Privacy Policy
ITweet ("ITweet," "Company," "we," "us," or "our") is firmly committed to safeguarding the privacy, confidentiality, and integrity of personal data entrusted to us. This Privacy Policy constitutes a legally structured statement describing, in comprehensive detail, the manner in which we collect, receive, record, organize, structure, store, adapt, alter, retrieve, consult, use, disclose, transmit, align, restrict, erase, or otherwise process personal data and associated information when you access or use the ITweet mobile application, website, and related services (collectively referred to as the "Services").
This Policy is implemented in accordance with the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU) 2016/679 (GDPR), and other applicable international privacy laws. Where jurisdictional standards differ, ITweet endeavors to apply the higher standard of protection where reasonably practicable.
By creating an account, accessing, or otherwise using ITweet, you expressly acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy.
This Privacy Policy serves as a transparent disclosure of ITweet's data handling practices. It explains the categories of personal data we collect, the lawful bases upon which we rely to process such information, the purposes for which such data is utilized across ITweet's features including Reels, Posts, Profile functions, Messaging systems, Analytics frameworks, Advertising mechanisms, and Payments infrastructure.
The Policy further describes how we share information under limited lawful circumstances, the security safeguards implemented to preserve confidentiality and integrity, and the legal rights available to users under Indian and European data protection regimes.
This Policy applies globally. Supplemental statutory rights are afforded to users located within the European Economic Area (EEA), the United Kingdom, and India in accordance with applicable regulations.
ITweet adheres to the principle of data minimization. We collect personal data that is necessary, proportionate, and relevant for providing and improving the Services.
2.1 Information You Provide Directly
When registering an account or using ITweet, you may provide personal information including your full name, username, display name, email address, and phone number. A profile photograph may be mandatory during account creation to enhance platform authenticity and mitigate impersonation risks.
Users may also provide biographical information, location details (where voluntarily added), and user-generated content such as Tweets, photo uploads, Reels videos, comments, retweets, quote retweets, captions, hashtags, metadata, and direct messages. Payment information may be processed for premium features; however, ITweet does not store complete payment card numbers.
Profile photographs and usernames may appear publicly across posts, comments, notifications, followers lists, and search results, depending on chosen visibility settings.
2.2 Reels-Specific Data Collection
ITweet offers a vertical short-form video feature known as "Reels," permitting uploads of videos up to sixty (60) seconds. When uploading or engaging with Reels, ITweet processes the video files, captions, hashtags, tagged locations, thumbnails, selected or original audio tracks, and associated engagement data.
Viewer interaction data, including watch duration, replay frequency, skip behavior, likes, comments, shares, and saves, may be processed to enhance recommendation algorithms and distribute content within For You and Following feeds.
2.3 Posts System Data
ITweet enables text-based Tweets, photo posts, Reels posts, and retweets with optional commentary. Metadata including timestamps, device information, engagement statistics, analytics insights, and visibility selections (Public, Followers-only, Private) are processed to support content distribution, moderation, and performance analytics.
2.4 Automatically Collected Data
When interacting with ITweet, technical information such as IP address, device identifiers, operating system, application version, crash logs, session duration, scroll behavior, and feature usage frequency may be automatically collected for fraud prevention, debugging, infrastructure security, and optimization purposes.
2.5 Advertising and Analytics Data
ITweet may display advertisements to support operational sustainability. Advertising data may include advertising identifiers, impression records, click activity, and segmentation metrics. Personalized advertising is conducted only where legally permissible and subject to user consent where required.
ITweet does not sell personal data to third parties.
ITweet processes personal data on lawful bases including user consent, contractual necessity, legitimate interests, compliance with legal obligations, and protection of vital interests. Certain personalization and analytics features may require consent in jurisdictions where mandated by law.
Certain personal data is required for account creation and platform functionality. Failure to provide mandatory data, such as authentication credentials or required identity attributes, may prevent account creation or limit functionality. Optional information remains at user discretion.
ITweet may anonymize or aggregate data for statistical research, product development, safety improvement, and marketing analysis. We do not attempt to re-identify anonymized data unless legally required.
ITweet operates as a globally accessible digital platform. By virtue of cloud-based infrastructure, distributed content delivery networks, analytics environments, and cybersecurity monitoring systems, personal data may be processed in jurisdictions outside the country in which a user resides. Personal data may therefore be transferred to, stored in, or accessed from countries outside India or the European Economic Area ("EEA").
