages through the scopes above.
How we use data
We use your data to authenticate you, keep your X connection working, fetch and cache your timeline, score and search posts, run features you start, execute deletion jobs you confirm, meter credits, and provide billing support.
To show progress, backups, receipts, and job history in the product UI.
To operate and protect the service (rate limits, revoked-token handling, abuse prevention, and a global daily spend guard).
We do not use your posts to train or fine-tune foundation models. X content is sent for inference only when a feature requires it.
AI providers and Deep Context
You choose an analysis provider for judgement: Claude, Gemini, ChatGPT, Grok. Requests are routed through Vercel AI Gateway.
Semantic-search embeddings use cohere/embed-v4.0. Deep Context retrieves live X evidence with xai/grok-4.5; your selected analysis model produces the contextual risk judgement when that second step runs.
Prompts may include post text, engagement metadata, media URLs for vision-capable models, live facts, and your chat messages. Providers process that content to return results. We do not claim that providers never log technical data on their side — see each provider’s terms.
Model output can be wrong in both directions. Flags are suggestions; deletions require your confirmation.
Where processing happens
xxxx.fish is a U.S.-based service. Our hosting, database, payment, analytics, and AI providers may process information in the United States and other locations where they operate.
Retention, disconnect, and deletion
We keep account, cached-post, analysis, conversation, job, preference, and credit records while your account is active so the service remains durable across sessions.
Cached copies may not immediately reflect a post changed or deleted directly on X. Posts successfully removed through xxxx.fish are automatically purged from our cache after a 24-hour job-settlement period. That purge also removes their scores, embeddings, Deep Context, explanation drafts, saved-result references, and any Timeline Report or assistant conversation that retained the post as evidence. Aggregate deletion counts and credit records may remain without the cached post text. You can request earlier removal by deleting your xxxx.fish account or contacting the privacy address below. We process applicable removal requests from X or the account owner as soon as reasonably possible and within 24 hours, unless law requires preservation.
Disconnecting your X account marks local tokens revoked and cancels stoppable deletion jobs so further X API calls should stop. Disconnect is reversible and does not erase historical product data.
Signed-in users can permanently delete their xxxx.fish account from the account menu. That flow blocks new metered work, cancels any stored Watchdog subscription, removes authentication and stored X credentials, and erases cached posts, analyses, searches, conversations, job history, preferences, feature suggestions, and the operational credit ledger. It does not delete posts on X.
After account deletion, we retain a one-way pseudonymous erasure receipt for as long as needed to prevent delayed payment events from recreating the account. Stripe and other providers may retain transaction, security, or backup records under their own retention schedules or where required for tax, fraud prevention, refunds, or legal claims.
Pre-deletion backups are generated on demand from the database and streamed to you; they are not written to a separate object-storage archive by the app. Backups include post text and metadata and media URLs, not media bytes.
To request access, correction, a portable copy, or deletion of personal data we control, contact privacy@xxxx.fish. We will verify the request and respond within the time required by applicable U.S. law.
Your privacy choices
You can disconnect X without deleting your xxxx.fish history, or permanently delete your xxxx.fish account and remaining credits from the account menu.
Depending on where you live and which laws apply, you may have rights to know, access, correct, delete, or obtain a copy of personal information, and to appeal a denied request. We do not sell personal information or use it for cross-context behavioral advertising.
Send privacy requests or appeals to privacy@xxxx.fish. You may make a request even if you cannot sign in, but we will need enough information to verify your identity and protect the account.
Security
Access tokens and refresh tokens are server-side only and are not intended to be sent to the browser.
Sessions are cookie-based; protected app routes require a session cookie.
We use access controls and the safeguards supplied by our hosting and database providers. No security system is perfect, and we do not claim a certification we have not earned.
You should disconnect xxxx.fish in the product and revoke the app in X’s connected-apps settings if you believe credentials were compromised.
Children
xxxx.fish is for adults and is not directed to children under 18. If you believe a child provided information to the service, contact the privacy address listed on this page.
Changes
We may update this policy as the product changes. The effective and last-updated dates appear at the top of the page (currently effective 2026-08-04, last updated 2026-08-05).
Contact
xxxx.fish is a U.S.-based service operated under the xxxx.fish name.
General contact: support@xxxx.fish.
Privacy requests: privacy@xxxx.fish.