Official Legal & Compliance
X (Twitter) Developer API Privacy Policy
Effective Date: September 5, 2026 • Application: ChatCoat
1. X Developer Platform & Policy Compliance
ChatCoat integrates with the X API v2 (operated by X Corp., formerly Twitter) to provide social media publishing, scheduling, automated comment replies, media attachments, direct messaging, and post lifecycle management for connected organizations.
By connecting your X account to ChatCoat, you acknowledge and agree that our processing of your X data strictly adheres to:
- X Developer Agreement: Compliant with the X Developer Agreement.
- X Developer Policy: Compliant with all requirements of the X Developer Policy, including data protection, privacy by design, and strict limitations on data redistribution.
- X Automation Rules: Compliant with X Automation Rules, ensuring no spamming, aggressive auto-tweeting, or unsolicited bulk direct messaging.
- X Privacy Policy: Operating in full harmony with the X Privacy Policy.
2. Information We Collect via X API v2
ChatCoat collects and processes only the minimal data strictly required to deliver automated publishing, mention polling, and conversational assistance:
Account & Profile Data
- X User ID (unique numerical platform identifier)
- Account username (handle, e.g., @username)
- Public display name and profile image URL
- AES-256 encrypted OAuth 2.0 access and refresh tokens
- Granted OAuth permission scope list
Content & Interaction Data
- Tweet text, links, hashtags, and scheduling timestamps
- Media files (images, GIFs, videos) uploaded to X endpoints
- Published Tweet IDs and permalinks (https://x.com/user/status/id)
- Public mentions and in-thread replies to your posts
- Direct message (DM) conversation IDs and message texts
3. Purpose of Processing X Data
All X data handled by ChatCoat is processed solely for authorized business operations configured by the account owner:
- Post Publishing & Scheduling: Composing, scheduling, and automatically posting tweets and multi-media attachments to your X profile at user-specified times.
- Post Lifecycle & Auto-Deletion: Automatically deleting scheduled campaign tweets via the X API v2 DELETE endpoint once a user-configured lifetime (hours) expires.
- Mention & Comment Monitoring: Polling public mentions and replies to your posts to detect pre-configured keywords (e.g., price, info, link, help).
- Automated Public Thread Replies: Publishing contextual, non-repetitive public replies to users who inquire about your campaign on X.
- Direct Message (DM) Customer Care: Delivering 1-on-1 private direct messages containing requested information or customer support links when triggered by customer engagement.
4. Security, Token Encryption & PKCE Standards
We implement comprehensive security controls to safeguard your X account access:
- OAuth 2.0 with PKCE: We use the OAuth 2.0 Authorization Code Flow with Proof Key for Code Exchange (PKCE S256). High-entropy code verifiers and state tokens are HMAC-signed to eliminate authorization code interception attacks.
- Authenticated Encryption at Rest: All X access tokens and refresh tokens are encrypted using AES-256 / Fernet before storage in our database. Plaintext tokens are never written to disk or recorded in operational application logs.
- Automatic Token Refresh: Expired or near-expiry access tokens are automatically refreshed in the background using the offline.access refresh token grant.
- Multi-Tenant Isolation: All connections, campaigns, and tokens are strictly segregated by organization ID to guarantee zero unauthorized cross-account visibility.
- Transport Layer Security (TLS 1.3): All requests between client browsers, ChatCoat servers, and X API endpoints occur strictly over TLS 1.3 encrypted HTTPS channels.
5. No Sale of X Data & Strict Use Restrictions
In strict accordance with the X Developer Policy:
- ChatCoat never sells, rents, leases, trades, or syndicates X user data, tweets, follower lists, or metadata to third parties, data brokers, or advertising networks.
- ChatCoat does not use X Content to train proprietary foundation or generative artificial intelligence models without your explicit prior authorization.
- ChatCoat does not conduct mass surveillance, profiling, or unauthorized bulk harvesting of X users or public timelines.
6. Requested X OAuth 2.0 Scopes Explained
ChatCoat requests only the granular scopes needed to execute user-directed publishing and automation:
tweet.readAllows ChatCoat to read your tweets, mentions, and reply threads to monitor keyword triggers and display campaign metrics.
tweet.writeAllows ChatCoat to publish scheduled tweets, upload media, post in-thread replies, and delete campaign posts upon timer expiration.
users.readAllows ChatCoat to verify your account identity, display your @handle and avatar in the dashboard, and retrieve mention author IDs.
offline.accessProvides a refresh token allowing ChatCoat to refresh access tokens in the background so scheduled campaigns publish reliably without requiring repeated logins.
dm.read & dm.writeAllows ChatCoat to send 1-on-1 private Direct Messages to consenting users who request details or customer support via your automated campaigns.
7. Data Retention, Disconnection & Deletion Rights
You retain complete sovereignty over your X account connection and stored data:
- One-Click Disconnect: You can disconnect your X account at any time from the ChatCoat Integrations page. Disconnecting immediately removes your credentials and purges all stored tokens from our database.
- Revocation via X: You can independently revoke ChatCoat’s access at any moment through your X account settings under Settings & Privacy > Security and account access > Apps and sessions.
- Complete Data Deletion Request: To request total deletion of your campaign records, lead data, and organization account, visit our public User Data Deletion Page or email our compliance team at support@chatcoat.com. All associated records will be permanently purged within 30 days.
8. Contact Us & Compliance Inquiries
If you have any questions, compliance requests, or data privacy inquiries regarding this X Developer API Privacy Policy, please contact:
Application: ChatCoat
Compliance & Support Email: support@chatcoat.com
Official Website: https://www.chatcoat.com