tweet.stream
← Back to the rinkTHE RULEBOOK / 01

Privacy policy.

Who we are

tweet.stream is an X API and Model Context Protocol (MCP) project maintained by Vartabase AI. This policy covers the tweet.stream website and any tweet.stream service we operate. If you run the open-source software yourself, you control that installation and are responsible for its data practices. Independent hosts and AI clients have their own policies.

When you visit this website

The landing page does not use advertising trackers, analytics scripts, third-party fonts, tracking cookies, or persistent browser storage. The rink, example tool responses, and score run in your browser; playing does not connect to X or publish anything. Our hosting infrastructure may process standard request information such as IP address, requested URL, browser information, and timestamps to deliver and protect the website.

When you connect an X account

A configured hosted service uses X OAuth 2.0 with PKCE. You authorize access on X; we do not ask for your X password. The server receives your X user ID, username, display name, access token, refresh token when issued, token expiry, and connection date. It creates a tweet.stream API key to authenticate your requests. The requested scopes are tweet.read, tweet.write, users.read, and offline.access.

How the service uses information

The hosted server uses credentials to authenticate requests, refresh access when permitted, and carry out API or MCP calls you or your authorized client initiate. Requests can include post text, replies, post identifiers, search queries, and requested timeline data. Relevant information is sent to X to fulfill the request and the result is returned to the requesting client. We do not sell personal information or use it for advertising.

AI clients and other recipients

If you connect an AI application, information returned by tools may be processed by that application and its model providers under their own terms. Only connect clients you trust. X processes information under its own privacy policy. Infrastructure providers process information needed to operate the service. We may disclose information when legally required or necessary to investigate abuse, protect users, or defend legal rights.

Storage and retention

The current open-source server persists connected-account credentials and profile fields in an operator-controlled token-store file. Its default implementation does not provide automatic expiry-based deletion of stored sessions. Records remain until removed by the operator or replaced on reconnection. The landing page does not collect or store these credentials. Request bodies are processed to fulfill calls; infrastructure logs and any copies retained by your AI client are managed separately by their operators.

Disconnecting and deletion

You can revoke tweet.stream in X’s Settings → Security and account access → Apps and sessions → Connected apps. Revoking access stops future authorized X calls but does not itself remove an existing token-store record or delete posts already published to X. To request deletion of a hosted account record, contact the maintainer through the contact page. For a self-hosted instance, ask its operator to remove your record and associated copies. Manage published posts directly on X. Never include API keys, tokens, or private account information in a public issue.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your information, object to processing, restrict processing, withdraw consent, or complain to your local privacy authority. Contact us to make a request; we may need to verify control of the relevant account. Where applicable, we process information to provide a requested service, with your authorization, for legitimate interests in security and operations, or to meet legal obligations.

Security and international processing

Treat API keys and OAuth credentials as passwords. We cannot guarantee absolute security. Information may be processed where our hosting providers, X, or your selected AI client operate, including outside your country. Self-hosters choose their own storage location and must protect token files, logs, backups, and network access.

Children and changes

The service is not intended for children under 13 or anyone below the minimum age required by X and local law. Contact us if you believe a child has provided personal information. We may update this policy when the service changes; the effective date below identifies the latest revision. Material changes will be described on this page.

Contact · Privacy policy · Terms of service