Privacy Policy
Last updated: September 2026
1. What We Collect
Account info: the email address you provide at signup. Usage data: your API call records (endpoint, time, credits used, status code) for billing and analytics. Deposit info: your crypto deposit addresses and on-chain transactions (public addresses only — we never touch your private keys). We do not store your plaintext password (only an argon2 hash).
2. How We Use It
To provide the service, bill you, prevent abuse, send verification codes and essential service notices. We do not sell your personal data. Usage data is used for operations and capacity planning.
3. Third Parties
Email delivery uses Resend (only your email and code are transmitted). Deposit detection reads public blockchain data directly. We do not use ad-tracking. The X data you query comes from public information on the X platform — SocialAPI is an independent third-party service, not affiliated with, associated with, or endorsed by X Corp. (formerly Twitter, Inc.). We do not represent X, and we never hand your credentials to X or any third party (we never ask for your X account in the first place).
4. Data Retention
Account and billing data is retained while your account is active. You may request account deletion; we will delete your personal data to the extent permitted by law (records required for billing/compliance may be retained as legally required).
5. Security
Passwords are stored as argon2 hashes; API keys are stored only as SHA256 hashes (a database breach cannot recover plaintext). Deposits store only public addresses — private keys never reach our servers. Traffic uses HTTPS.
6. Your Rights
You may access, correct, or delete your account data. If you are in a GDPR/CCPA jurisdiction, you have the corresponding data rights. Contact us below to exercise them.
7. Contact
For privacy matters, contact [email protected]。