Privacy Policy

Last updated: August 10, 2026

1. Overview

X68 Hub ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and what rights you have regarding your data.

By using X68 Hub (the "Service"), you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you register, we collect:

  • Your name and email address
  • A hashed password (we never store your password in plain text)
  • Your subscription plan and its expiry date

2.2 X (Twitter) Account Data

When you add an X account to monitor, we collect and store:

  • The X username (handle) and numeric user ID
  • When you connect official X OAuth: encrypted authorization tokens and granted scopes
  • Follower count and follower ID lists (snapshots taken periodically)
  • Public profile information of followers: display name, username, avatar URL, follower/following counts, bio, and verification status
  • Unfollow and new-follow events with timestamps and detected reason (unfollow, suspended, deleted, blocked)

X account data is retrieved via TwitterAPI.io, a third-party X/Twitter data provider. If you choose the post-management feature, we separately use the official X API with OAuth 2.0 User Context to list and delete posts that you explicitly select. We do not use browser cookies or scraping, and we do not store X access tokens in the browser. We request only the permissions needed for listing and deleting posts; we cannot post, like, or follow on your behalf. The post-management feature stores OAuth tokens encrypted on the server, uses them only for the requested X API operations, and deletes them when you disconnect the connection.

2.3 Usage Data

We automatically collect certain technical information, including:

  • IP address and browser/device type
  • Pages visited and features used within the Service
  • API usage counts (for rate-limit enforcement and abuse prevention)
  • Error logs for debugging purposes

2.4 Telegram Integration (Optional)

Telegram notifications use the Telegram chat ID you provide. If you enable the personal-account link scheduler, we also store an encrypted Telegram login session, a masked phone number, the group names and IDs you choose, and the links, captions, schedules, and delivery results you create. Login codes and two-step verification passwords are not retained. We read your Telegram dialog list to identify groups; we do not store conversation content or contacts. Messages are sent from your Telegram account only to groups you enable and select.

2.5 Payment and Billing Information

Subscriptions are purchased via manual bank transfer. When you initiate an upgrade, we collect and store:

  • The plan and billing period you selected
  • A payment order record with status (pending / confirmed / rejected)
  • Any transfer reference note you provide

We do not collect, store, or process credit card numbers, bank account credentials, or any raw payment credentials. Bank transfers are made directly by you through your own banking app; we only receive confirmation of the transfer on our end.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service
  • Detect and notify you of follower changes on your monitored X accounts
  • Send you alerts and notifications via web dashboard and Telegram as you configure
  • Confirm payment orders and activate your subscription plan
  • Prevent abuse, fraud, and unauthorized use of the Service
  • Respond to support requests and communicate with you about the Service
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

4. Third-Party Services

We use the following third-party services to operate the Service:

TwitterAPI.io

A third-party data provider used to retrieve public X/Twitter follower lists and profile data. Your monitored X username is sent to this service to fetch follower information. Subject to TwitterAPI.io's terms.

Neon (PostgreSQL hosting)

Our database is hosted on Neon, a serverless PostgreSQL provider. Your data is stored in their infrastructure and subject to Neon's Privacy Policy.

Telegram Bot API

Used to deliver optional alert notifications. Only your Telegram chat ID is transmitted to send messages you explicitly opted into.

Telegram MTProto API (Optional)

Used only when you connect a personal Telegram account for scheduled link delivery. Telegram receives your login requests and the messages you schedule for the groups you select.

OpenAI-compatible API (Optional)

If you use the AI Writer feature, your style preferences and optional trend context are sent to an AI API provider. No personally identifiable information is included in these requests.

5. Data Retention

We retain your data as follows:

  • Account data: Retained for the duration of your account. To request deletion, contact us at the email below.
  • Follower snapshots and events: Retained to provide historical tracking. You may request deletion by contacting us.
  • Payment order records: Retained as long as necessary for billing dispute resolution and applicable financial record-keeping requirements.
  • Usage logs: Retained for up to 90 days for debugging and abuse prevention.
  • X OAuth connection: Encrypted tokens are retained until you disconnect X or delete your account. Post deletion audit records retain filters and counts, not full post text or tokens.

6. Your Rights

Depending on your location, you may have certain rights regarding your personal data, including under the GDPR (European Economic Area) and CCPA (California).

Your rights include:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and associated personal data. Contact us at the email below and we will process your request within 30 days.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to certain types of processing.
  • Opt-out of sale: We do not sell personal data. No opt-out is needed.

To exercise any of these rights, email us at support@top1.us. We will respond within 30 days.

7. Data Security

We implement industry-standard security measures including encrypted database connections (TLS/SSL) and hashed passwords (bcrypt). However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. For material changes, we may also send you an email notification.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

support@top1.us