Privacy Policy
Effective: 22 August 2026 · Last updated: 22 August 2026 · Applies to: the X-Relay Discord bot, the X-Relay Telegram bot and x-relay.com
The short version
- We store the minimum needed to deliver alerts: your platform ID, your server or chat, your trackers, your plan, and where to send the alerts.
- We do not read messages in your Discord server. The bot has no message-reading listener — everything in an alert comes from public X content.
- We never ask for an X login, cookies, wallet keys, or card details, and we never receive them.
- We do not sell data and we run no advertising or tracking network.
- Want it gone? Delete your trackers, or write to support@x-relay.com and we erase your records.
Contents
01Who is responsible
X-Relay is an independently operated service. The operator of x-relay.com and of the X-Relay bots is the data controller for the information described here.
For any privacy question, request or complaint: support@x-relay.com. We answer privacy requests within 30 days.
X-Relay is not affiliated with X Corp., Discord Inc. or Telegram. Those platforms have their own privacy policies, which govern what they do with your data.
02What we never collect
- The messages in your Discord server. The bot runs no message listener and stores no message content. It cannot read your channels' conversations, and nothing in an alert is taken from them.
- Your X / Twitter credentials. No password, no cookies, no session, no OAuth grant on your account. X-Relay reads only public X content, using its own infrastructure.
- Wallet keys or seed phrases. Never asked for, never accepted, never needed.
- Card or bank details. Payments run through a crypto payment processor; card data does not exist in this flow at all.
- Your email address — unless you choose to write to us, in which case we hold that correspondence.
- Location, device fingerprints, contacts, or any advertising identifier.
03What we store, exactly
This is the complete list, taken from the live database schema rather than written from memory.
If you use the Discord bot
| Data | Detail |
|---|---|
| Server identity | Server (guild) ID and name; the ID and display name of the server owner and of whoever added the bot |
| Delivery destination | The webhook URL alerts are sent to, and the channel ID it belongs to |
| Your trackers | The X handles, keywords, X List IDs and bio-filter terms you chose; which activity types you enabled; an optional role ID to ping; the timestamp of the last alert sent |
| Plan state | Plan expiry, grace period, trial flag, tracker allowance, Turbo expiry, digest preference, reminder timestamps |
| Preferences | Contract-address detection on or off; alert branding |
| Trial history | That your Discord account used its one-time trial, and when |
If you use the Telegram bot
| Data | Detail |
|---|---|
| Account identity | Your Telegram user ID, and your username / first name / last name as Telegram reports them |
| Delivery destination | The chat or group ID where you want alerts |
| Your trackers | Same as above — handles, keywords, lists, bio filters, activity types |
| Plan state | Same as above |
| Service state | Whether the bot was blocked by that chat (so we stop wasting attempts on it); whether you joined our channel where that was part of an offer; which one-off campaign messages were sent to you, so you are not messaged twice |
If you pay
| Data | Detail |
|---|---|
| Invoice record | Order number (it contains your server or user ID), the processor's transaction ID, product, plan tier, number of months, amount in USD, invoice link, timestamps |
| Payment record | Transaction ID, order number, target ID, when it was credited |
| Manual grants | If we grant or extend a plan by hand (support case, promo), a note of it |
We do not receive or store your wallet address, your coin balance, or your payment history from the processor. If you ask for a refund or a payout, you give us an address for that single transfer, and we keep the record of that transfer.
If you use referrals
Your referral code, which accounts joined through it, amounts earned, and payouts made (amount, note, date).
Technical logs
The servers keep operational logs so that failures can be diagnosed: server and chat IDs, tracked handles, timings, errors and delivery outcomes. These logs are for running and fixing the service, nothing else. They are not used to profile anyone and are not shared.
04Data about the X accounts you track
To deliver alerts, we process information about the X accounts our users choose to monitor — handle, display name, profile and bio text, posts, follower and following changes, and similar. All of it is public information published on X, retrieved as any visitor would see it. We do not access private accounts, protected posts, or direct messages.
We keep only what monitoring requires: the current state of a tracked account, so we can tell what changed since last time, plus short-lived working data. Alert content itself is delivered to the user and is not archived by us as a library of posts.
If you are the owner of a tracked X account and you want to know what we hold about it, or object to that processing, write to support@x-relay.com. Note that the choice to monitor a public account is made by our users, and that public posts remain visible on X regardless of what we do.