ITweet recognizes that cross-border data transfers require enhanced safeguards. Accordingly, we implement structured legal, technical, and organizational measures designed to ensure that personal data remains protected in accordance with GDPR, the Digital Personal Data Protection Act, 2023, and other applicable frameworks.
7.1 Transfers from the European Economic Area (EEA)
Where personal data originating in the EEA is transferred to jurisdictions not recognized as providing adequate protection under Article 45 GDPR, ITweet implements approved transfer mechanisms pursuant to Chapter V of the GDPR.
These mechanisms may include the use of Standard Contractual Clauses ("SCCs") adopted by the European Commission. Such clauses impose legally binding obligations on data importers to uphold confidentiality, security, and enforceable data subject rights.
ITweet conducts transfer risk assessments and may apply supplementary technical measures such as encryption, pseudonymization, and strict access limitations where necessary.
7.2 Transfers Under India's DPDP Act
In compliance with India's Digital Personal Data Protection Act, 2023, cross-border transfers are conducted in accordance with lawful government notifications and applicable statutory restrictions. Where permitted, ITweet ensures that contractual safeguards and security controls are maintained.
7.3 Cloud Infrastructure and Distributed Systems
ITweet utilizes geographically distributed cloud infrastructure and content delivery systems to ensure availability, performance, and resilience. Providers are contractually required to implement encryption, strict access controls, and audit safeguards.
7.4 Supplementary Safeguards
Supplementary safeguards may include encryption in transit and at rest, role-based access controls, segmentation of data storage architecture, periodic vulnerability testing, and monitoring mechanisms designed to prevent unauthorized access.
7.5 Onward Transfers and Sub-Processors
Any onward transfers conducted by authorized processors are subject to equivalent contractual data protection obligations. ITweet remains responsible for ensuring that all subprocessors comply with applicable data protection requirements.
7.6 Transparency Regarding Transfers
Users located within the EEA may request additional information regarding international safeguards applied to their personal data. ITweet will provide relevant information subject to confidentiality and security considerations.
ITweet retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including service delivery, contractual compliance, fraud prevention, dispute resolution, and regulatory obligations. We adhere to the principle of storage limitation under GDPR and India's Digital Personal Data Protection Act, 2023.
8.1 Account Information Retention
Personal data associated with an active account is retained for the duration of the account's existence. Upon deletion, ITweet initiates structured erasure procedures. Certain data may temporarily remain within encrypted backup systems until scheduled overwrite cycles occur.
8.2 User-Generated Content
Posts, Reels, comments, and metadata remain stored while published. Deleted content is removed from public view but may persist temporarily within replicated infrastructure layers or distributed caching systems.
8.3 Messaging Data
Private messages are retained to enable platform functionality. Deletion by one user does not automatically remove copies retained by other participants.
8.4 Analytics and Log Data
Technical logs and analytics metrics are retained for limited durations necessary for debugging, fraud prevention, and service optimization. Aggregated or anonymized data may be retained longer for statistical analysis.
8.5 Legal Retention and Litigation Holds
Certain records may be retained longer where required by tax regulations, financial compliance standards, court orders, or dispute resolution procedures.
8.6 Backup and Disaster Recovery
Encrypted backup systems are maintained for resilience purposes. Expired backup data is securely overwritten or destroyed in accordance with internal deletion schedules.
8.7 Secure Deletion and Anonymization
When retention periods expire, personal data is securely erased through cryptographic deletion, overwriting, or destruction processes. Where feasible, data may be anonymized to eliminate identifiable attributes.
Messages in one-to-one chats on ITweet are now truly end-to-end encrypted. This means ITweet cannot read the contents of your private conversations.
9.1 Device Keys
Each of your devices generates its own ECDH keypair. The private key never leaves the device — it is stored locally in your browser's IndexedDB — while only the corresponding public key is published so other participants can encrypt messages to you.
9.2 Message Sealing
Message bodies are sealed with AES-GCM on your device before they are ever sent to our servers, and are decrypted only on-device by the intended recipient. ITweet stores only the encrypted ciphertext.
9.3 Push Notifications
Because message content is not available to our servers, push notifications no longer include message text. They display a generic "Sent you a message" instead.
