Privacy policy

Last updated: Sep 24, 2026

1. Introduction

Firecrest helps you write posts for X that fit your niche. You tell us what you are promoting and point us at a few pages of your own. We read those pages, work out the niche you write in, look at recent high-performing posts in that niche, and generate draft posts for you to edit. You decide what happens to each draft: copy it out and post it yourself, or have us publish it to your connected X account, straight away or at a time you schedule.

This policy explains what we collect, how we use it, who we share it with, and how long we keep it. By using the Service you consent to the processing described here.

2. Who is responsible for your data

Squared Sums Pte Ltd ("we", "us", "our"), 160 Robinson Road, #14-04 SBF Centre, Singapore 068914, operates Firecrest and is the data controller for personal data processed through the Service. You can reach us at [email protected]. Messages to that address also reach our data protection officer.

3. Information we collect

3.1 Information you provide

  • Account details. Your email address, and a display name if you set one. We sign you in with a one-time code sent to your email, so we hold no password.
  • Images you upload. A profile picture, if you set one, which only you see. Images you attach to posts, stored in our object storage with their file name, type, and size. When you publish a post, its images go to X and become public.
  • Your onboarding answers. What you are promoting and what kind of thing it is, its name, up to three web addresses, who you want to reach, the tone you want, the languages you write in, and anything you want us to avoid. Section 3.4 covers what we take from the X account you connect.
  • Your posts. Every draft we generate for you and every post you write yourself, with your edits and whether you saved, scheduled, published, or discarded each one. Discarding a draft hides it so you can restore it later. We erase drafts when we erase your account.
  • Communications with our support team. Contact form messages, with the name and email address you give, and the bug reports and feature requests you file from your account.
  • Billing details. Stripe processes your payment. We receive purchase confirmation, your subscription status, and the billing name and email Stripe reports back. We do not receive or store full payment card numbers.

3.2 Information we derive from what you provide

From your onboarding answers, the pages you point us at, and the handle, display name, and bio of the X account you connect, our AI provider drafts a niche label, a set of search keywords, tone tags, a description of what you are promoting, and who you want to reach. You review and edit these before we save them or generate anything from them. Each brand profile you create holds its own set.

3.3 Automatically collected information

  • Usage analytics. Umami counts page views, including navigation inside the app, and records a set of product events. See section 6.
  • Your IP address, when you load a page that shows prices. We send it to IPInfo to guess your country and show prices in your currency. We keep IPInfo's answer in server memory for up to a day and do not write it to our database. See section 8.
  • Sign-in session details. When you sign in we store your IP address and browser user agent with that session, so we can investigate account abuse. They stay with the session record until you sign out or we purge your account.
  • Sign-in security data. We count recent one-time-code requests per email address to stop anyone flooding an inbox with codes.
  • A time zone, if you set one so scheduled posts go out at the hour you meant. We store the zone you choose, not your location.

3.4 Information we receive from X

When you connect an X account, X sends us your handle, display name, profile picture address, bio, and the website link on your profile. We refresh these once a day while the account stays connected. We send your handle, display name, and bio to our AI provider with your onboarding answers to draft the fields in section 3.2. We prefill the website link as one of the pages you ask us to analyse, and you can remove it.

Connecting also stores an access credential, encrypted, so we can act on the permissions you granted. We request every permission Firecrest uses when you connect: read your profile, read and publish posts, upload media, and keep that access without asking you to approve it again. We ask for all of them at once because X cannot add a permission later without making every connected account reconnect. You can revoke them at any time by disconnecting the account here or from your X settings. Disconnecting deletes the credential and the profile details we copied from X.

We publish nothing to a disconnected account: a queued post that comes due fails instead. Disconnecting leaves your queue in place, so if you reconnect the same account, anything still scheduled publishes at its scheduled time.

4. Pages you ask us to analyse

When you give us a web address during onboarding, our servers fetch that page and extract its readable text. The site sees the request come from us, not from you. We send the extracted text to our AI provider and hold it only while you onboard: we stop using it after an hour and delete it when you finish onboarding, or within a day after that hour if you do not. Give us only addresses you are happy to have read this way, such as your own site or landing page. We fetch only the addresses you list, and we do not re-fetch them on a schedule.

5. How we use your information

  • To provide and maintain the Service, including signing you in.
  • To work out the niche and voice of each brand profile you set up, and to generate draft posts from them.
  • To publish a post to your connected X account when you tell us to, either straight away or at a time you schedule, and to keep the queue of posts you have scheduled.
  • To find recent high-performing public posts on X that match your keywords, as examples for the drafts.
  • To store your drafts so you can come back to them.
  • To process payments, manage subscriptions, and prevent fraudulent transactions.
  • To count your generations and posts against your plan's limits.
  • To communicate with you about your account, subscription, or support requests, including the sign-in codes we email you.
  • To send you product news and offers, only if you ticked the optional box when you bought your plan. You receive the emails in the item above either way.
  • To improve the Service based on usage patterns and feedback.
  • To comply with legal obligations and enforce our terms.
  • To protect against unauthorized access and ensure platform security.

We publish to X only the posts you select, to the account you connected, at the time you chose. We never publish a post without an instruction from you. We do not sell your personal data, and we use your drafts and profiles only to generate posts for you.

6. Analytics

We use Umami to understand how people use the product. Umami sets no cookies, stores no identifier on your device, and anonymises IP addresses, so this site shows no cookie consent banner for analytics.

Umami records page views automatically. Beyond those we record named events: signing in, starting checkout, completing a purchase, opening the billing portal, finishing onboarding and each of its steps, generating drafts, and actions on drafts and posts such as saving, discarding, scheduling, and publishing. The data attached to these events is limited to yes/no flags, small counts, fixed option values, and the identifier of the Stripe price involved, which identifies the plan being bought and not the person buying it.

