Privacy Policy
Crosspost is operated by MikeDemo. This page explains what is stored and why.
What is stored
- Your email address and sign-in details, including two-factor setup.
- The tweet.app handle you watch and your posting preferences.
- A record of posts already sent, so the same post is never published twice.
- Your four X developer values, encrypted at rest.
How your X keys are handled
Your API key, API key secret, access token and access token secret are encrypted before they are stored, are only decrypted on the server when a post is published, and are never sent back to any browser — including yours.
Who it is shared with
- The hosting and database provider that runs the service.
- X, when a post is published with your credentials.
- tweet.app, when your watched account is checked for new posts.
- hCaptcha, which screens the sign-in and sign-up form for bots.
Your data is not sold, and it is not used for advertising.
Deleting your data
Removing your keys in the app deletes them and stops all posting immediately. Deleting your account removes your settings and post history. You can also revoke Crosspost's access at any time by regenerating your tokens in the X developer console.
Contact
For any question about your data, reach MikeDemo through the links in the footer of this site.