Timeline Compass
TermsPrivacyFulfillment

Privacy Policy

What Timeline Compass collects, who it is shared with, and how to get it all back or delete it. Short version: we store what you create, we never post to your X account, we do not train AI models on your content, and we do not sell your data.

Effective 2026-07-29

1. Who is responsible

Timeline Compass (“we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information. Privacy questions and data-rights requests go to jvomarketingautomation@gmail.com.

2. What we collect

Account and identity

Your email address, display name, and authentication records. Sign-in is handled by Clerk; we never see or store your password.

Your X connection (only if you connect it)

Your X handle and account identifier, access tokens, and your public posts and their public engagement metrics. Tokens are encrypted before storage. We request read-only permissions (tweet.read, users.read, offline.access) — we cannot post, reply, like, follow, or send messages as you, and we never ask for the ability to. We do not read your direct messages or private data.

Content you create

Ideas, folders, brain dumps, drafts and generated variants, articles and their versions, coaching conversations, saved reply lists, tags, and notes.

Analysis we generate for you

Content DNA and voice profiles, account health checks, algorithm analyses, and account research — all derived from public data and the content you provide.

Billing

Subscription status, plan, entitlements, and Stripe customer and subscription identifiers. We never receive or store your card number — card data goes directly to Stripe.

Operational records

Usage counters, background job records, rate-limiting counters, request identifiers, and an append-only audit log of security-relevant actions (such as connecting an account, exporting data, or requesting deletion). Rate-limiting identifiers are pseudonymized before storage, and our logs are automatically redacted so credentials and tokens are not written to them.

3. Why we use it

  • To provide the service — storing your work, generating output you request, showing your history.
  • To bill you — managing trials, subscriptions, and entitlements.
  • To keep the service secure — abuse prevention, rate limiting, fraud and incident investigation.
  • To support you — responding when you contact us.
  • To meet legal obligations — tax, accounting, and lawful requests.

Where the law requires a legal basis (such as the GDPR), we rely on performance of our contract with you for service and billing, our legitimate interests in security and abuse prevention, your consent where you choose to connect your X account, and legal obligation where applicable.

4. What we do not do

  • We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
  • We do not use your content to train AI models — ours or anyone else’s.
  • We do not post, message, or take any public action on your X account.
  • We do not run advertising networks, cross-site trackers, or third-party behavioral profiling inside the application. We count page views using our host’s privacy-preserving analytics, which sets no cookies, assigns no persistent identifier, and cannot follow you to other sites.

5. Who we share it with

We use these processors, each only for the purpose listed:

  • Clerk — authentication and identity management.
  • Supabase — the PostgreSQL database storing your account and content.
  • Vercel — application hosting, the AI Gateway that routes model requests, and aggregate page-view analytics.
  • Stripe — payment processing and subscription management.
  • X (X Corp.) — retrieving your public posts and profile, when you connect your account.
  • AI model providers — currently Anthropic and OpenAI, accessed through the Vercel AI Gateway. Content you submit for generation is sent to these providers to produce your requested output.

We may also disclose data if legally required, or to protect the rights and safety of users and the service. If the business is ever sold or merged, your data may transfer as part of it; we would notify you first.

These providers may process data in the United States and other countries. Where required, transfers rely on the providers’ standard contractual clauses or equivalent safeguards.

6. How long we keep it

  • Account and content data: while your account is open, and until you delete it.
  • Account-deletion task records: retained for up to 90 days after completion so we can prove the deletion happened, then automatically purged.
  • Security and audit records: retained in pseudonymized form, meaning they are not linked to you by name or email.
  • Billing and tax records: retained as long as tax and accounting law requires.

7. Your rights and controls

Export. Download a complete, structured copy of your data from settings at any time.

Deletion. Delete your account from settings. This cancels billing, deletes your identity record, and erases your content. The only thing retained is pseudonymized audit and deletion evidence, which cannot be used to reconstruct your content. Deletion cannot be undone — export first.

Disconnect X. Revoke the X connection at any time from settings; you can also revoke it from X’s own connected-apps screen.

Depending on where you live, you may also have rights to access, correct, restrict, or object to processing, to data portability, and to complain to a supervisory authority. Residents of California, Colorado, Connecticut, Virginia, and other US states with privacy laws have equivalent rights, including the right not to be discriminated against for exercising them. We do not sell data, so there is nothing to opt out of on that front. Contact jvomarketingautomation@gmail.com and we will respond within the timeframe the applicable law requires.

8. Security

Access to your data is scoped to your account and enforced on the server. X tokens are encrypted at rest, webhook deliveries are signature-verified and replay-protected, request logs are automatically redacted, and rate limits apply across sensitive boundaries. No system is perfectly secure; if a breach affects your personal data, we will notify you and any regulator as the law requires.

9. Cookies

We use cookies that are strictly necessary to keep you signed in and to secure the session. We do not use advertising or cross-site tracking cookies. Our page-view analytics is cookieless: it stores no identifier on your device.

10. Children

The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

11. Changes

If we make a material change to this policy, we will notify you by email or in the app before it takes effect.

12. Contact

Contact us at jvomarketingautomation@gmail.com.


Questions about this policy: jvomarketingautomation@gmail.com