Xcue Privacy Policy

Last Updated: February 7, 2026
Developed by Fabricio Garcia Roque II (@FaboRoque)

Xcue is an AI-powered co-pilot designed to help users engage authentically on X. We prioritize technical transparency and a "Local-First" data philosophy.

The Xcue Promise: We do not store your X credentials, we do not clone your identity, we do not sell your personal data, and we never use your private interactions to train AI models.

1. Secure Authentication & Account Data

  • X Auth 2.0: We use the native X (Twitter) Auth 2.0 protocol for secure login. We do not see or store your X password. We only maintain the necessary OAuth tokens via Supabase to verify your access and manage your account features.
  • Unified Experience: As of v1.2, we have transitioned to X-native authentication. Your email and preferences are maintained in our secure Supabase database until you request account deletion.

2. AI Identity & Profile Sync (Local-Only)

  • Style Calibration: Xcue analyzes your profile (bio, tone, and vocabulary) to calibrate the AI to match your unique voice.
  • Zero Cloning: This calibration data is processed locally within your browser. We do not save, clone, or transmit your "Identity Profile" to our servers or any third-party databases.
  • No Persistence: If you uninstall the extension or clear your cache, this local calibration is erased.

3. Voice & Audio Privacy

  • Voice-to-Draft: Audio is captured solely for real-time transcription into text.
  • Ephemeral Processing: Audio data is processed instantly and is never recorded or stored. Once the transcription is complete, the audio data is immediately discarded.

4. Contextual Intelligence & Vision

  • Real-Time Processing: To generate relevant replies, Xcue analyzes the text and images in the active thread using the Google Gemini 3 Flash architecture.
  • No Logging: This context is used only for the duration of the generation session and is not maintained or logged after the reply is drafted.

5. Nature of Service: Human-in-the-Loop

  • Non-Automated: Xcue is a writing assistant, not a bot. It cannot post, like, or reply autonomously.
  • Manual Control: All AI-generated suggestions are presented in your private sidepanel. No content is published until you manually click "Post."

6. Data Retention & Training

  • No Model Training: We strictly adhere to enterprise API policies. Your private data, voice transcripts, and profile context are never used to train base models for Google or any other provider.
  • Data Deletion: You may request the permanent deletion of your account at any time by emailing support@x-cue.com. We will remove all associated account data within 7 business days.

7. Contact & Support

For questions or technical inquiries, please reach out via: