Privacy policy
Last updated September 15, 2026
In short
- We keep the minimum: your sign-in, what you set up, and a prepaid ledger.
- We read public posts from X, Bluesky, Reddit, YouTube and Hacker News through their official APIs, read only, and show them to the paying user whose watches matched them.
- We do not sell personal data, ours or anyone's, and we run no ad trackers. Our analytics is cookieless and stores nothing about you.
- A cached post is deleted 30 days after we fetched it.
- You can pause or delete your account from Settings at any time.
Who we are
Xiroto is operated by Md Obydullah, an individual based in Bangladesh. Xiroto is a read-only tool that watches public posts on X, Bluesky, Reddit, YouTube and Hacker News for the topics and accounts you choose, and drafts replies you can post yourself.
This policy explains what we collect, why we collect it, who else touches it, and how you get it deleted. If anything here is unclear, email us at [email protected] or reach us on X at @obydulme.
What we collect
Your account. When you sign in with X we store your X handle and your X user id. If you sign in with Google or with an email code, or add an address later, we store your email address. If you choose to set a password we store it hashed, never in plain text.
What you set up. This is the working data of the product: your projects, your watches (keywords, brand terms and the accounts you follow), your active hours and timezone, a Telegram chat id if you link one, your spend limits, the lines you write about how you want to sound, and any API keys you create for your editor. A key is stored only as a hash, so nobody at Xiroto can read it back to you or use it.
The browser extension. If you install Xiroto for your browser, it sends only the post you press its control on, with what that post already shows: its text, its link, its author's handle and name, the date and the counts. It reads nothing else on the page, it never calls the platform's own API and it never reads your cookies or your login. Your Xiroto key is kept in that browser and sent only as the bearer on that one request. It is filed the way a post you paste in by hand is filed, and deleted on the same schedule.
Two rows in the extension read more than one post, and each says so before you press it. Note their rhythm sends the dates of the posts a profile page is already showing, and never a word of their text. Capture what is on screen takes one picture of the visible tab, on your click, and sends it to be read once. Neither one scrolls the page, opens another, or fetches anything.
Technical data. Server logs, your IP address for rate limits, a session cookie, a cookie holding your theme and one holding the project you last opened. We count page views and a few named events with Umami, a cookieless analytics tool: no cookies, no personal data, your IP address hashed with a salt that changes daily and never stored. We honour Do Not Track. We run no advertising trackers.
Public posts we read from X, Bluesky, Reddit, YouTube and Hacker News
To run a watch we call the public API of each platform it covers, X, Bluesky, Reddit, YouTube or Hacker News, and fetch the public posts that match it. For each post we store the text, or the title and description for a video, a link to the original, the author's public handle, name, avatar, bio and follower or subscriber count, the engagement counts the platform shows (likes, replies, reposts, views, upvotes, points, comments), and the time it was posted.
These posts go into one shared cache, one row per post no matter how many users' watches matched it. A post is deleted 30 days after we last fetched it, whether or not a watch still refers to it. A post you starred stays up to 90 days. An author's public profile goes when none of their posts is left.
X. We use the official X API with read access only. We store the post id, text, link, time, like, reply, repost and view counts, and the author's public profile fields. We never ask for your X password, and the only token we hold is the read-scoped one from sign-in with X, if you use it.
Bluesky. We use the public Bluesky API, read only and without an account. We store the post id, text, link, time, like, reply and repost counts, and the author's public profile fields. Bluesky is an open network: posts there are public by design and readable by anyone.
Reddit. We use the official Reddit Data API, public search and listing endpoints only. We store the post id, subreddit, title, an excerpt of the body, score, comment count and times. We do not use Reddit data to train any AI model. If a post has been removed from Reddit and is still in Xiroto, tell us and we drop our copy.
YouTube. We use the YouTube Data API to read public videos: id, title, description, channel name and avatar, subscriber, view, like and comment counts, and the publish time. We never ask for access to your YouTube account, and YouTube data is deleted within 30 days of fetching.
Hacker News. We use the Hacker News Search API run by Algolia, read only and without an account. We store the item id, the story title and link or an excerpt of its text, an excerpt of a comment with the title of the story it answers, the author's username, public bio and karma, the point and comment counts, and the time it was posted. Hacker News items are public by design and readable by anyone.
The people who wrote these posts are not our users, and we process their public posts on the basis of legitimate interest: showing a paying user what was said in public about the topics they follow, so they can answer it. If you wrote a post we cache and want it removed, email [email protected] with a link to it and we will delete our copy within 30 days.
Xiroto is read only on every platform. It never posts, likes, follows, replies, upvotes, comments or sends messages from your account, and sign-in with X asks for read scopes only.
How we use it
We use what we collect to:
- run your watches and show you the posts that match them
- score those posts so the ones worth answering come first
- write a suggested reply with an AI model, using the post text and your voice profile. You decide whether to post it, by hand, on the platform the post came from
- send you a Telegram ping if you have linked a chat
- charge your prepaid balance for each post read
- answer your support messages
- keep the service working, and keep it free of abuse
That is the whole list. The posts and public profiles Xiroto collects exist for one reason: to show a paying user what matches their watches, so they can reply to it themselves on the platform it came from. We do not sell that data, rent it, license it, share it with advertisers or data brokers, or build profiles of the people who wrote those posts for anyone else. Nobody outside the app sees it.
