Privacy policy

Last updated: Aug 24, 2026

1. Introduction

SteadyBoost helps you write posts for X that fit your niche. You tell us what you are promoting and point us at a few pages of your own; we read those pages, work out the niche you are writing in, look at recent high-performing posts in that niche, and generate draft posts for you to edit. You choose what to do with each draft: copy it out and post it yourself, or — where the feature is available to you — have us publish it to your connected X account, immediately or at a time you schedule.

This policy explains what we collect, why, who else sees it, and how to get rid of it. It describes what the service actually does today. Where something is handled by hand rather than automatically, we say so.

2. Who is responsible for your data

The controller of your personal data is [TBC: registered legal entity, company number, and registered address], contactable at [email protected].

3. Information we collect

3.1 Information you give us

  • Account details. Your email address, and a display name if you set one. We sign you in with a one-time code sent to your email, or with your X account if you choose that instead. Either way we never hold a password.
  • Files you upload. A profile picture, if you set one, shown only to you. Any other files you upload are stored in our object storage under your account, along with their file name, type, and size. An image you attach to a post is different: if that post is published, the image goes to X and becomes public.
  • What you tell us during onboarding. What you are promoting and what kind of thing it is, its name, up to three web addresses, who you are trying to reach, the tone you want, the languages you write in, anything you want us to avoid, and an optional call to action and link. Where you connect an X account, what we take from it is described in section 3.4.
  • Every draft we generate for you. Including your edits, and whether you approved or discarded each one. Discarding a draft hides it rather than deleting it, so that you can restore it later. Drafts are erased when your account is.
  • Anything you send our support. Contact form messages, bug reports, and feature requests, along with the name and email address you submit them under.
  • Billing details, if you buy something. These go directly to Stripe. We never see or store your card number; we keep the billing name and email Stripe reports back to us, along with what you bought. Where a purchase includes a licence key, we store that key against your account and email it to you.

3.2 Information we work out from what you give us

From the pages you point us at, the answers you give during onboarding, and the bio on any X account you connect, we derive and store a niche label, a set of search keywords, a summary of your writing voice, a short description of what you are promoting, and the extracted text of those pages. You can review and edit these before anything is generated. Each brand profile you create holds its own set.

3.3 Information collected automatically

  • Usage analytics. We use Umami to count page views, including navigation within the app, and to record a small number of product events. See section 6.
  • Your IP address, used once per visit to guess your country so we can show prices in a sensible currency. That lookup is not stored. See section 8.
  • Sign-in session details. When you sign in we store the IP address and browser user agent against that session, so you can tell your own sessions apart and so we can investigate account abuse. These are deleted with the session.
  • Sign-in security data. We count recent one-time-code requests per email address to stop people being spammed with codes.
  • A time zone, if you set one in your settings so that scheduled posts go out at the hour you meant. We store the zone you choose, not your location.

3.4 Information we receive from X

If you sign in with X, or connect an X account to a brand profile, X sends us your handle, display name, profile picture address, and the email address on your X account. Where you connect an account we also store your X bio and profile URL, and your bio is sent to our AI provider to draft a description of what you are promoting — that description prefills a field you can edit or clear before anything is generated from it. Your handle itself is stored for your reference and is not used to generate anything.

Connecting an X account also stores an access credential for it, so that we can act on the permissions you granted. We ask only for the permissions the features you use require, and you can revoke them at any time by disconnecting the account here or from your X settings. Disconnecting cancels any posts still queued for that account.

4. Pages you ask us to analyse

When you give us a web address during onboarding, our servers fetch that page and extract its readable text. Two things follow from that. The site you name will see a request coming from us rather than from you, and the text we extract is held on our servers for the rest of onboarding, stored against your profile, and sent to our AI provider. Only give us addresses you are happy to have read this way — your own site, your own landing page. We do not fetch anything you have not explicitly listed, and we do not re-fetch those pages on a schedule.

5. How we use your information

  • To sign you in and keep your session secure.
  • To work out the niche and voice of each brand profile you set up, and to generate draft posts from them.
  • To publish a post to your connected X account when you tell us to, either straight away or at a time you schedule, and to keep the queue of posts you have scheduled.
  • To find recent high-performing public posts on X that match your keywords, as examples for the drafts.
  • To store your drafts so you can come back to them.
  • To take payment, manage your subscription, and count how many times you have generated drafts.
  • To send you the emails the service depends on: sign-in codes, and messages about your account or purchase.
  • To send you product news and offers, only if you ticked the optional box when you signed up or bought something. This is separate from the emails above, which you receive either way.
  • To answer you when you contact us.
  • To understand which parts of the product get used, in aggregate.
  • To protect the service from abuse, and to meet our legal obligations.

We publish to X only the posts you have selected, to the account you connected, at the time you chose. We never post anything you have not approved, and we never post on your behalf without an instruction from you. We do not sell your personal data. We do not use your drafts or your profiles to generate anything for anyone else.

6. Analytics

We use Umami to understand how the product is used. Umami sets no cookies and stores no identifier on your device, which is why this site has no cookie consent banner for analytics. It anonymises IP addresses.

