X Follow Checkup
Start organizing follows
Log in
Legal

Privacy Policy

Review how personal information and connected data are handled.

Introduction

Lurest Inc. (the "Company") establishes this Privacy Policy as follows regarding the handling of user information in "X Follow Checkup" (the "Service") provided by the Company.

Article 1 (Information We Collect)

The Company may collect or handle the following information in providing the Service.

Through the X API, the Service does not collect X passwords, DM contents, post contents, email addresses or telephone numbers registered with X, or precise location information. However, the available information may change if the X API specifications or the user's authorization scope changes.

  1. Information about the user's own X account: user ID, username, display name, profile description, profile image and banner URLs, profile location, account creation time, public metrics, verification, identity verification, parody and protected-account status, DM availability when available, and subscription status
  2. Public information about following accounts and followers: user ID, username, display name, profile description, profile image and banner URLs, profile location, account creation time, public metrics, verification, identity verification, parody and protected-account status, DM availability when available, subscription status, follow relationships, and information necessary to determine mutual-follow status
  3. Analysis results, relationship summaries, processing status, error messages, and error codes
  4. Stripe customer IDs, payment, billing and refund identifiers and status, amounts, receipt and invoice URLs, email addresses entered in Stripe Checkout, and other information necessary for payment management
  5. Names, email addresses, categories, X handles, subjects, and inquiry messages provided through the inquiry form
  6. Access date and time, URLs, browser, device, IP address, cookies, log information, error information, and other technical information regarding Service usage
  7. Cached pages, images, styles, scripts, fonts, and similar resources stored on the user's device by the Service Worker

Article 2 (Purposes of Use)

The Company uses collected information for the following purposes.

To improve quality, the Company may analyze non-personally identifiable statistics, error occurrence, processing time, acquisition success rates, and similar information. The Company does not use following accounts, followers, profile information, or analysis results acquired through the X API for advertising, external sale, AI model training, or user analysis beyond the purpose of providing the Service.

  1. To provide the Service, perform authentication and identity verification, and manage login status
  2. To acquire, display, organize, and analyze both following-account and follower information using the X API
  3. To display and manage analysis results, acquisition processing, payment records, usage history, and billing or refund documents
  4. To respond to inquiries, verify identity, and send important notices
  5. To investigate bugs, respond to incidents, ensure security, and prevent unauthorized use
  6. To improve Service quality and features using non-personally identifiable statistics and similar information
  7. To comply with laws, terms, X Developer Agreement / Policy, and other applicable rules

Article 3 (Handling of X API and X Data)

The Service acquires information using the X API based on the user's explicit authentication and consent.

The Company handles information acquired from the X API to the extent necessary to provide Service features. Acquired information is handled in accordance with X's terms of service, developer policies, and other conditions set by X.

For data obtained through the X API, the Company complies with deletion, update, usage restriction, and other requirements established by X, and takes appropriate measures such as deleting, updating, or suspending use of stored data as necessary.

The Company does not use information acquired from the X API for purposes that violate laws or X's terms. The Company also does not sell or provide acquired X data to third parties outside the purpose of the Service without user consent.

Article 4 (Handling of Access Tokens and Similar Information)

The Service may handle access tokens, refresh tokens, and other information necessary for authentication issued through X OAuth authentication.

The Company uses this information to the extent necessary to maintain login status for the Service, access the X API, refresh tokens, and otherwise provide the Service.

Authentication information is stored in the user's browser as an encrypted httpOnly cookie for up to 30 days. Logging out invalidates the Service cookie but does not revoke authorization on X. Revoke authorization through X settings.

Article 5 (Third-Party Provision)

The Company does not provide users' personal information to third parties except in the following cases.

  1. When the user has given consent
  2. When required by law
  3. When necessary to protect a person's life, body, or property and it is difficult to obtain the user's consent
  4. When particularly necessary to improve public health or promote the sound growth of children and it is difficult to obtain the user's consent
  5. When cooperation with a national agency, local government, or its contractor is necessary, and obtaining the user's consent may interfere with execution of the relevant affairs
  6. When handling is entrusted to service providers to the extent necessary for payment, data storage, hosting, email delivery, or other provision of the Service

Article 6 (External Services)

The Service uses the following external services.

