Legal
Privacy Policy
The short version
We store your X profile data, your posts and their performance, the accounts you target, and your achievements. Your X access tokens are encrypted. There are no analytics or advertising cookies of any kind. Deleting your account deletes your data within 30 days.
1. Who controls your data
CodeHawks, based in Folkestone, United Kingdom, is the data controller for personal data processed through Hawkpost. Contact us at hello@codehawks.co.uk about anything in this policy.
We handle personal data under the UK GDPR and the Data Protection Act 2018.
2. What we store
Your X account
- Your X user ID, handle, display name and profile image URL, so the app can show you which account you are working on.
- OAuth access and refresh tokens, encrypted with AES-256-GCM before they are written to the database. These let Hawkpost read your metrics and publish posts you have approved. They are never shown in the interface or logged.
- Your timezone, so the daily plan arrives in your morning.
Content and activity
- Posts and drafts you create in Hawkpost, plus posts it imports from your X timeline so your history is complete.
- Performance figures for your posts: impressions, likes, reposts, replies, quotes and bookmarks.
- Daily follower, following and post counts, kept as a dated snapshot so the app can show you a trend.
- The accounts you add as targets, including their public handle, bio and follower count, plus your own private notes and tier for them.
- A log of replies and other engagement you record, used for your daily progress and the Connection achievements.
- Public posts from your target accounts, cached for up to 72 hours so the reply feed loads without calling X on every page view.
- Your achievements, XP, level and streak, and your niche description, content pillars and projects.
Account and billing
- Your email address, which we receive from Stripe when you subscribe. We use it for billing notices and important service messages. X does not give us your email, so free-plan accounts usually have none on file.
- Your Stripe customer and subscription identifiers, your plan and its status. We never see or store card details.
- A count of how many X posts have been read on your behalf this month, so we can apply your plan's allowance.
If you add your own AI key
You can optionally supply your own Google AI API key for image and video generation. It is encrypted at rest with the same scheme as your X tokens and used only to make requests you trigger. You can remove it at any time from settings.
3. What we do not do
- No analytics or advertising cookies. No Google Analytics, no pixels, no session recording, no third-party trackers. The only cookies Hawkpost sets are the ones it needs to keep you signed in (see section 8).
- We do not sell or share your data with anyone for their own marketing.
- We do not read your direct messages. Hawkpost never requests DM access.
- We do not train AI models on your content. See section 5.
4. Why we are allowed to process it
- Performing our contract with you. Almost everything above: without it there is no plan, no analytics and no publishing.
- Legitimate interests. Keeping the service secure, preventing abuse, measuring our own X data costs, and fixing bugs from error logs.
- Legal obligation. Keeping billing records for tax purposes.
- Consent. Only where we ask for it specifically, such as storing your own AI provider key. You can withdraw it at any time.
Where we store information about your target accounts, those people are not our customers. We hold only what X already publishes about them, plus your private notes, on the basis of our and your legitimate interest in running a targeted engagement plan. If someone objects, contact us and we will remove them.
5. AI processing
To draft posts, classify your content and write your weekly review, we send the model the material it needs: the text of your recent posts and their performance figures, your niche description and content pillars, and the handles and public bios of target accounts. We do not send your email address, your billing details or your X tokens.
Requests go through Vercel AI Gateway to Google's Gemini models. These are business API endpoints, which means the content is not used to train the underlying models. Image and video generation works the same way, or through your own key if you have added one.
6. Who else processes your data
We keep the list short on purpose. Each of these is a processor acting on our instructions under a data processing agreement.
- Neon hosts the database.
- Vercel hosts and runs the application, stores uploaded and generated files, and routes AI requests.
- Google provides the AI models, via Vercel.
- Stripe processes payments and holds your billing details as its own controller.
- X Corp receives requests we make on your behalf, under the authorisation you granted.
Some of these operate outside the UK, including in the United States. Those transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework.
7. Generated images are stored with public read access
Images and video that Hawkpost generates for you, and any logo you upload, are stored on Vercel Blob and are readable by anyone who has the file's URL. The URLs are not listed or linked anywhere public, but they are not secret either. This is because X needs to fetch the file in order to attach it to a post.
Do not upload anything confidential as a logo or post image. We are planning to move this to signed, expiring URLs.
8. Cookies
Hawkpost uses three cookies, all strictly necessary, so there is no consent banner:
hawkpost_session: a signed token that keeps you logged in. Lasts 30 days and can be invalidated by us at any time.x_oauth_stateandx_code_verifier: short-lived values used once during X sign-in to prevent request forgery. Deleted the moment sign-in completes.
All are HTTP-only and cannot be read by scripts in your browser.
9. How long we keep things
- While your account is open: your posts, analytics, targets and achievements are kept indefinitely, because the coaching depends on history.
- Cached target posts: deleted automatically after 72 hours.
- Cached account searches: deleted after 7 days.
- After you delete your account: your data is removed within 30 days. X tokens are destroyed immediately.
- Billing records: kept for six years after the last transaction, as UK tax law requires.
- Error logs: kept for up to 30 days.
10. Security
- X tokens and any AI provider key you supply are encrypted with AES-256-GCM before being stored.
- Every database table has row-level security enabled and denies access to the public API key outright. Application code is the only path in.
- Data is encrypted in transit with TLS.
- Sessions can be revoked centrally, so a lost or stolen cookie can be invalidated without waiting for it to expire.
No system is perfect. If we discover a breach affecting your personal data we will notify the ICO within 72 hours where required, and tell you directly if there is a high risk to you.
11. Your rights
You have the right to:
- get a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we process it;
- receive it in a portable, machine-readable format;
- withdraw any consent you gave.
Email hello@codehawks.co.uk and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you gave us the chance to fix it first.
12. Children
Hawkpost is not for anyone under 16, and X itself requires users to be at least 13. We do not knowingly collect data about children. If you think we have, contact us and we will delete it.
13. Changes to this policy
If we change how we use your data in a way that materially affects you, we will tell you by email or in the app before it takes effect. The date at the top of this page always shows the current version.
See also our terms of service.
Questions about this document? hello@codehawks.co.uk