Legal

Privacy Policy

Effective October 1, 2026

This policy explains what Amplify (“Amplify”, “we”, “us”) collects when you use amplify.cv, the Amplify web app at app.amplify.cv, the Amplify iOS and Android apps, and Amplify by text message (together, the “Service”), how we use it, and the choices you have.

  • We collect what you give us and what we need from X to do the job: drafting, scheduling, analytics.
  • Amplify publishes to your X account only when you approve it.
  • Your X access tokens are encrypted at rest.
  • We don’t sell your personal information and we don’t show ads.
  • You can disconnect X or delete your account at any time from the app.

1. Who we are

Amplify is an AI head of content for X (formerly Twitter). You chat with an assistant on the web, in our mobile apps or by text message; it drafts posts in your voice, schedules and publishes them to the X accounts you connect when you approve, reports how they perform, and can draft replies to accounts you choose to follow closely (“Reply Radar”).

Amplify is the controller of the personal information described in this policy. You can reach us at support@amplify.cv. Amplify is not affiliated with or endorsed by X Corp.

2. Information we collect

Account information

  • Your email address, and optionally your name and phone number.
  • If you set a password, a salted hash of it (never the password itself). One-time sign-in codes, password reset and email verification links are stored only as hashes and expire.
  • If you sign in with Google, Apple, GitHub, Microsoft, X or Facebook, that provider’s identifier for your account and the profile details it shares with us, such as your email address and name.
  • A growth goal, if you tell Amplify one.

Connected X accounts

  • When you connect an X account, X issues access and refresh tokens for the permissions you grant. We store them encrypted (AES-256-GCM) and use them only to act for you.
  • Your X user ID, handle, display name, profile picture URL, the permissions granted and the connection’s status.

Information we read from X

  • Your posts and their metrics (such as impressions, likes, reposts, replies, quotes and bookmarks, and owner-only metrics like profile and link clicks where X provides them), plus daily follower, following and post counts, so we can show analytics and learn what works for you.
  • For accounts you choose to track with Reply Radar: their public profile and the public posts they publish while you track them.
  • Posts you share as links in a chat, so Amplify can read and discuss them.

Public X profiles and posts are stored once in a shared cache keyed by X’s own IDs, so the same public post is not fetched twice for different users.

Content you create

  • Your chat messages with Amplify (web, app or text message) and Amplify’s replies.
  • Images you upload.
  • Drafts, threads, scheduled and published posts, their publishing history and any errors, Reply Radar drafts, the reply you chose to send, and notes you give about how to reply to specific people.

Voice and style memory

For each connected account, a style profile: tone, audience, topics, example posts, phrases to avoid, and short notes about your preferences that you give Amplify or that it records when you state a lasting preference. Amplify uses this so drafts sound like you across conversations.

Usage and billing

  • Usage records (for example, messages sent, X API reads and posts, and AI usage, with their cost) used to apply plan limits and to bill.
  • Your plan and subscription status, and the Stripe customer and subscription IDs. Card details are entered with and processed by Stripe; we don’t receive or store your full card number.

Devices and technical information

  • If you turn on notifications in a mobile app, a push token for your device so we can send them.
  • A session token stored on your device or in your browser to keep you signed in.
  • Technical logs our servers keep for security and troubleshooting, such as IP address, request path and time, and errors.

The waitlist

If you join the waitlist on amplify.cv, we store your email address, when you joined, where you came from (for example, the referring site or campaign), and the country Cloudflare infers from your connection.

X Circle (amplify.cv/x-circle)

X Circle needs no login and never gets access to any X account. When you enter a username, we look up that account’s recent public posts and profiles through a third-party X data provider and draw the result. To understand how the tool is used, we record page visits, lookups and button clicks (like Download or Post on X) together with the username involved, the country, device type (desktop, mobile or tablet), the referring site’s domain, a random ID kept in your browser tab’s session storage, and a visitor ID that is a keyed hash of your IP address and browser user agent with a key that changes every day. We do not store your IP address or user agent, and X Circle does not set cookies. Your IP address is also used briefly to rate limit lookups.

Cookies

We don’t use advertising or third-party tracking cookies. The web app keeps your session and preferences in your browser’s storage so it works.

3. How we use information

  • To provide the Service: chatting with you, drafting posts and replies in your voice, scheduling and publishing the posts you approve, showing analytics and insights, and running Reply Radar.
  • To sign you in, keep your account secure, and send sign-in codes and account emails.
  • To apply plan limits, process payments and keep billing records.
  • To send notifications you have turned on.
  • To answer support requests.
  • To prevent abuse, fraud and misuse, and to comply with the law.
  • To understand how the Service is used in aggregate and improve it.

We do not use your content to train AI models, and we do not sell your information or use it for advertising.

4. Posting to X

Amplify publishes or schedules a post on your X account only when you approve it: by pressing Post or Schedule on a draft, or by explicitly asking Amplify to post or schedule it. Drafts are saved for your review and are never published on their own. Reply Radar drafts replies for you to choose from; it never sends a reply automatically. Scheduled posts can be cancelled before they go out.