Analytics events never carry your email address, your account identifier, your Stripe customer or session identifiers, the content of your drafts, or anything you typed in free text during onboarding.

7. Cookies

  • Essential cookies. Required for basic platform functionality and security: the session cookies that keep you signed in.
  • Preference cookies. Store your language preference. Your light/dark theme and the account you last selected are kept in your browser's local storage.

We use no advertising or cross-site tracking cookies. You can control cookie preferences through your browser settings.

8. Third parties we share data with

  • Anthropic (AI provider): receives your onboarding answers, the text extracted from the pages you listed, the handle, display name, and bio of the X account you connect, and the example posts, to produce your niche, keywords, tone tags, description, and drafts.
  • GetXAPI (X data provider): receives your niche keywords and language to search X for recent high-performing public posts. It receives neither your identity nor your drafts.
  • X Corp: receives your connection request when you connect your X account, and returns the details in section 3.4. When you publish or schedule a post, X also receives that post's text and any image you attached, published publicly under your X account. X's own terms and privacy policy govern what happens to it after that.
  • Stripe (payments): payment processing, subscriptions, and the billing portal.
  • Resend (email): sends our emails, so it receives your email address and the message.
  • S3-compatible object storage: stores your profile picture and the images you attach to posts.
  • IPInfo: receives your IP address when you load a page that shows prices, and returns your country. See section 3.3.
  • Umami (analytics): as described in section 6.
  • Discord (internal alerts): operational notifications to our team. A sign-up or new subscription alert carries a masked email address (its first letter and domain); a failed scheduled post alert carries your X handle and the failure reason.

Each provider processes data under its own privacy policy and our data processing arrangements with them. The websites you ask us to analyse are not our providers; section 4 covers our requests to them.

9. International data transfers

Your data is processed outside Singapore, mainly in the United States, where Anthropic and most of the other providers in section 8 are based. Where data is transferred internationally, we rely on standard contractual safeguards and provider-level data protection commitments.

10. Data storage and security

  • We encrypt all traffic to and from the Service in transit using TLS.
  • Card details never reach our servers; Stripe processes payments on PCI-compliant infrastructure.
  • We encrypt your X access credentials before storing them.
  • We hold no passwords. Sign-in uses one-time codes that expire.
  • We rate-limit, per user, the requests that cost money or send email.
  • We check each page we fetch for you so the request cannot reach our internal network.

No method of storage or transmission is perfectly secure. If we discover a breach affecting your personal data, we will tell you and the relevant authority as the law requires.

11. How long we keep things

  • Your account and everything in it: kept while your account exists. See section 12.
  • Drafts, including discarded ones: kept while your account exists. Discarding hides a draft so you can restore it. Ask us if you want a specific draft erased sooner.
  • Posts you have scheduled: kept while your account exists. A post whose X account is disconnected stays queued and fails when it comes due, unless you reconnect the account first. Deleting your account cancels your plan; once no plan is active, a queued post fails instead of publishing, and the purge removes anything still queued.
  • Text extracted from your pages: used for an hour, then deleted when you finish onboarding or within the following day, whichever comes first.
  • Cached example posts: we cache the public posts we pull from X for up to 48 hours. We cache them against a set of keywords, not against you, and share them with everyone writing in the same niche.
  • Sign-in throttling counters: deleted once they expire.
  • Payment records: kept after your account is deleted, for accounting and tax purposes. See section 12.

12. Deleting your account

You can delete your account from your settings. We mark your account for deletion, and a job that runs once a day purges it permanently 30 days later. Deleting your account cancels your plan immediately. We do not refund the unused period, except as section 5.4 of our terms allows. If you cancel the deletion within those 30 days, you keep your data, but you need to subscribe again to use the Service.

When the purge runs, we delete your account and with it:

  • Your sign-in sessions and credentials.
  • Every brand profile you created, with its keywords, tone tags, description, and the details of the X account attached to it.
  • Any X access credentials we held for you, and any posts still queued for publication.
  • Every draft and post, and your generation history.
  • Your profile picture and every image you attached to a post, removed from object storage.
  • Any bug reports and feature requests you filed.
  • Your customer record at Stripe, deleted through Stripe's API.

These records survive the purge:

  • Payment and subscription records, with the billing name and email address attached to each purchase. We detach them from your account and keep them as our record of transactions.
  • Messages you sent through our contact form, and the raw records of payment events Stripe sent us.

To have these erased as well, email us at [email protected]. We erase them by hand unless the law requires us to keep them.

13. Your rights

Subject to applicable data protection laws, you have the right to:

  • Access your personal data and request copies.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data (right to be forgotten).
  • Object to certain data processing activities.
  • Receive your data in a portable format.
  • Withdraw consent for optional processing.
  • Lodge a complaint with the Singapore Personal Data Protection Commission (PDPC) or another competent supervisory authority.

Deleting your account is self-service, as described in section 12. We handle every other request by hand: email [email protected] and we will respond within the time the law allows. We offer no self-service export, so a person on our team fulfils a request for a copy of your data.

14. Children

Firecrest is not directed to users under 16 years of age, and we do not knowingly collect personal data from children under 16. If we learn that we have collected such data, we will delete it.

15. Changes to this policy

We may update this policy from time to time. We will announce material changes through the Service or by email, and change the "Last updated" date above.

16. Contact

For questions about this policy or to exercise your rights, contact us at [email protected], or by post at Squared Sums Pte Ltd, 160 Robinson Road, #14-04 SBF Centre, Singapore 068914.