Privacy Policy
Last Updated: January 29, 2026
This Privacy Policy describes how Turbox ("we", "us", or "our") collects, uses, and protects your personal information when you use our Service.
1. Information We Collect
1.1 Information You Provide
Account Information
- Email address (via Google OAuth)
- Name and profile information from your Google account
- X/Twitter username and account information (via OAuth)
Service Configuration
- Search queries you create
- Reply templates and messages
- Query settings and preferences
- Account settings and preferences
Payment Information
- Billing information processed through Stripe (we do not store credit card numbers)
- Subscription tier and payment history
- Add-on purchases and usage records
1.2 Information Automatically Collected
Usage Data
- Number of replies sent
- Search queries executed
- Tweets found and replied to
- Login timestamps and session information
- Feature usage statistics
Technical Data
- IP address
- Browser type and version
- Device information
- Operating system
- Referring/exit pages
- Date and time stamps
Cookies and Similar Technologies
- Session cookies for authentication
- Preference cookies for settings
- Analytics cookies for service improvement
1.3 Information from Third Parties
X/Twitter API
- Public tweet data matching your search queries
- Your X/Twitter profile information
- Tweet IDs and metadata for duplicate prevention
- Reply success/failure status
Google OAuth
- Email address
- Name and profile picture
- Account verification status
Stripe
- Payment status and transaction history
- Subscription status and billing cycles
2. How We Use Your Information
2.1 To Provide the Service
- Authenticate your account
- Execute your search queries on X/Twitter
- Post replies to X/Twitter on your behalf
- Track usage and enforce subscription limits
- Prevent duplicate replies
- Display analytics and statistics
- Provide customer support
2.2 For Billing and Subscriptions
- Process payments through Stripe
- Manage your subscription and billing cycles
- Send invoices and payment receipts
- Handle upgrades, downgrades, and cancellations
- Process add-on purchases
2.3 For Communications
- Send service notifications (usage warnings, limit reached)
- Provide customer support responses
- Send important updates about the Service
- Communicate Terms or Privacy Policy changes
- Send optional marketing emails (with your consent)
2.4 For Improvement and Analytics
- Analyze usage patterns to improve features
- Monitor Service performance and uptime
- Debug errors and technical issues
- Develop new features and functionality
- Understand user needs and preferences
2.5 For Legal and Security
- Prevent fraud and abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Protect our rights and property
- Respond to legal requests and prevent harm
3. How We Share Your Information
We do NOT sell your personal information. We only share information in the following circumstances:
3.1 Third-Party Service Providers
X/Twitter (API)
- We send your search queries and reply content to X/Twitter's API
- X/Twitter receives your account credentials via OAuth
- Subject to X/Twitter's Privacy Policy
Stripe (Payment Processing)
- Payment and billing information for subscription management
- Subject to Stripe's Privacy Policy
Firebase/Firestore (Data Storage)
- Account information, queries, usage data, and settings
- Hosted on Google Cloud infrastructure
- Subject to Google's Privacy Policy
Google OAuth (Authentication)
- Email and basic profile information
- Subject to Google's Privacy Policy
3.2 Legal Requirements
We may disclose information if required by law, subpoena, court order, or government request, or if necessary to:
- Comply with legal obligations
- Protect our rights and property
- Prevent fraud or security issues
- Protect user safety
3.3 Business Transfers
If we undergo a merger, acquisition, bankruptcy, or asset sale, your information may be transferred to the acquiring entity. You will be notified of any such change via email or Service notification.
3.4 With Your Consent
We may share information with third parties when you explicitly consent, such as when you authorize integrations or connect additional services.
4. Data Security
4.1 Security Measures
We implement reasonable security measures to protect your information:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Authentication: Secure OAuth 2.0 authentication flows
- Access Controls: Limited employee access on a need-to-know basis
- Monitoring: Automated monitoring for suspicious activity
- Infrastructure: Secure hosting on Firebase/Google Cloud Platform
4.2 Limitations
No security system is impenetrable. We cannot guarantee absolute security of your data. You are responsible for:
- Maintaining the security of your account credentials
- Using strong passwords
- Logging out from shared devices
- Notifying us of suspected unauthorized access
5. Data Retention
5.1 Active Accounts
We retain your information for as long as your account is active or as needed to provide the Service.
