Who we are
TweetLock is an iOS app for creators, indie hackers, and builders who want to ship before they scroll. It locks selected social apps during a building window and releases them once you post your daily build-in-public update. This policy covers the TweetLock app and this website. In it, "we", "us", and "TweetLock" mean the app's developer; "you" means the person using it.
We designed TweetLock to collect as little as the job needs. Where we can keep something on your device instead of our servers, we do.
What we collect
We collect the following when you use TweetLock:
- X (Twitter) account
- When you connect X, we receive your X user ID, username, display name, and profile image, and — if you grant it — the email on your X account. We also store the OAuth access and refresh tokens that let the app post on your behalf.
- Your build updates
- The text of the build-in-public posts you publish through TweetLock, the resulting tweet ID, and when you posted. This is how the streak is verified.
- Streak & activity
- Your current and longest streak, the dates you shipped, and your last post date.
- Settings
- Your lock schedule and frequency, the goals you picked during onboarding, your notification preference, time zone, and whether you've finished onboarding.
- Subscription status
- Whether you have an active trial or TweetLock Pro entitlement. Purchases are handled by Apple; we never see your card or payment details.
We do not ask for or collect your contacts, location, photos beyond what you explicitly attach to a post, or your activity in any other app.
What stays on your device
The single most sensitive thing — which apps you lock — never reaches our servers. TweetLock uses Apple's Screen Time (Family Controls) framework. The apps and categories you choose are represented as opaque tokens that Apple keeps on your device. We can't read them, and neither can anyone else. We never see your browsing, your usage, or the names of the apps you blocked.
GIFs and images you attach while composing are held on your device and uploaded directly to X when you post. We don't keep a copy.
How we use it
- To connect your X account and publish the updates you write.
- To calculate and protect your streak across time zones.
- To arm your lock schedule and send the ship reminders you opt into.
- To remember your setup so a reinstall doesn't make you start over.
- To check whether your trial or Pro entitlement is active.
- To respond to you when you contact support.
We do not sell your data, we do not use it for advertising, and we do not build advertising profiles. We don't run third-party analytics or tracking SDKs in the app.
How long we keep it
We keep your account data for as long as your account exists. When you delete your account, the associated records — your profile, posts, and streaks — are removed immediately (see below). Posts you already published to X remain on X; deleting your TweetLock account does not delete tweets from your X timeline.
Your choices & rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise the core of these directly in the app:
- Access & correction — your profile, schedule, and goals are editable in Settings.
- Disconnect X — Settings → 𝕏 account → Disconnect signs you out and clears local setup.
- Notifications — toggle ship reminders in Settings or iOS Settings at any time.
- Deletion — delete your whole account in one step (next section).
To make any other request, email us at support@tweetlock.online and we'll respond within a reasonable time.
Deleting your account
You can delete your TweetLock account from inside the app: Settings → Delete account. This is permanent and immediate. When you confirm, we:
- delete your Supabase account and all data tied to it — profile, posts, and streaks;
- revoke the X authorization tokens we hold, where X supports it; and
- sign you out and clear TweetLock's data from your device.
Some records may persist briefly in encrypted backups before they age out, and your published tweets stay on X. If you'd rather we handle the deletion for you, email support@tweetlock.online.
Security
Data is encrypted in transit. Access to your records is enforced by row-level security so that you can only reach your own data. OAuth tokens are managed by our authentication provider rather than stored loose in the app. No system is perfectly secure, but we work to keep the surface small — the less we collect, the less there is to protect.
Children
TweetLock is not directed to children under 13 (or the minimum age required in your country), and we don't knowingly collect their data. If you believe a child has provided us information, contact us and we'll remove it.
Changes to this policy
If we change how we handle your data, we'll update this page and move the "last updated" date. Material changes will be surfaced in the app. Continuing to use TweetLock after a change means you accept the updated policy.
Contact
Questions about your privacy, or a request about your data? Email support@tweetlock.online. For anything else, the support page lists common topics and our response times.