Privacy Policy
Effective date: October 1, 2026
This policy explains what personal data RentMyThread collects, why, who it’s shared with, how long we keep it and the choices you have. It applies to rentmythread.com and the service behind it. Our Terms of Service explain how the service itself works.
The short version
- We get your basic X profile when you sign in. Creators also let us read their tweets and post and delete the sponsored replies they approved.
- We use your data only to run RentMyThread: spotting tweets that take off, posting and removing replies, counting views, billing, payouts, safety and support.
- Card and bank details are handled by Stripe. We never see or store them.
- No analytics, ad trackers or third-party cookies on our site: just a sign-in cookie.
- We don’t sell your personal information or share it for advertising.
- Email support@rentmythread.com to see, correct or delete your data.
This summary is here to help you read the full text below. The full text is what applies.
1.Who we are
RentMyThread (rentmythread.com) is operated by Joseph Dafforn, an individual based in Massachusetts, USA (“RentMyThread”, “we”, “us”). We decide how your personal data is used for the service, which makes us the “controller” under EU and UK law. You can reach us at support@rentmythread.com.
2.What we collect and why
From X, when you sign in
- Your X user ID, @handle, display name, profile image link and follower count. We refresh these each time you sign in.
- The access and refresh tokens X gives us, with their permissions (scopes) and expiry. We encrypt the tokens before storing them (AES-256-GCM).
We use these to sign you in, show who you are, and keep your account linked to X. Sponsors give read-only access, and we never post for sponsors. Creators also give permission to post and to stay connected, which we use only as described below. We don’t receive your X password, email address or direct messages.
If you’re a creator
- Your recent original tweets (not replies or reposts): their ID, text (the latest version, if you edit one) and posting time, plus their public metrics (impressions, likes, reposts and replies), which we record repeatedly as the tweet grows. We check for new tweets only while you have an approved sponsor with an active campaign, or a sponsored reply that’s up. We use these to tell when a tweet is taking off compared with your usual reach, and to run brand-safety checks.
- The result of the brand-safety check on each tweet we look at.
- The sponsored replies we post for you: their text, ID and view counts for each block.
- Your settings (trigger level, minimum CPM, daily limit, approval mode, blocked categories, quiet hours and timezone) and the sponsors you approved or declined.
- An email address, if you give one. If you give it before you set up payouts, we pass it to Stripe when we create your payout account. We may use it to contact you about your account or payouts.
- Your Stripe Connect account ID, whether it can receive payouts, and your earnings and payout records. Stripe collects your identity documents, tax ID and bank details directly; we don’t receive them.
If you’re a sponsor
- Your company name (we fill it in from your X display name, and you can change it), website, and billing email if you give one. If you give a billing email before your first top-up, we pass it to Stripe as your customer email.
- Your campaigns: name, category, reply copy (including any links in it), brand X handle, bids, budgets, targeting (including any creator handles you list), dates and topics to avoid.
- Your Stripe customer ID. You pay through Stripe Checkout; your card details go to Stripe, not to us.
For everyone
- Transaction records: a ledger of top-ups, holds, charges, earnings, fees, payouts, refunds and disputes, with the Stripe reference IDs. We need these to keep balances right, pay creators and meet tax and accounting rules.
- Audit logs: records of key actions, such as sign-up (with your role and handle), campaign and approval changes, balance reversals and admin actions like suspending an account. We use them for security, support and resolving disputes.
- Messages you send us, such as support emails, to answer you.
- Technical data: the cookies described below, the request logs our hosting providers keep (such as IP address, browser type, the page requested and the time), and our application logs on Vercel and Railway, which can include your X handle, account ID and payment reference IDs. These are used to run, debug and secure the service.
We don’t use analytics tools, advertising pixels or other trackers, and we don’t build advertising profiles. Brand-safety checks run on our own servers with a keyword filter; we don’t send your tweets to any AI provider. If that changes, we’ll update this policy first.
3.Legal bases (EU and UK users)
If you’re in the EU, the UK or another place with similar laws, we rely on these legal bases:
- Contract: to run your account and do what you asked for, such as posting the replies you approved, charging sponsors, and paying creators.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, run brand-safety checks, keep records, enforce our Terms and improve the service. We weigh these against your rights.