5.2 After Deletion
When you delete your account:
- Most personal information is deleted within 30 days
- Some data may be retained for legal, tax, or fraud prevention purposes
- Aggregated, anonymized data may be retained indefinitely
5.3 Backup Systems
Data may persist in backup systems for up to 90 days after deletion.
6. Your Rights and Choices
6.1 Access and Update
You can access and update your information through:
- Account settings dashboard
- Email requests to support@turbox.com
6.2 Delete Your Account
You can delete your account at any time through your account settings. This will:
- Cancel your subscription
- Delete your queries and settings
- Remove your account information within 30 days
6.3 Revoke API Access
You can revoke Turbox's access to your accounts:
- X/Twitter: Visit twitter.com/settings/connected_apps
- Google: Visit myaccount.google.com/permissions
6.4 Marketing Communications
You can opt out of marketing emails:
- Click "Unsubscribe" in any marketing email
- Update preferences in account settings
- You will still receive essential service notifications
6.5 Cookies
You can control cookies through your browser settings:
- Block all cookies (may impact functionality)
- Delete existing cookies
- Receive notifications before cookies are placed
6.6 Data Portability
You can request a copy of your data in a portable format by emailing support@turbox.com.
7. Regional Privacy Rights
7.1 European Union (GDPR)
If you are in the EU, you have additional rights:
- Right to Access: Obtain a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact support@turbox.com.
Legal Basis for Processing:
- Performance of contract (providing the Service)
- Legitimate interests (improving Service, fraud prevention)
- Consent (marketing communications)
- Legal obligations (tax, legal requirements)
7.2 California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: What personal information we collect and how it's used
- Access: Request a copy of your personal information
- Delete: Request deletion of your personal information
- Opt-Out: Opt out of the "sale" of personal information (we don't sell data)
- Non-Discrimination: Not be discriminated against for exercising your rights
To submit a request, email support@turbox.com with "California Privacy Rights" in the subject line.
Response Timeline: We will respond to verifiable requests within 45 days.
7.3 Other Jurisdictions
We respect privacy rights in all jurisdictions. If you have questions about your regional rights, contact us at support@turbox.com.
8. Children's Privacy
The Service is NOT intended for individuals under 18 years of age. We do not knowingly collect information from children. If we learn we have collected information from a child under 18, we will delete it immediately. Contact us at support@turbox.com if you believe we have collected information from a child.
9. International Data Transfers
Our Service uses third-party providers that may process data outside your country of residence:
- Firebase/Firestore: Google Cloud data centers worldwide
- Stripe: Global payment processing infrastructure
These providers implement appropriate safeguards for international data transfers, including:
- Standard Contractual Clauses (EU)
- Privacy Shield certifications where applicable
- Equivalent data protection measures
10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
11. Analytics and Tracking
11.1 Analytics Tools
We may use analytics services to understand Service usage:
- Usage patterns and feature adoption
- Error tracking and performance monitoring
- User journey and behavior analysis
11.2 Do Not Track
Some browsers have "Do Not Track" signals. We currently do not respond to DNT signals but honor opt-out preferences where applicable.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be communicated via:
- Email notification to registered users
- Notice in the Service dashboard
- Updated "Last Updated" date at the top
Material changes will be announced at least 30 days in advance. Continued use after changes constitutes acceptance of the updated Privacy Policy.
13. Contact Us
13.1 Privacy Questions
For questions about this Privacy Policy or our privacy practices:
Email: support@turbox.com
Website: https://turbox.com
13.2 Data Protection Officer
For GDPR-related inquiries, contact our Data Protection Officer at:
Email: support@turbox.com
13.3 Response Time
We aim to respond to all privacy inquiries within 7 business days.
---
Summary (Not Legally Binding)
What We Collect:
- Email, name (from Google)
- X/Twitter username (via OAuth)
- Search queries and replies you create
- Usage statistics and analytics
How We Use It:
- To run your searches and post replies
- To manage your subscription and billing
- To improve the Service
- To communicate important updates
How We Share It:
- X/Twitter (to post tweets)
- Stripe (for payments)
- Firebase/Google (for storage)
- We don't sell your data
Your Rights:
- Access, update, or delete your data
- Revoke API access anytime
- Opt out of marketing emails
- Request data export
Security:
- Encrypted data in transit and at rest
- Secure OAuth authentication
- Industry-standard security practices
For detailed information, please read the full Privacy Policy above.
Questions? Email support@turbox.com