X Aligne
Effective August 3, 2026

Privacy notice

This notice explains the data X Aligne processes when provider-backed features are enabled. A qualified privacy professional should review it against the owner’s final company, jurisdiction, support, retention, and subprocessor details before commercial launch.

Data we process

Account data can include your email address, display name, authentication identifiers, workspace settings, drafts, schedules, saved signals, contacts, automation settings, API-key metadata, usage events, and service logs. Secret API keys are shown once and stored only as hashes.

X account data

When you connect X, X Aligne stores the account identifier, username, authorized scopes, token expiry, and encrypted OAuth access and refresh tokens. It uses those credentials only for features you invoke, such as account sync, analytics, scheduling, and explicit publishing. Disconnecting removes the stored connection.

AI and billing

Text submitted for AI assistance is sent to the configured AI provider, either directly or through Vercel AI Gateway. Subscription checkout and billing are handled by Dodo Payments; X Aligne stores customer, subscription, product, status, and renewal metadata rather than full card details.

Providers

Supabase provides authentication and database services, Vercel hosts the application and optional AI Gateway, OpenAI and Google may process AI requests, X supplies account APIs, and Dodo Payments supplies checkout and subscription services. Their processing is also governed by their own terms and privacy notices.

Browser demo and extension

The unauthenticated demo stores workspace state in browser local storage. The Manifest V3 extension stores its API URL and scoped key in Chrome local storage; content scripts do not receive the key. You can reset demo data, revoke extension keys, or clear browser/extension storage at any time.

Retention, security, and choices

Data is retained while needed to provide the service, meet legal obligations, resolve disputes, and protect the service. Controls include row-level database policies, server-only provider credentials, encrypted X tokens, hashed API keys, signed billing webhooks, and scoped access. No system is completely secure. Account export, correction, and deletion workflows must be verified before public launch.

Questions

Use the support contact published by the service owner. Until that private channel is added, you may open a repository issue for general questions, but never include credentials, tokens, payment information, or sensitive personal data in a public issue.

← Back to X Aligne