5. Service providers and sharing

We share information only as needed to run the Service, with these kinds of providers:

  • X (X Corp.), through the X API: to read your account, posts and metrics and the public accounts you track, to publish the posts you approve, and to revoke access when you disconnect.
  • AI model providers, through OpenRouter: to generate replies and drafts we send your messages and the context needed to answer (for example your voice notes, goal, recent drafts, analytics figures, the content of X posts you link, and images you attach). When Amplify searches the web for you, the search query is sent the same way. These providers process this content to produce a response.
  • Public X post viewers (fxtwitter and vxtwitter): when you share a link to an X post, we request that post by its ID from these public services to show it to you. No information about you is included in the request.
  • An X data provider (TwitterAPI.io): for X Circle lookups of public accounts by username.
  • Stripe: payment processing and subscription management. Stripe receives your email address and the payment details you enter.
  • Resend: to deliver sign-in codes and account emails to your email address.
  • Cloudflare: hosts amplify.cv, the waitlist and X Circle, and carries traffic to our API and web app as a network and security provider.
  • Hosting: our application servers, database and file storage run on infrastructure in the European Union.
  • Expo, Apple and Google: push notifications to the mobile apps are delivered through Expo’s push service and Apple Push Notification service or Firebase Cloud Messaging.
  • A messaging provider: if you use Amplify by iMessage or SMS, your phone number and messages pass through the provider that relays them.
  • Sign-in providers you choose to use (Google, Apple, GitHub, Microsoft, X or Facebook).

We may also disclose information if required by law or legal process, to protect the rights, safety or property of our users, the public or Amplify, or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

6. Where data is processed

Our servers and database are in the European Union. Some of the providers above, including X, OpenRouter and the model providers it routes to, Stripe, Resend and Cloudflare, process data in the United States and other countries. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission’s Standard Contractual Clauses.

7. How long we keep it

  • While your account is open, we keep your account information, conversations, drafts, posts, style memory and analytics so the Service keeps working and remembers you.
  • When you delete your account (Settings → Delete account), we immediately delete your account and the data linked to it from our database: profile, sign-in links, connected accounts and their tokens, conversations and messages, drafts and scheduled posts, publishing history, style memory, tracked accounts and Reply Radar drafts, analytics, usage records and subscription record, and we sign you out. Uploaded image files are kept in separate storage; email support@amplify.cv and we will delete them.
  • Backups: nightly database backups are kept for 14 days and server snapshots for up to 7 days, so deleted data is fully gone from backups within 14 days.
  • Public X data in the shared cache (public posts and profiles) is not tied to your account and is not removed when you delete it.
  • Payment records are kept by Stripe as required for tax and accounting.
  • Waitlist entries are kept until the waitlist is no longer needed or you ask us to remove yours.
  • X Circle: finished circles are cached for up to 3 days, the public interaction data behind them is deleted 45 days after the last refresh, cached profiles expire after 30 days, and usage events are deleted after 90 days.

8. Security

Traffic to the Service is encrypted in transit (HTTPS). X access tokens are encrypted at rest, passwords and one-time codes are stored only as hashes, and our database and storage are not reachable from the public internet. Access to production systems is limited to the people who run the Service. No system is perfectly secure; if you believe your account has been compromised, contact us right away.

9. Your choices and rights

  • Delete your account at any time in Settings → Delete account. If you have a paid subscription, cancel it on the Billing screen first; deleting your account does not cancel a Stripe subscription by itself.
  • Disconnect an X account at any time in the app. We ask X to revoke our access and erase the stored tokens; the history of posts you published stays in your account until you delete it. You can also revoke Amplify’s access from your X settings (connected apps) at any time; deleting your Amplify account does not by itself revoke it there.
  • Access, export or correct your information: you can edit your name in the app, and email support@amplify.cv for a copy of your data or other corrections. We respond within 30 days.
  • Notifications: turn them off in your device settings. Text messages: reply STOP to opt out.
  • Waitlist: email us to be removed.

Depending on where you live, you may have the right to access, correct, delete or port your personal information, to restrict or object to certain processing, and to withdraw consent at any time. To exercise any of these, email support@amplify.cv from the address on your account so we can verify the request. You will not be treated differently for exercising your rights.

11. California residents

In the past 12 months we have collected the categories of information described in section 2: identifiers (such as email, phone number and account IDs), commercial information (plan and billing records), internet activity (usage and technical logs), and the content you provide. We use and disclose them for the business purposes in sections 3 and 5. We do not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information to infer characteristics about you. You may request to know, delete or correct your personal information, and may use an authorized agent; we will verify requests before acting on them.

12. Children

The Service is not directed to children. You must be at least 13 years old to use it, or at least 16 if you live in the European Economic Area or the United Kingdom. If we learn that we have collected information from a child below these ages, we will delete it.

13. Changes to this policy

We may update this policy as the Service changes. We will post the new version here with a new effective date, and for material changes we will notify you by email or in the app before they take effect.

14. Contact

Questions or requests about privacy: support@amplify.cv.