AI scoring and drafts
Two things go to an AI model. Scoring: the text of a matched post, so the ones worth answering come first. Drafting: the text of the one post you asked about and a few of your own public posts, so the draft sounds like you. Nothing else about you is sent, and nothing is sent about posts you did not match.
When you edit a draft and mark it as replied, we store what you wrote next to the draft it came from, for 90 days, so Xiroto can learn how you write. Both are deleted with your account.
When you discuss a draft, what you say to Xiroto and what it answers are kept for 90 days and deleted with your project. A draft you choose to use is kept with the one before it for 90 days, to learn what the drafts keep getting wrong.
If you paste text, upload a CV, or give us a page to read, we read it once to write memory lines you can see, edit and delete on Grow, Memory. We do not keep the file or the page.
If you drop a screenshot on Xiroto, or capture one with the extension, the model reads it once to write down the posts it can see. We do not keep the picture. What we keep is those posts, as examples on Grow, Examples, which you can see, edit and delete.
Post ideas we draft for you come from your own memory, your replies, the posts your watches found, the posts you tell us you published, and the text you tell us you posted; dismissed ones are deleted after 30 days, unposted ones after 14. A post you put in a series stays as long as the series.
The models run through OpenRouter and the providers behind it, under their API terms. We do not train any model on platform data or on your data, and we do not allow a provider to keep what we send beyond serving that one call.
Your own API keys
If you add your own X, YouTube or model keys, they are encrypted at rest with AES-256-GCM and are never shown again after you save them. They are used only for your own projects, and they are deleted when you delete the project or your account.
Payments
For every top-up we record the amount, the method, and a transaction reference. For crypto that reference is the transaction hash you give us. We never see or store card numbers.
Today you top up with crypto: Binance Pay, or USDT and TRX on public blockchains, under their own terms, and we record the transaction hash you give us. Card, Google Pay and Apple Pay come through Creem, the trading name of Armitage Labs OÜ, acting as merchant of record: it takes your name, email, billing country and card details under its own privacy policy, handles the tax, and hands us the amount, a reference and your billing country. We still never see the card number. Creem is the seller named on your receipt. Separately, a usage ledger records every X, Reddit, YouTube and model call made for you with its cost. That ledger is what your balance is charged from.
Who else touches your data
These are the processors we rely on to run Xiroto:
- X Corp, for the X API
- Bluesky Social, PBC, for the public Bluesky API
- Reddit, Inc., for the Reddit API
- Google, for the YouTube Data API
- Algolia, for the Hacker News Search API
- OpenRouter and the model providers behind it, which receive the post text and your voice examples when a draft is generated
- Firecrawl, which fetches a page you ask us to read, on our behalf, and receives that URL
- Creem (Armitage Labs OÜ, Estonia), as merchant of record for card, Google Pay and Apple Pay
- Vercel, for hosting
- Umami Software, Inc., for cookieless analytics (Umami Cloud)
- Supabase, for the database
- Amazon Web Services, for sending email
- Cloudflare, for DNS, inbound email, and the bot check on our forms
- Telegram, for pings, if you have linked a chat
- Binance Pay and the crypto networks you pay through (BSC, Tron, Solana), for top-ups today
- A card payment provider, for card, Google Pay and Apple Pay top-ups. Not wired yet; it is named here the day it is, and it, not us, will hold your card details
We do not sell personal data, yours or that of the people whose public posts we cache, and we do not share it for advertising. Each processor above handles data only to provide its service to us, never for its own use.
Xiroto uses YouTube API Services to read public videos. Google's handling of that data is covered by the Google Privacy Policy. Xiroto does not ask for access to your YouTube account.
These processors run outside the EU and the UK: the database is in Singapore and the rest is mostly in the United States. Where the law requires it, transfers rest on the processor's standard contractual clauses.
Keeping and deleting
You can pause your account at any time, which stops every watch and every charge. You can delete your account from Settings. Nothing runs for 7 days and you can restore it inside that window, after which your projects, watches, keys and voice profile are deleted.
The payment and usage ledger is kept for accounting. It stays attached to an account row that has been stripped of your handle, your email and every other personal field. Your email address is replaced by a one-way hash, so that a deleted account can be recognised if it comes back. Unused balance is not refunded.
How long things stay:
- Your account and what you set up: until you delete it, plus the 7 day restore window
- Cached public posts: 30 days after we last fetched them, 90 if you starred one
- Expired sign-in sessions and codes: deleted daily
- Demo links: 30 days after they expire
- The payment and usage ledger: as long as accounting requires, with personal fields removed
- Server logs at our host: a short rolling window, days not months
- Database backups: our host keeps daily backups for 7 days, so a deleted row can outlive its deletion by that long
Your rights
Depending on where you live, under GDPR, UK GDPR, CCPA or your local law, you can ask for access to your data, correction of it, deletion of it, a copy of it, and you can object to how we use it.
Email [email protected] from the address on your account and we will answer within 30 days. You can also complain to your local data protection authority.
Security
Traffic is encrypted with TLS in transit, your keys are encrypted at rest, and access to the database is least privilege. No method is perfect. If you find a problem, tell us at [email protected] and we will look at it quickly.
Age
Xiroto is not for anyone under 16.
Changes to this policy
When this policy changes we update this page and the date at the top. Material changes are announced by email to account holders.