Postrait

Privacy Policy

Postrait reads public posts from an X account and writes up what they suggest about how that account thinks and works. This page says what we read, where it goes, and how long we keep it.

What we read

When you enter a handle, we read that account's public posts on X: up to its most recent 200 posts of its own — originals, replies and posts shared with a comment — and the mix of its last 300 actions. Posts shared without any words of their own are counted but never read, because they carry none of the account's own writing.

We read only public posts. We never read protected accounts, direct messages, or anything that requires being logged in. If an account has fewer than 30 public posts of its own, we decline to read it.

The posts reach us through a third-party service that supplies public X data. We are not affiliated with X Corp., and we do not use your X login — there is nothing to log into here.

Where the posts go

To produce a reading, the sampled posts are sent to DeepSeek, the language-model provider we use for the analysis. DeepSeek processes and stores that data on servers located in the People’s Republic of China, under the laws of that jurisdiction.

If you are not comfortable with public posts being processed and stored in mainland China, do not use this service.

What we keep, and for how long

The full sample of posts stops being used after 48 hours. It exists only so we can look into a reading that has just come out; past that point we never read it again, and a cleanup job that runs once a day deletes it. Between the moment a sample expires and the next daily run, it can still sit in the database for up to another day.

The reading itself — the four-letter type, how strongly each dimension leans, the quotes it cites, the written read and the mix of activity — is kept so that a report link keeps working after you pay for it.

A reading is cached per account for 48 hours. Asking for the same account again inside that window returns the stored reading instead of reading X again.

To stop scripted bulk querying, we record a salted hash of the requesting IP address. It counts toward the hourly limit for one hour and is ignored after that. The same daily cleanup job deletes these rows, so a hash can remain in the database for up to about a day after it has stopped counting. We never store the address itself, and the hash is used for nothing else.

We set no tracking cookies and run no third-party analytics.

If you pay

Payment is handled by Creem, our merchant of record. Card details go to Creem and never reach us. From Creem we store the order ID, the buyer email address they pass on, and the unlock token that your report link carries. The $4.99 charge appears on your statement through Creem.

Anyone public can be looked up

Any public X account can be looked up here by anyone, including an account that is not yours. The account holder is not asked and is not notified.

A reading is an inference drawn from public posts by a language model. It is not a statement of fact about the person behind the account, it is not confirmed by them, and it can be wrong. Please do not treat it as a finding about anyone.

Removing a reading

If you want a reading about an account you control removed, email support@postrait.io with the handle. We delete the reading and everything stored with it. We answer support mail within 3 business days.

Contact

Questions about this policy: support@postrait.io.