Privacy policy
Last updated September 5, 2026
Who we are
Sonket is operated by Md Obydullah, an individual based in Bangladesh. Sonket is a read-only tool that watches public posts on X for the topics and accounts you choose, and drafts replies you can post yourself.
This policy explains what we collect, why we collect it, who else touches it, and how you get it deleted. If anything here is unclear, email us at [email protected] or reach us on X at @0xObydul.
What we collect
Your account. When you sign in with X we store your X handle and your X user id. If you sign in with Google or with an email code, or add an address later, we store your email address. If you choose to set a password we store it hashed, never in plain text.
What you set up. This is the working data of the product: your projects, your watches (keywords, brand terms and the accounts you follow), your active hours and timezone, a Telegram chat id if you link one, your spend limits, and a short voice profile built from a few of your own public posts so drafts sound like you.
Technical data. Server logs, your IP address for rate limits, a session cookie, a cookie holding your theme and one holding the project you last opened. We run no analytics trackers and no advertising cookies.
Public posts we read from X
To run a watch we call the X API and fetch public posts that match it. For each post we store the text, the author handle, name, avatar, follower count and bio, the like, reply, repost and impression counts, and the time it was posted.
These posts go into one shared cache, one row per post no matter how many users' watches matched it. A post stays while any watch still refers to it, and is deleted 30 days after none does.
Sonket is read only. It never posts, likes, follows, replies or sends messages from your account, and sign-in with X asks for read scopes only.
How we use it
We use what we collect to:
- run your watches and show you the posts that match them
- score those posts so the ones worth answering come first
- write a suggested reply with an AI model, using the post text and your voice profile. You decide whether to post it, by hand, on X
- send you a Telegram ping if you have linked a chat
- charge your prepaid balance for each post read
- answer your support messages
- keep the service working, and keep it free of abuse
Your own API keys
If you add your own X or model keys, they are encrypted at rest with AES-256-GCM and are never shown again after you save them. They are used only for your own projects, and they are deleted when you delete the project or your account.
Payments
For every top-up we record the amount, the method, and a transaction reference. For crypto that reference is the transaction hash you give us. We never see or store card numbers.
Crypto payments happen on public blockchains and through Binance Pay, under their own terms. Separately, a usage ledger records every X and model call made for you with its cost. That ledger is what your balance is charged from.
Who else touches your data
These are the processors we rely on to run Sonket:
- X Corp, for the X API
- OpenRouter and the model providers behind it, which receive the post text and your voice examples when a draft is generated
- Vercel, for hosting
- Supabase, for the database
- Amazon Web Services, for sending email
- Cloudflare, for DNS, inbound email, and the bot check on our forms
- Telegram, for pings, if you have linked a chat
- Binance and the crypto networks you pay through
We do not sell personal data and we do not share it for advertising.
Keeping and deleting
You can pause your account at any time, which stops every watch and every charge. You can delete your account from Settings. Nothing runs for 7 days and you can restore it inside that window, after which your projects, watches, keys and voice profile are deleted.
The payment and usage ledger is kept for accounting. It stays attached to an account row that has been stripped of your handle, your email and every other personal field. Your email address is replaced by a one-way hash, so that the free credit cannot be claimed twice. Unused balance is not refunded.
Your rights
Depending on where you live, under GDPR, UK GDPR, CCPA or your local law, you can ask for access to your data, correction of it, deletion of it, a copy of it, and you can object to how we use it.
Email [email protected] from the address on your account and we will answer within 30 days. You can also complain to your local data protection authority.
Security
Traffic is encrypted with TLS in transit, your keys are encrypted at rest, and access to the database is least privilege. No method is perfect. If you find a problem, tell us at [email protected] and we will look at it quickly.
Age
Sonket is not for anyone under 16.
Changes to this policy
When this policy changes we update this page and the date at the top. Material changes are announced by email to account holders.