05Why we hold it, and on what legal basis
| Purpose | Data used | Basis (GDPR Art. 6) |
|---|---|---|
| Deliver the alerts you asked for | Identity, destination, trackers | Performance of a contract |
| Run plans, trials and limits correctly | Plan state, trial history | Performance of a contract |
| Take and credit payments | Invoice and payment records | Performance of a contract; legal obligation for records |
| Keep the service alive and debug failures | Technical logs | Legitimate interests — a working service |
| Stop abuse, farming of free plans and fraud | Owner IDs, trial history, referral data | Legitimate interests — protecting the service |
| Tell you about your own subscription (expiry, breakage) | Identity, plan state | Performance of a contract |
| Occasional product or offer messages in the bot | Identity, plan state | Legitimate interests; you can opt out by replying or writing to us |
We do not sell personal data, do not share it with data brokers, and do not use it for advertising or profiling.
07Where it is stored
The database and both bots run on a dedicated server located in New York, United States. The website is served by Vercel's global network. If you are in the EEA or the UK, this means your data is transferred to and stored in the United States; we rely on the transfer being necessary to perform our contract with you, and we keep the amount of data involved to the minimum described above.
08How long we keep it
| What | Kept for |
|---|---|
| Trackers you delete | Removed immediately |
| Your server / chat record, plan state, remaining trackers | Until you ask us to erase it — see below |
| Invoice and payment records | Kept as business records; anonymised or removed on request where no legal duty requires otherwise |
| Technical logs | Roughly 3 weeks, then rotated away automatically |
| Database backups | 30 days, then deleted |
Removing the bot does not erase your settings. This is deliberate: servers frequently remove a bot for a permissions clean-up and add it back the same day, and we would rather they find their trackers intact than lose them. If you want the data actually erased, tell us — that is one email and we do it.
09Your rights and how to delete
Depending on where you live, you have some or all of these rights: to access the data we hold about you, to correct it, to erase it, to restrict or object to processing, to receive a copy in a portable format, and to complain to your local data-protection authority.
Do it yourself, right now
- Delete individual trackers with the remove commands in the bot.
- Delete the Discord webhook in your channel settings — no further alert can be delivered through it.
- Remove the bot from your server, or block the Telegram bot, to stop everything immediately.
Ask us
Write to support@x-relay.com from an account we can connect to your record, or message us from the same Discord or Telegram account, and say what you want: a copy of your data, a correction, or full erasure. We reply within 30 days. Erasure removes your server or user record, your trackers, your plan state and your delivery destination. Payment records may be kept where a legal or accounting duty applies; backups age out within 30 days.
10The website
x-relay.com sets no advertising cookies and no cross-site trackers. It uses Vercel Analytics, which counts page views without cookies and without building a profile of you. Like every web host, Vercel records standard request logs, which include IP addresses, for security and operations. Pages load fonts from Google Fonts, which means your browser contacts Google to fetch them.
11Security
- All traffic between you, the platforms and us runs over encrypted connections.
- The database is not exposed to the public internet; server access is limited to the operator.
- Backups are kept on the same protected server and expire after 30 days.
- Webhook URLs are treated as secrets — they are stored to deliver your alerts, and are never shown to other users or shared with anyone.
- Payment credentials for the processor are held in server-side configuration, outside the code repository.
No system is perfectly secure. If we discover a breach that affects your data, we will inform you and, where required, the relevant authority, without undue delay. If you believe you have found a vulnerability, please report it to support@x-relay.com rather than disclosing it publicly.
12Children
X-Relay is not directed at children. You must be at least 13 (or older, where local law or platform rules require) to use the bots, and at least 18 to pay for a plan. If you believe a child has provided us with data, write to us and we will delete it.
13Changes to this policy
If we change what we collect or why, we update this page and the date at the top. For a change that materially affects your privacy, we give notice at least 7 days in advance through the bot or the site.
14Contact
| Purpose | Where |
|---|---|
| Privacy requests, deletion, access, complaints | support@x-relay.com |
| Day-to-day support | Telegram bot · Discord server |
| The agreement itself | Terms of Service |
| How the product handles your accounts | Security overview |
X-Relay is an independent tool. Not affiliated with X Corp., Discord Inc. or Telegram.