How we read X, Hacker News and other sources.

LiquidUser shows you people describing a problem your product solves in public posts. This page says how we read those posts, what we keep and for how long, and what we will never do with them or with your accounts.

Last updated 29 September 2026. If any of this changes, this page changes first.

The short version

  • We read X only through X's official API, and we only read. We have never asked X for permission to post, like, follow or send messages, and we never will.
  • No scraping, no logged-in cookies, no pools of accounts, and no X data bought from third-party resellers.
  • We keep the text of an X post for 14 days at most. After that we keep only the post's ID, its link and the scores LiquidUser worked out.
  • When the author or X asks us to delete something, we delete it within 24 hours.
  • Anyone can opt out with their X handle. No account and no proof needed.
  • We never match an X handle to an email address, and we never train a model on X posts.
  • LiquidUser drafts a reply. You read it, change it and post it yourself, in X's own composer.
  • On Hacker News you get a brief, not text to paste, because HN's guidelines ban generated comments.

How we read X

We use version 2 of the X API with our own developer app, on X's pay-per-use plan. Every call it makes is a read: it searches recent posts for people describing a problem, looks up the author of a post we show you, and checks how much of our X budget we have used.

The app has no write permission at all. If we add a way to connect your own X account (to read your own lists, mentions and replies), it will ask for read permissions only and list each one before you agree. We will never ask you to create your own X developer app or bring your own API key.

When our X credit runs out, X stops answering and your scan says X is unavailable. We do not look for another way in.

A test in our code fails if anyone adds an X write permission, a request that posts, likes, reposts, follows or sends a message, a session cookie, or a third-party source of X data. Another test fails if any agent tool can post.

What we keep, and for how long

Post text

Up to 14 days after we read it, so you can see it while the conversation is still live. A daily job then clears the text from our database and from every saved result that quoted it.

IDs and our scores

The post ID and link, the author's X user ID and handle, and LiquidUser's own judgements (fit, intent, timing, the problem it matches) stay while your workspace uses them, so the same post is not shown to you twice and your history still makes sense.

Deleted and private posts

X's developer terms say stored posts must be kept current, and deleted within 24 hours when X or the author asks. We do that. Today we learn about a deletion when the author or X tells us. Checking every stored post against X costs money for each post, so we keep the text window short instead.

Models

Post text is sent to our language model provider to judge whether the author has the problem and to write your brief. The subprocessors page names it. We never use X posts to train or fine-tune a model.

The people in the posts

LiquidUser searches for problems described in public posts. It has no feature that follows a particular person, and it does not guess anyone's health, religion, politics or other sensitive traits.

We never match an X handle to an email address. The people you see come with their public post and profile link, never with contact details.

Anyone can remove themselves on the opt-out page with an X profile link or just their @handle, with no account and no proof. Within minutes the handle goes on a suppression list, stored as a salted hash, what we stored from their posts is erased, and they disappear from every workspace. We never collect their posts again.

Replies are yours to post

LiquidUser never posts, likes, follows, reposts or sends a message, on X or anywhere else, and neither can its agent tools. It drafts. For an X post, the draft opens in X's own composer with the reply already addressed. You edit it and press Post.

X's automation rules say “sending automated replies to posts based on keyword searches alone is not permitted”, and since 23 February 2026 X's API rejects replies the author did not ask for. A person reading and posting each reply is the only way we would want our own account to work, so it is the only way LiquidUser works.

What works on X is also what keeps an account safe: reply to fewer people and say something useful, say who you are when you mention your product, and never paste the same text under many posts.

How we read Hacker News

We read Hacker News through its public search API (run by Algolia) and the official Hacker News API. Both are free and documented.

HN's guidelines say: “Don't post generated text or AI-edited text. HN is for conversation between humans.” So for a Hacker News thread LiquidUser gives you a brief: the point worth making, the fact from your own site that backs it, the question worth asking and whether mentioning your product fits. There is no text to paste. You write the comment.

Other sources

Your website

When you scan your own site, LiquidUserBot reads up to eight public pages and follows your robots.txt.

GitHub

Public issues and discussions through GitHub's official API, when it is switched on. Settings, under Sources, shows whether it is. We never contact an author off GitHub.

Bluesky

Public posts through Bluesky's public API, read only and without an account. We leave out accounts that ask apps not to show them to logged-out readers, and self-labelled bots. You post every reply yourself.

Forums

Off. forum.cursor.com's and community.openai.com's terms don't allow automated reading, so we read a forum only after its owner agrees in writing.

Reddit

We do not read Reddit. Reddit puts every API app behind manual approval and requires written permission for commercial use, and we will not scrape it.

Anything we add

The same rules: the source's official, documented interface, read only, with its status shown in Settings.

The rules we follow

Each line above comes from one of these. They are the primary sources, not summaries of them.

Questions, or something here that doesn't match what you see in the product: write to privacy@liquiduser.com.

What we promise

  • We never post for youNo replies, likes, follows or messages in your name. You post every reply yourself.
  • No bots, no account pools, no proxiesNothing signs in as anyone, and nothing scrapes.
  • No fake numbersNo invented counters, testimonials or countdown timers. Every number comes from real data or the plan's own limits.
  • Official APIs onlyX through its paid API, Hacker News and Bluesky through their public ones. Read only.
  • Briefs on Hacker NewsHN bans generated comments, so there you get what to say and write the reply yourself.