Legal and trust
Privacy Policy
Learn how PilotMyX processes account details, connected X data, MCP credentials, scheduled posts, logs, service providers, retention, and privacy rights.
Last updated: July 17, 2026
Data controller
TheoryCraft SaaS is the data controller for personal data processed by PilotMyX. Privacy requests can be sent to [email protected] or to 59 Rue de Ponthieu, 75008 Paris, France.
Data we process
Account data includes your linked X identity, authentication records, preferences, and security events.
Connected X data can include the X account identifier, username, profile counters, posts, post metadata, public or account-authorized metrics, synchronization state, and the credentials required to maintain the connection.
Publishing data includes drafts, schedule times, uploaded image files and alt text, and publication status. MCP data includes token identifiers, scopes, expiry, revocation, and usage timestamps. The secret token itself is shown only once when it is created.
Technical data can include IP address, user agent, request logs, error details, and security signals. Public-site analytics are collected only after you consent.
Why we process data
We process account, X connection, MCP, and scheduling data to perform the service you request. We process security, reliability, and limited diagnostic data for our legitimate interest in operating and protecting PilotMyX.
We process optional Google Tag Manager and Google Analytics data only after you accept analytics cookies.
Who receives data
Data is shared only with providers needed for the relevant operation. These can include X Corp for account authentication and API operations, Hetzner for European hosting, and Google for analytics only after consent.
A compatible MCP client receives only the data and actions allowed by the token scopes you create. Your chosen client operates under its own privacy terms.
International transfers
Some providers, including X or Google, may process data outside the European Economic Area. Where required, transfers rely on an applicable legal mechanism such as an adequacy decision or standard contractual clauses.
Retention
Account and connected X data are retained while your account is active and for the period reasonably needed to complete deletion, resolve incidents, or meet legal obligations. Cached metrics and publication records are retained to provide analytics, freshness context, and publication status until deletion or an applicable retention limit.
Uploaded image files are temporary. PilotMyX removes them from active storage as part of successful publication or explicit draft or image deletion; a published-file deletion failure is retried from durable media state. The account limit applies only to pending media. Pending, scheduled, cancelled, or failed publications retain their images so the draft can be reused, subject to that limit. Uploaded images are excluded from service backups.
Revoked credentials and expired authentication records are deleted or rendered unusable according to security and legal retention needs. Server logs are kept for a limited operational and security period.
Security
PilotMyX uses access controls, account isolation, scoped credentials, transport security, and operational logging to reduce unauthorized access. No internet service can guarantee absolute security, so you should revoke credentials and contact us immediately if you suspect exposure.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time without affecting processing performed before withdrawal.
You may also lodge a complaint with the CNIL in France or another competent supervisory authority. We may need to verify your identity before completing a request.
No sale of personal data
PilotMyX does not sell personal data and does not use connected X content for cross-context behavioral advertising.