Effective 24 August 2026
Privacy Policy
This policy explains what Post Ascent handles when you use the website, native applications, hosted service, API, or MCP tools. The product is currently in private beta and this policy will evolve as the service develops.
1. The short version
Post Ascent uses information to provide writing, recommendation, publishing, synchronisation, and account features. We do not sell personal information. We limit provider access by capability, require clear approval for external actions, and provide ways to export or delete hosted account data.
2. Information we handle
Account and device information
For hosted accounts, we process your email address, authentication sessions, device registrations, workspace membership, entitlements, and security or audit events. Magic-link emails are used to confirm access to your account.
X account and content information
When you connect X, we process the account identifier, profile details, authorised tokens, relationships needed by selected features, posts, post media, and performance data. We may also process public profile and post information for recommendations, Inbox monitoring, Mutuals, and caching.
Writing and product information
We process drafts, replies, ideas, writing preferences, Coach requests and results, action receipts, usage records, spend estimates, sync cursors, and the settings needed to operate the product.
Website information
The current marketing website does not use advertising trackers or marketing cookies. Standard infrastructure logs may include an IP address, request path, timestamp, user agent, and security diagnostics.
3. How we use information
- Provide and secure accounts, devices, workspaces, and entitlements.
- Find relevant public conversations and refresh user-selected Inbox sources.
- Help you write, edit, publish, and learn from posts.
- Synchronise permitted data between Mac, iPhone, API, and MCP clients.
- Apply usage allowances, deduplication, cost controls, and abuse prevention.
- Diagnose faults and improve reliability, accessibility, and product design.
- Meet legal obligations and enforce the Terms of Use.
4. Providers
We share only the information needed for a provider to perform its role:
- X for account authorisation, publishing, and reads that require official or user-authorised access.
- TwitterAPI.io for eligible public X profile, relationship, and post reads in the managed service.
- OpenRouter to route Coach requests to the model selected by Post Ascent. A Coach request may include your instructions, relevant writing context, the post being answered, and an image when the selected model supports images.
- Robotomail for transactional account email.
- Cloudflare R2 for hosted media storage and encrypted off-site backups.
- Hetzner for hosted application and database infrastructure.
These providers process information under their own terms and privacy commitments. We may replace a provider when needed for security, quality, availability, or cost, while preserving the product's capability boundaries.
5. Credentials and security
Self-hosted DIY stores user-supplied provider credentials locally using macOS security facilities. The managed service stores the X credentials required for Cloud Pro operation in encrypted form. It uses scoped device, session, API, and MCP credentials so each client receives only the access it needs. No internet service can guarantee absolute security, but we use encryption in transit, restricted network access, audit trails, guarded releases, and encrypted backups.
6. Caching and retention
Public X data may be cached across hosted accounts so the service does not repeatedly purchase or request the same public resource. Private, owned, account-specific, or permission-limited data is kept within its workspace boundary. Active Inbox items can move to an archive after the product's active window rather than being immediately discarded.
We retain account data while an account is active and for the period reasonably needed to provide the service, resolve disputes, prevent abuse, meet legal obligations, and recover from faults. Backup copies age out according to the backup retention schedule. Some public information may remain in a shared cache until it expires or is refreshed.
7. Your choices
You can disconnect X, remove local provider credentials, change monitored people, revoke devices or personal access tokens, export hosted account data, and request hosted account deletion. Disconnecting or deleting Post Ascent does not delete content already published to X.
To request access, correction, export, or deletion, email [email protected]. We may need to verify that the request belongs to the account holder.
8. International processing and children
Our providers may process information in countries other than your own. Their locations and appropriate contractual or legal safeguards govern those transfers. Post Ascent is not directed to children and you must meet X's and your jurisdiction's minimum age requirements.
9. Changes and contact
We will update this page when practices materially change and will provide additional notice when appropriate. Questions about privacy can be sent to [email protected].