The short version
- We read X only through X's official API, and we only read. We have never asked X for permission to post, like, follow or send messages, and we never will.
- No scraping, no logged-in cookies, no pools of accounts, and no X data bought from third-party resellers.
- We keep the text of an X post for 14 days at most. After that we keep only the post's ID, its link and the scores LiquidUser worked out.
- When the author or X asks us to delete something, we delete it within 24 hours.
- Anyone can opt out with their X handle. No account and no proof needed.
- We never match an X handle to an email address, and we never train a model on X posts.
- LiquidUser drafts a reply. You read it, change it and post it yourself, in X's own composer.
- On Hacker News you get a brief, not text to paste, because HN's guidelines ban generated comments.
How we read X
We use version 2 of the X API with our own developer app, on X's pay-per-use plan. Every call it makes is a read: it searches recent posts for people describing a problem, looks up the author of a post we show you, and checks how much of our X budget we have used.
The app has no write permission at all. If we add a way to connect your own X account (to read your own lists, mentions and replies), it will ask for read permissions only and list each one before you agree. We will never ask you to create your own X developer app or bring your own API key.
When our X credit runs out, X stops answering and your scan says X is unavailable. We do not look for another way in.
A test in our code fails if anyone adds an X write permission, a request that posts, likes, reposts, follows or sends a message, a session cookie, or a third-party source of X data. Another test fails if any agent tool can post.
What we keep, and for how long
- Post text
Up to 14 days after we read it, so you can see it while the conversation is still live. A daily job then clears the text from our database and from every saved result that quoted it.
- IDs and our scores
The post ID and link, the author's X user ID and handle, and LiquidUser's own judgements (fit, intent, timing, the problem it matches) stay while your workspace uses them, so the same post is not shown to you twice and your history still makes sense.
- Deleted and private posts
X's developer terms say stored posts must be kept current, and deleted within 24 hours when X or the author asks. We do that. Today we learn about a deletion when the author or X tells us. Checking every stored post against X costs money for each post, so we keep the text window short instead.
- Models
Post text is sent to our language model provider to judge whether the author has the problem and to write your brief. The subprocessors page names it. We never use X posts to train or fine-tune a model.
The people in the posts
LiquidUser searches for problems described in public posts. It has no feature that follows a particular person, and it does not guess anyone's health, religion, politics or other sensitive traits.
We never match an X handle to an email address. The people you see come with their public post and profile link, never with contact details.
Anyone can remove themselves on the opt-out page with an X profile link or just their @handle, with no account and no proof. Within minutes the handle goes on a suppression list, stored as a salted hash, what we stored from their posts is erased, and they disappear from every workspace. We never collect their posts again.
Replies are yours to post
LiquidUser never posts, likes, follows, reposts or sends a message, on X or anywhere else, and neither can its agent tools. It drafts. For an X post, the draft opens in X's own composer with the reply already addressed. You edit it and press Post.
X's automation rules say “sending automated replies to posts based on keyword searches alone is not permitted”, and since 23 February 2026 X's API rejects replies the author did not ask for. A person reading and posting each reply is the only way we would want our own account to work, so it is the only way LiquidUser works.
What works on X is also what keeps an account safe: reply to fewer people and say something useful, say who you are when you mention your product, and never paste the same text under many posts.
How we read Hacker News
We read Hacker News through its public search API (run by Algolia) and the official Hacker News API. Both are free and documented.
HN's guidelines say: “Don't post generated text or AI-edited text. HN is for conversation between humans.” So for a Hacker News thread LiquidUser gives you a brief: the point worth making, the fact from your own site that backs it, the question worth asking and whether mentioning your product fits. There is no text to paste. You write the comment.
Other sources
- Your website
When you scan your own site, LiquidUserBot reads up to eight public pages and follows your robots.txt.
- GitHub
Public issues and discussions through GitHub's official API, when it is switched on. Settings, under Sources, shows whether it is. We never contact an author off GitHub.
- Bluesky
Public posts through Bluesky's public API, read only and without an account. We leave out accounts that ask apps not to show them to logged-out readers, and self-labelled bots. You post every reply yourself.
- Forums
Off. forum.cursor.com's and community.openai.com's terms don't allow automated reading, so we read a forum only after its owner agrees in writing.
We do not read Reddit. Reddit puts every API app behind manual approval and requires written permission for commercial use, and we will not scrape it.
- Anything we add
The same rules: the source's official, documented interface, read only, with its status shown in Settings.
The rules we follow
Each line above comes from one of these. They are the primary sources, not summaries of them.
- X Developer Agreement: Keep stored posts current, delete within 24 hours on request, no training models on X content.
- X Developer Policy: No off-X matching without consent, no bulk or spammy actions, design the service to prevent violations.
- X Automation Rules: No automated replies triggered by keyword searches, no automated likes or follows, no scripting the website.
- X API changelog: Since 23 February 2026 the API rejects replies the original author did not ask for.
- X Web Intents: How a website opens X's own composer with a reply filled in, without any app permission.
- X Terms of Service: Crawling or scraping X without written consent is prohibited.
- Hacker News guidelines: No generated or AI-edited comments, and no automated posting.
- Hacker News API: The official, public read API.
- HN Search API: The public search API for Hacker News posts and comments.
- Reddit Responsible Builder Policy: Why LiquidUser does not read Reddit.
Questions, or something here that doesn't match what you see in the product: write to privacy@liquiduser.com.