- Legal obligation: to keep tax and accounting records and respond to lawful requests.
4.What other people can see
- Everyone on X can see the sponsored replies posted from a creator’s account. They’re public posts on X.
- Sponsors can browse a directory of every active creator account, showing its handle, follower count, minimum CPM, approval mode (auto-post or confirm each reply), number of completed sponsored replies and blocked categories. Sponsors also see whether a creator approved or declined their campaign, and for their own replies, the tweet, the reply, its views and the charges.
- Creators can see a sponsor’s company name, X handle and the campaign copy and details they’re asked to approve.
- We (the operator, as admin) can see account data to review accounts, run the service and help you.
5.Service providers and sharing
We use these service providers to run RentMyThread. They process data for us to provide their service:
- Vercel hosts the website and keeps request logs.
- Railway runs our background worker, which watches tweets, posts and deletes replies, counts views and sends payouts.
- Neon hosts our Postgres database, which stores the data described above.
- Stripe processes sponsor payments (Checkout), creator payouts (Connect) and identity verification for payouts. When you provide personal data in connection with payments or payouts, Stripe receives that personal data and processes it in accordance with Stripe’s Privacy Policy.
- X Corp handles sign-in, and we read tweets and metrics and post and delete replies through the X API. X processes that data under X’s Privacy Policy.
- Cloudflare provides DNS for rentmythread.com and forwards emails sent to support@rentmythread.com to our mailbox.
- Our email provider hosts that mailbox, so it stores the emails you send us, including privacy requests.
We also share data when the law requires it, to protect the rights, safety or property of our users, us or others, with a buyer or successor if RentMyThread is transferred (who must keep honoring this policy), or when you ask us to.
We don’t sell your personal information, and we don’t “share” it for cross-context behavioral advertising as California law defines those terms.
7.How long we keep data
- Account, profile, settings, campaigns, tweets and metrics: while your account is open.
- X tokens: while your account is open. If you disconnect RentMyThread in X’s settings, they stop working at once, and we delete them when your account is closed.
- When you ask us to close your account, we delete or anonymize your data within 30 days, except what we must keep: transaction and payout records, and the audit logs tied to them, are kept for as long as tax, accounting and legal rules require, generally up to 7 years.
- Request and application logs are kept by our hosting providers for their usual, short retention periods.
8.Security
We encrypt X tokens at rest (AES-256-GCM), use HTTPS, keep sign-in cookies signed and out of reach of page scripts, check your role and ownership on every action, and limit admin access to the operator’s X account. Payment and bank details stay with Stripe. No system is perfectly secure, but we work to protect your data, and we’ll tell you about a breach that affects it as the law requires.
9.Your rights and choices
Wherever you live, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct it (you can also edit most of it in your settings, and your X profile details update when you sign in);
- delete it: email us and we’ll close your account.
You can also disconnect RentMyThread from your X account at any time in X’s connected apps settings. We then can’t post, delete or read anything for you.
If you’re in the EU or UK, you can also object to or ask us to restrict some processing, ask for your data in a portable format, and complain to your local data protection authority.
If you’re in California or another US state with a privacy law, you have the right to know what we collect, and to delete and correct it. We don’t sell or share personal information or use it for targeted advertising, so there’s nothing to opt out of. We won’t treat you differently for using your rights.
To make a request, email support@rentmythread.com from the email on your account or tell us your X handle. We may need to confirm the request comes from you, for example through your X account. An authorized agent can ask for you with proof of authority. We’ll answer within 30 days, or sooner if the law requires.
10.Children
RentMyThread is only for people 18 and older. We don’t knowingly collect personal data from anyone under 18. If you think a minor has signed up, email support@rentmythread.com and we’ll delete their data.
11.International transfers
We’re based in the United States, and our database and servers run mainly in the United States. If you use RentMyThread from elsewhere, your data is transferred to and processed in the US, whose laws may differ from yours. Where the law requires it, we rely on safeguards our service providers offer for these transfers, such as Standard Contractual Clauses.
12.Changes to this policy
We’ll post any change here with a new effective date. For material changes, we’ll give reasonable notice first, for example by email or a notice in the app.
13.Contact
RentMyThread is operated by Joseph Dafforn, Massachusetts, USA. For any privacy question or request, email support@rentmythread.com.