Privacy Policy
Last updated: March 19, 2026
1. Introduction
XWipe ("we", "our", "us") is a product of BestDid Technology Ltd. This Privacy Policy explains how we collect, use, store, and protect your information when you use our bulk tweet deletion service at getxwipe.com.
2. Information We Collect
When you use XWipe, we collect the following information:
- X Account Data: Your X (Twitter) username, profile information, and OAuth access tokens necessary to perform deletions on your behalf.
- Email Address: Your email address associated with your X account, used for account communication.
- Usage Data: Deletion counts, subscription status, and basic usage analytics.
- Payment Information: Payment processing is handled entirely by Paddle. We do not store your credit card numbers or bank details on our servers.
3. How We Use Your Information
- To authenticate you via X OAuth and perform tweet deletions
- To manage your subscription and deletion quotas
- To process payments through Paddle
- To send important service-related communications
- To improve and maintain the service
4. Data Storage & Security
We take the security of your data seriously:
- OAuth tokens are encrypted at rest using AES-256-GCM encryption before being stored in our PostgreSQL database.
- All data is transmitted over HTTPS/TLS encrypted connections.
- Database access is restricted and follows the principle of least privilege.
5. Cookies
We use a session cookie provided by NextAuth.js to keep you signed in. This is a strictly necessary cookie and does not track you across other websites. We do not use advertising or analytics cookies.
6. Third-Party Services
XWipe integrates with the following services:
- X (Twitter) API: Used to access and delete your tweets. Subject to X's Privacy Policy.
- Paddle: Used for payment processing. Subject to Paddle's Privacy Policy.
7. Data Retention & Deletion
We retain your data only for as long as your account is active. You can request deletion of your account and all associated data at any time by contacting us. Upon account deletion:
- Your OAuth tokens are immediately revoked and deleted
- Your account data is permanently removed from our database
- Paddle may retain transaction records as required by financial regulations
8. Your Rights
You have the right to access, correct, or delete your personal data. You can revoke XWipe's access to your X account at any time through your X account settings. To exercise any of these rights, contact us at the email below.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the updated policy on this page with a revised date.
10. Contact
If you have questions about this Privacy Policy, contact us at info@getxwipe.com.