Privacy Policy

Last updated: August 2026

This Privacy Policy explains how xposter.app ("we", "us") collects, uses, and protects your personal information when you use our Service.

Who is responsible for your data

xposter.app is operated from Türkiye and is the data controller for the personal data described in this policy. For any question about this policy, or to exercise the rights listed in section 5, contact [email protected]. We answer data requests within 30 days.

1. Information We Collect

We collect the following information:

2. How We Use Your Information

Legal basis for processing (GDPR Article 6):

3. AI Processing

Content you submit for generation is sent to Anthropic's Claude API to produce output. Anthropic's own privacy policy and data practices govern how they handle API inputs. We do not use your prompts to train our own models.

4. Data Storage

Your account data and generated posts are stored on our server in the European Union. Passwords are hashed using bcrypt and are never stored in plain text.

5. Your Rights

You have the following rights regarding your personal data:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

Data breaches: In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with applicable law.

6. Cookies

We use a single authentication token stored in your browser's local storage to keep you logged in. We do not use tracking cookies or third-party analytics cookies.

7. Third-Party Services

The Service depends on the providers below. We list what each one receives, because "third-party services" without that detail tells you nothing useful.

8. International Data Transfers

Our server and your stored data are located in the European Union (Germany). However, several of the providers listed above operate outside the EU, principally in the United States: Anthropic, Voyage AI, LemonSqueezy, Resend, Google and X. Using the Service therefore involves transferring personal data outside the EEA.

These transfers rely on the transfer mechanisms offered by each provider. Standard Contractual Clauses adopted by the European Commission and, where the provider is certified, the EU–US Data Privacy Framework. If you would like details of the mechanism relied on for a specific provider, contact us and we will tell you.

9. Data Retention

We retain your account data for as long as your account is active. If you request deletion, we remove your personal data within 30 days.

Server access logs are a separate case and we would rather say so than let the sentence above imply otherwise. They record IP addresses, timestamps and requested pages, they are kept for 14 days and then deleted automatically, and they are not searched or erased individually when an account is deleted. They exist to investigate abuse and faults.

10. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. In certain EU member states the age of digital consent is 16. If you are under this age, please obtain parental consent before registering.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before they take effect. For material changes that affect how we process your personal data, we will seek your explicit consent where required by law. Continued use of the Service after the effective date of non-material updates constitutes acceptance of the revised policy.

12. Contact

Questions or data requests? Email us at [email protected].