ChatCoat App Icon
ChatCoat Application

Official Legal & Compliance

Privacy Policy>X (formerly Twitter)

X (Twitter) Developer API Privacy Policy

Effective Date: September 5, 2026 • Application: ChatCoat

1. X Developer Platform & Policy Compliance

ChatCoat integrates with the X API v2 (operated by X Corp., formerly Twitter) to provide social media publishing, scheduling, automated comment replies, media attachments, direct messaging, and post lifecycle management for connected organizations.

By connecting your X account to ChatCoat, you acknowledge and agree that our processing of your X data strictly adheres to:

  • X Developer Agreement: Compliant with the X Developer Agreement.
  • X Developer Policy: Compliant with all requirements of the X Developer Policy, including data protection, privacy by design, and strict limitations on data redistribution.
  • X Automation Rules: Compliant with X Automation Rules, ensuring no spamming, aggressive auto-tweeting, or unsolicited bulk direct messaging.
  • X Privacy Policy: Operating in full harmony with the X Privacy Policy.

2. Information We Collect via X API v2

ChatCoat collects and processes only the minimal data strictly required to deliver automated publishing, mention polling, and conversational assistance:

Account & Profile Data

  • X User ID (unique numerical platform identifier)
  • Account username (handle, e.g., @username)
  • Public display name and profile image URL
  • AES-256 encrypted OAuth 2.0 access and refresh tokens
  • Granted OAuth permission scope list

Content & Interaction Data

  • Tweet text, links, hashtags, and scheduling timestamps
  • Media files (images, GIFs, videos) uploaded to X endpoints
  • Published Tweet IDs and permalinks (https://x.com/user/status/id)
  • Public mentions and in-thread replies to your posts
  • Direct message (DM) conversation IDs and message texts

3. Purpose of Processing X Data

All X data handled by ChatCoat is processed solely for authorized business operations configured by the account owner:

  • Post Publishing & Scheduling: Composing, scheduling, and automatically posting tweets and multi-media attachments to your X profile at user-specified times.
  • Post Lifecycle & Auto-Deletion: Automatically deleting scheduled campaign tweets via the X API v2 DELETE endpoint once a user-configured lifetime (hours) expires.
  • Mention & Comment Monitoring: Polling public mentions and replies to your posts to detect pre-configured keywords (e.g., price, info, link, help).
  • Automated Public Thread Replies: Publishing contextual, non-repetitive public replies to users who inquire about your campaign on X.
  • Direct Message (DM) Customer Care: Delivering 1-on-1 private direct messages containing requested information or customer support links when triggered by customer engagement.

4. Security, Token Encryption & PKCE Standards

We implement comprehensive security controls to safeguard your X account access:

  • OAuth 2.0 with PKCE: We use the OAuth 2.0 Authorization Code Flow with Proof Key for Code Exchange (PKCE S256). High-entropy code verifiers and state tokens are HMAC-signed to eliminate authorization code interception attacks.
  • Authenticated Encryption at Rest: All X access tokens and refresh tokens are encrypted using AES-256 / Fernet before storage in our database. Plaintext tokens are never written to disk or recorded in operational application logs.
  • Automatic Token Refresh: Expired or near-expiry access tokens are automatically refreshed in the background using the offline.access refresh token grant.
  • Multi-Tenant Isolation: All connections, campaigns, and tokens are strictly segregated by organization ID to guarantee zero unauthorized cross-account visibility.
  • Transport Layer Security (TLS 1.3): All requests between client browsers, ChatCoat servers, and X API endpoints occur strictly over TLS 1.3 encrypted HTTPS channels.

5. No Sale of X Data & Strict Use Restrictions

In strict accordance with the X Developer Policy:

  • ChatCoat never sells, rents, leases, trades, or syndicates X user data, tweets, follower lists, or metadata to third parties, data brokers, or advertising networks.
  • ChatCoat does not use X Content to train proprietary foundation or generative artificial intelligence models without your explicit prior authorization.
  • ChatCoat does not conduct mass surveillance, profiling, or unauthorized bulk harvesting of X users or public timelines.

6. Requested X OAuth 2.0 Scopes Explained

ChatCoat requests only the granular scopes needed to execute user-directed publishing and automation:

tweet.read

Allows ChatCoat to read your tweets, mentions, and reply threads to monitor keyword triggers and display campaign metrics.

tweet.write

Allows ChatCoat to publish scheduled tweets, upload media, post in-thread replies, and delete campaign posts upon timer expiration.

users.read

Allows ChatCoat to verify your account identity, display your @handle and avatar in the dashboard, and retrieve mention author IDs.

offline.access

Provides a refresh token allowing ChatCoat to refresh access tokens in the background so scheduled campaigns publish reliably without requiring repeated logins.

dm.read & dm.write

Allows ChatCoat to send 1-on-1 private Direct Messages to consenting users who request details or customer support via your automated campaigns.

7. Data Retention, Disconnection & Deletion Rights

You retain complete sovereignty over your X account connection and stored data:

  • One-Click Disconnect: You can disconnect your X account at any time from the ChatCoat Integrations page. Disconnecting immediately removes your credentials and purges all stored tokens from our database.
  • Revocation via X: You can independently revoke ChatCoat’s access at any moment through your X account settings under Settings & Privacy > Security and account access > Apps and sessions.
  • Complete Data Deletion Request: To request total deletion of your campaign records, lead data, and organization account, visit our public User Data Deletion Page or email our compliance team at support@chatcoat.com. All associated records will be permanently purged within 30 days.

8. Contact Us & Compliance Inquiries

If you have any questions, compliance requests, or data privacy inquiries regarding this X Developer API Privacy Policy, please contact:

Application: ChatCoat

Compliance & Support Email: support@chatcoat.com

Official Website: https://www.chatcoat.com