Page views are recorded automatically. Beyond those we record a small number of named events — signing up, signing in, starting checkout, opening the billing portal, completing a purchase, finishing an onboarding step, finishing onboarding, and generating drafts. The data attached to these events is limited to yes/no flags, small counts, fixed option values, and the identifier of the Stripe price involved, which identifies the plan being bought and not the person buying it.

Analytics events never carry your email address, your account identifier, your Stripe customer or session identifiers, the content of your drafts, or anything you typed in free text during onboarding.

7. Cookies

  • Essential. A session cookie that keeps you signed in. Without it the service cannot work.
  • Preferences. Your language and light/dark theme choices, so they persist between visits.

We use no advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings.

8. Third-party services

These are the services that receive data as part of running SteadyBoost:

  • Anthropic — receives your onboarding answers, the text extracted from the pages you listed, the bio of any X account you connect, and the example posts, in order to produce your niche, keywords, voice summary, description, and drafts.
  • GetXAPI — receives your niche keywords and language in order to search X for recent high-performing public posts. It does not receive your identity or your drafts.
  • X Corp — receives your sign-in or connection request when you use your X account, and returns the details in section 3.4. When you publish or schedule a post, X also receives that post's text and any image you attached, published publicly under your X account. What happens to it then is governed by X's own terms and privacy policy, not ours.
  • Stripe — payment processing, subscriptions, and the billing portal.
  • Resend — sends the emails, and so receives your email address and the message contents.
  • S3-compatible object storage — stores your profile picture and any images you attach to posts.
  • IPInfo — receives your IP address when you load a page with prices, so we can guess your country and pick a currency. We do not store the result.
  • Umami — analytics, as described in section 6.

Each of these processes data under its own privacy policy. The websites you ask us to analyse are not our services; requests to them are described in section 4.

9. International data transfers

The services listed above operate internationally, and your data is processed outside your country of residence. Anthropic, Stripe, Resend, IPInfo, GetXAPI, and X are all reachable only as internet services, and we do not control where within their infrastructure your data is handled.

10. Data storage and security

  • All traffic to and from the service is encrypted in transit using TLS.
  • Card details never reach our servers; payments run through Stripe's PCI-compliant infrastructure.
  • We hold no passwords. Sign-in uses one-time codes that expire.
  • Requests that cost money or send email are rate-limited per user.
  • Pages we fetch on your behalf are checked so they cannot be used to reach our internal network.

No service can promise perfect security, and we do not. If we discover a breach affecting your personal data, we will tell you and the relevant authority as the law requires.

11. How long we keep things

  • Your account and everything in it — kept while your account exists. See section 12.
  • Drafts, including discarded ones — kept while your account exists. Discarding is not deletion; it hides the draft so you can restore it. If you want a specific draft erased before then, ask us.
  • Posts you have scheduled — kept until they are published, you cancel them, or the X account they were queued for is disconnected. A post still queued when your account is marked for deletion is cancelled rather than published.
  • Cached example posts — public posts we pull from X are cached for up to 48 hours and then expire. They are cached against a set of keywords rather than against you, and are shared by everyone writing in the same niche.
  • Sign-in throttling counters — deleted automatically once they expire.
  • Payment records — kept after your account is deleted, for accounting and tax purposes. See section 12.

12. Deleting your account

You can delete your account from your settings. Deletion is not immediate: your account is marked for deletion and permanently purged 30 days later, by a job that runs once a day. During those 30 days you can cancel and keep everything.

When the purge runs, we delete your account and with it:

  • Your sign-in sessions and credentials.
  • Every brand profile you created, including the extracted page text, keywords, voice summary, description, and the details of any X account attached to it.
  • Any X access credentials we held for you, and any posts still queued for publication.
  • Every draft we generated for you, and your generation history.
  • Your profile picture and any images you attached to posts, removed from object storage.
  • Any bug reports and feature requests you filed.
  • Your customer record at Stripe, deleted through Stripe's API.

Some things deliberately survive, and you should know which:

  • Payment and subscription records, which keep the billing name and email address attached to the purchase. They are disconnected from your account but not erased, because we need a record of transactions.
  • Messages you sent our contact form, and the raw records of payment events received from Stripe.
  • Any files other than your profile picture that you uploaded remain in object storage. Ask us and we will remove them.

If you want any of the surviving records erased as well, email us at [email protected] and we will do it by hand where the law does not require us to keep them.

13. Your rights

Depending on where you live, you have the right to access your personal data, correct it, have it deleted, object to or restrict how we use it, receive a copy in a portable form, and complain to your data protection authority.

Deleting your account is self-service, as described in section 12. Everything else is handled manually: email [email protected] and we will respond within the time the law allows. We do not currently offer a self-service export, so a request for a copy of your data is fulfilled by a person.

14. Age restrictions

This service is not intended for anyone under 16. We do not knowingly collect data from under-16s, and will delete it if we find we have.

15. Changes to this policy

We may update this policy. Material changes will be announced by email to account holders or a notice in the app, and the date at the top of this page will change.

16. Contact

Questions about this policy, or a request about your data: [email protected].