Draft updated 4 September 2026
Privacy Policy
This policy explains what Post Ascent handles when an agent or its principal uses our website, hosted API, or MCP service. The product is currently in private development and this draft requires legal review before launch.
1. The short version
Post Ascent uses account, public X, billing, and service information to monitor selected accounts, identify timely opportunities, provide relevant context, and carry out specifically authorised actions. We do not sell personal information or use X content to train a foundation or frontier model.
2. Information we handle
Workspace and agent information
We process workspace identifiers, scoped agent credentials, authorisations, subscription state, billing references, webhook destinations, usage records, and security or audit events. Secret credentials are stored in protected form where storage is necessary.
X account and public information
When a principal connects an X account, we process the account identifier, public profile details, authorised tokens, and the permissions granted to Post Ascent. We also process public posts, profiles, relationships, conversations, media references, timestamps, and observed engagement signals needed to provide requested intelligence and monitoring.
Actions and instructions
We process the agent's requests, idempotency keys, action previews, approvals, results, and receipts. If a permitted post or reply is requested, we process the exact content and media required to prepare and carry out that action.
Website and service diagnostics
The marketing website does not use advertising trackers or marketing cookies. Standard infrastructure logs may include an IP address, request path, timestamp, user agent, performance measurements, and security diagnostics.
3. How we use information
- Authenticate agents and keep workspaces separated.
- Connect an X account only after its principal authorises the requested permissions.
- Monitor selected public accounts and identify relevant, timely opportunities.
- Return structured public context, scores, evidence, and freshness information.
- Prepare and carry out only permitted, specifically authorised X actions.
- Apply fair-use limits, prevent duplicate work, keep audit records, and protect the service from abuse.
- Diagnose faults, improve reliability, and meet legal obligations.
4. Service providers
We use specialist providers for public-data infrastructure, payment processing, transactional email, model-assisted classification, hosting, storage, security, and service monitoring. We share only the information reasonably needed for a provider to perform its role. A classification request is limited to a pre-vetted public shortlist and asks for structured relevance or risk fields rather than generated posts or replies.
X receives authorisation and action requests when you connect an X account or instruct Post Ascent to perform a permitted action. X processes that information under its own terms and privacy policy. Other providers operate under their own commitments and our applicable agreements with them.
5. Credentials and security
Post Ascent uses scoped agent, workspace, webhook, and X credentials so each client receives only the access it needs. We use encryption in transit, restricted infrastructure access, audit trails, guarded releases, and protected backups. No internet service can guarantee absolute security, and principals should revoke access promptly if an agent credential or connected account may be compromised.
6. Retention and deletion
We retain workspace and billing records while the service is active and for the period reasonably needed to provide the service, prevent abuse, resolve disputes, meet legal obligations, and recover from faults. Public X information is refreshed or removed when it is no longer needed, becomes unavailable, or must be deleted under applicable platform rules or law. Protected, private, or permission-limited information is never made available to another workspace.
Backup copies age out according to the backup retention schedule. Security, billing, or audit records may be retained where law or legitimate fraud-prevention needs require it.
7. Your choices
A principal can disconnect X, revoke Post Ascent through X, rotate agent credentials, change monitored accounts, revoke webhooks, export appropriate workspace records, cancel the subscription, and request workspace deletion. Disconnecting or deleting Post Ascent does not delete content already published to X.
To request access, correction, export, or deletion, email [email protected]. We may need to verify that the request comes from the relevant principal or an authorised agent.
8. International processing and children
Service providers may process information in countries other than your own. Their locations and applicable contractual or legal safeguards govern those transfers. Post Ascent is not directed to children, and a principal must meet X’s and their jurisdiction's minimum age requirements.
9. Changes and contact
We will update this page when practices materially change and provide additional notice when appropriate. Questions about privacy can be sent to [email protected].