Handling of information by external services is governed by the terms and privacy policies established by each service provider.

  1. X API and X OAuth authentication
  2. Stripe for payments, billing, refunds, and management of payment email addresses
  3. Supabase for storage of analysis results and processing or payment linkage information
  4. Vercel for hosting, application execution, and infrastructure logs
  5. Resend for inquiry emails and payment or refund notifications in non-production environments

Article 7 (Use of Cookies and Similar Technologies)

The Company uses httpOnly cookies to validate OAuth authentication, maintain login status, and ensure security. OAuth validation cookies are retained for up to 10 minutes, and the encrypted session cookie is retained for up to 30 days.

For offline display and faster loading, the Service Worker may store same-origin public pages, images, styles, scripts, fonts, and similar resources in Cache Storage on the user's device. API responses, authenticated pages, analysis result pages, PDF output, and cross-origin resources are not cached.

Users may delete cookies and site data through browser settings. However, disabling or deleting cookies may make login and some other Service features unavailable.

Article 8 (Retention Period)

Authentication cookies are retained for the period stated in the preceding Article or until logout. Acquisition job progress is held temporarily on the server and is deleted one hour after it starts or when the server process ends.

For the analysis result data stored in AnalysisResult.xUserRows, including lists of following accounts and followers, relationship information used to determine mutual follows, and other public profile information of third parties, only xUserRows is deleted approximately 180 days after creation. The AnalysisResult record itself and its metadata, aggregates, error information, and payment linkage information are not part of this deletion.

At this time, the Service does not provide a feature that allows users to delete analysis data from the screen, nor automatic deletion after 180 days. The Company manually deletes xUserRows through administrator operations using Prisma Studio, SQL, or similar existing tools.

The analysis status, relationship aggregates, error information, and payment linkage information (such as the Stripe customer ID, payment, invoice, and refund identifiers, and receipt and invoice URLs) are retained for the management of usage history and for legal retention. Payment-related information is retained for approximately 7 years from the transaction in accordance with the Electronic Books Maintenance Act and other relevant laws.

Payment, refund, invoice, email, and infrastructure log information is retained for periods required by law and according to the contracts and settings of Stripe, Resend, Vercel, and other applicable providers.

To request deletion of saved analysis data or similar information, use the inquiry form or email contact@lurest.net. The Company generally verifies identity through X OAuth login and, only for paying users who cannot log in to X, may supplement verification by matching the email address registered with Stripe. After confirming identity, the relevant data, and legal retention obligations, the Company will respond through administrator operations within a reasonable period.

Article 9 (Security Measures)

The Company takes necessary and appropriate security measures to prevent leakage, loss, damage, unauthorized access, and similar incidents involving acquired information.

However, due to the nature of internet communications and external services, the Company does not guarantee complete security.

Article 10 (Disclosure, Correction, Deletion, and Similar Requests)

Users may request disclosure, correction, suspension of use, deletion, and similar handling of their personal information held by the Company in accordance with laws.

Users who wish to make such requests should use the Service inquiry form or email contact@lurest.net. After verifying identity through means such as logging in to the user's X account, the Company will respond manually within a reasonable scope in accordance with laws. The Service currently does not provide an account deletion screen or a self-service data deletion feature.

Article 11 (Use by Minors)

If a minor uses the Service, the minor shall use it after obtaining consent from a parent, guardian, or other legal representative.

Article 12 (Changes to this Policy)

The Company may change this Policy as necessary. The revised Policy becomes effective when displayed on the Service or at the time specified by the Company.

Article 13 (Inquiries)

Inquiries regarding this Policy should be made through the inquiry page or inquiry window separately designated by the Company.

Established: May 12, 2026

Last revised: June 13, 2026