1. Who controls your data
Oskar Freye, operating xmaxx.me under the name xmaxx, is responsible for the personal data described in this policy. Privacy questions and requests can be sent to oskar@freye.tech.
2. Data we collect
Account and identity data
Clerk provides authentication for xmaxx. We receive identifiers needed to recognize your account, such as your Clerk user ID, email address, and session status. Clerk may also process profile details and login-provider information according to its own privacy policy.
Connected X account data
When you connect X, we may receive your X user ID, handle, display name, avatar, account status, posts, public metrics, mentions, and the scopes you approved. We store OAuth tokens so the Service can perform the actions you request. Tokens are encrypted before storage.
Content and settings
We process drafts, threads, notes, uploaded media files, schedules, automation settings, replies, saved items, and other content you submit. Uploaded media is stored in private cloud object storage. We also store plan limits, feature preferences, and records needed to run scheduled or automated actions safely.
The canvas stores panel positions and user-created artifacts in your browser's local storage. Artifacts can include copied post or note text and metrics. This browser-local data stays on the device until you clear site data or remove it through the available canvas controls. Server-side account deletion does not clear data already held by your browser.
Usage, billing, and technical data
We process feature usage, account limits, request logs, error records, timestamps, and basic device or network data needed for security and reliability. If you use a paid plan, we receive plan, subscription, and payment-status events from Clerk or its payment partners. xmaxx does not store complete payment-card details.
3. Why we use data
We use personal data to:
- create and secure your account;
- connect the X accounts you authorize;
- draft, schedule, publish, measure, and manage content at your request;
- run the automations and account preferences you enable;
- apply plan limits, process subscriptions, and prevent abuse;
- diagnose failures, protect the Service, and meet legal obligations;
- respond to support, privacy, and account-deletion requests.
Where European data-protection law applies, these activities rely on performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal duties, or consent where the law requires it. You can withdraw consent without affecting earlier processing.
4. How we handle X data
xmaxx uses X data only to provide features you request and to maintain the connected account. We do not sell X data. We do not use your X OAuth tokens for advertising or to operate accounts you have not connected.
Actions such as publishing, deleting, or reading account information depend on the scopes shown by X during authorization. You can review and revoke the connection in xmaxx or in X's connected apps settings.
Disconnecting an X account stops new API access and removes the active OAuth credentials from normal use. It does not automatically delete drafts, analytics, uploaded media, or browser-local canvas artifacts. Contact us if you want server-side account data erased; clear xmaxx site data in your browser to remove browser-local artifacts.
6. Retention and deletion
We keep account data while your xmaxx account is active. Connected-account credentials remain available while needed to maintain the connection. Some product records use soft deletion, and uploaded media does not currently have a self-service deletion control. Contact oskar@freye.tech to request erasure of server-side account data. Requests are handled manually and may require identity verification.
Security logs, billing records, backups, dispute records, and information required by law may remain after an erasure request. We retain those records only for the relevant security, accounting, dispute, backup, or legal purpose. Browser-local canvas artifacts are controlled by your browser and must be cleared on the device separately.
7. Security
xmaxx uses access controls, encrypted transport, restricted cloud permissions, and encryption for stored X OAuth tokens. No online service can guarantee absolute security. Contact us promptly if you believe your account or connected X account has been compromised.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data; receive a portable copy; withdraw consent; and complain to a data-protection authority.
Send a request from the email attached to your xmaxx account to oskar@freye.tech. We may need to verify your identity before acting on the request. You can also revoke X access directly through X at any time.
10. Children, changes, and contact
The Service is not directed to children under 18. We do not knowingly collect their personal data.
This policy may change as the Service, providers, or legal requirements change. The effective date above identifies the current version. Material changes will be communicated through the Service or by email where appropriate.
Contact Oskar Freye at oskar@freye.tech for privacy questions or requests.