whenspots Back home
Last updated October 2, 2026

Privacy Policy

Whenspots helps you write, schedule, publish and analyze posts on X. This policy explains what we collect when you use Whenspots, why we collect it, and the choices you have. We only collect what the product needs to work, and we don't sell your data.

What we collect

  • Account details. When you sign in with X or Google, we receive your name, username, email address and profile picture from that provider.
  • X connection. If you connect an X account, we store the access tokens X issues to us so we can publish on your behalf and read metrics for the posts you publish through Whenspots. We also store the account's public profile (handle, display name, avatar, follower count).
  • Your workspace. The posts, threads, drafts, schedules, ideas, templates, settings and notifications you create in Whenspots.
  • Media. Images, videos and GIFs you upload, along with the alt text you add.
  • Post metrics. Impressions, likes, replies, reposts and bookmarks for posts you published through Whenspots, read from the X API.

We don't use advertising trackers. We count page views with Vercel Web Analytics, which doesn't use cookies (see below).

How we use it

  • To sign you in and keep your workspace in sync across devices.
  • To publish posts and threads to X at the times you schedule, and only those.
  • To show how your posts perform and suggest better times to post.
  • To generate drafts when you use the AI studio.
  • To keep the service secure and fix problems.

Services we rely on

  • Supabase hosts our database, sign-in and file storage. Your workspace and uploads are stored there, and each account can only access its own rows.
  • X receives the posts and media you publish, and we read your profile and post metrics through its API. X's own privacy policy applies to anything you post there.
  • Google handles sign-in if you choose "Continue with Google". When you use the AI studio, your brief and settings are sent to Google Gemini. If you turn on "Write like me", a few of your published posts are sent as voice samples too.
  • Vercel hosts Whenspots. Its Web Analytics counts page views and records the page path, referrer, country, browser and device type, without cookies and without identifying you across sites. Query strings are stripped before anything is sent.

We share data with these providers only so they can run Whenspots for you, never so they can market to you.

Cookies and local storage

We use essential cookies to keep you signed in and to complete the X connection flow securely. Whenspots also keeps a copy of your workspace in your browser's local storage so the app loads quickly. We don't use cookies for advertising.

Security

X access tokens are stored server-side and never sent to your browser. Data travels over HTTPS, and database access is restricted per account. No system is perfectly secure, but we work to protect your information and limit who can access it.

Keeping and deleting your data

We keep your data for as long as your account is active. You can export your workspace from Settings at any time. Disconnecting an X account in Settings revokes its token and removes it from our database. To delete your account and all associated data, contact the Whenspots team, and we'll delete it within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to how it's used. To exercise any of these rights, contact the Whenspots team.

Children

Whenspots isn't meant for anyone under 13, or the minimum age for using X where you live, and we don't knowingly collect their data.

Changes to this policy

If we make meaningful changes, we'll update the date at the top of this page and let you know in the app.

Contact

Questions about this policy? contact the Whenspots team.