9.4 Scope and Limitations
- Older messages sent before encryption was enabled remain stored as plaintext and continue to render normally.
- Group chats are end-to-end encrypted on supported clients. Message bodies are sealed before they leave the device and are only readable by the group members holding their matching keys.
- If you lose access to all your devices, previously encrypted messages may not be recoverable, as ITweet does not hold your private keys.
- Metadata such as sender, recipient, and timestamps is still processed to deliver messages.
ITweet utilizes automated systems and algorithmic processes to enhance user experience, improve content discovery, maintain platform safety, and ensure operational efficiency. Such systems may analyze behavioral signals, engagement metrics, and interaction patterns to personalize feeds, recommend Reels, detect harmful content, and prevent abuse.
10.1 Content Ranking and Personalization
The "For You" and "Following" feeds are partially powered by ranking systems that evaluate user engagement, viewing patterns, and content attributes. These systems prioritize relevance and recency while mitigating spam and low-quality content.
10.2 Reels Recommendation Systems
Automated recommendation models may analyze watch duration, interaction signals, hashtags, audio engagement, and follower relationships to present personalized short-form video content.
10.3 Automated Content Moderation
ITweet deploys automated tools to detect potential violations of Community Guidelines, including spam, abusive behavior, and harmful material. Certain enforcement actions may result from automated detection, subject to further review where appropriate.
10.4 Fraud Detection and Security Monitoring
Automated detection systems analyze login behavior, device characteristics, and suspicious activity patterns to prevent account compromise and fraudulent use.
10.5 Human Review Rights
Where legally required, including under Article 22 GDPR, users may request human review of decisions based solely on automated processing that significantly affect them.
10.6 Fairness and Transparency
ITweet periodically evaluates algorithmic systems to mitigate bias and ensure fairness. Full disclosure of algorithmic mechanisms may be limited to protect intellectual property and platform security.
ITweet respects the legal rights granted to individuals under the General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023. Depending on jurisdiction, users may exercise specific rights in relation to their personal data.
11.1 Right of Access
Users may request confirmation of whether their personal data is processed and obtain access to such data, including purposes of processing, recipients, retention periods, and information regarding cross-border transfers.
11.2 Right to Rectification
Users may request correction of inaccurate or incomplete personal data. Many updates may be performed directly through account settings.
11.3 Right to Erasure
Users may request deletion of personal data under certain conditions, subject to lawful retention requirements and regulatory obligations.
11.4 Right to Restrict Processing
Users may request temporary restriction of processing where permitted by law.
11.5 Right to Data Portability
Where applicable, users may request a machine-readable copy of their personal data for transfer to another service provider.
11.6 Right to Object
Users may object to processing based on legitimate interests or direct marketing purposes.
11.7 Right to Withdraw Consent
Consent-based processing may be withdrawn at any time without affecting prior lawful processing.
11.8 Rights Under India's DPDP Act
Indian users may exercise rights of access, correction, erasure, grievance redressal, and nomination in accordance with statutory provisions.
11.9 Complaint and Supervisory Authorities
Users in the EEA may lodge complaints with their local supervisory authority. Indian users may approach designated grievance officers under the DPDP Act.
11.10 Identity Verification
ITweet may verify identity prior to fulfilling rights requests and may decline manifestly excessive or unfounded requests as permitted by law.
ITweet is committed to safeguarding the privacy and safety of minors. The Services are intended for individuals who meet the applicable minimum age requirements in their jurisdiction. ITweet does not knowingly collect or process personal data from children below the lawful age threshold without obtaining required parental or guardian consent.
The minimum age requirement to create an ITweet account is thirteen (13) years, or such higher age as required by local law. Users represent that they meet applicable age requirements when registering.
12.1 Compliance with India's DPDP Act
In India, individuals under eighteen (18) years are considered children under the Digital Personal Data Protection Act, 2023. Where required, ITweet may obtain verifiable parental consent, restrict certain features, and disable targeted advertising for accounts reasonably believed to belong to minors.
12.2 GDPR Article 8 Compliance
Within the European Economic Area, processing of children's data may require parental consent for individuals below the applicable age threshold determined by Member State law.
12.3 Safety and Moderation Safeguards
ITweet may apply enhanced moderation measures, restrict messaging capabilities, and implement protective visibility settings to reduce risks associated with minor accounts.
12.4 Parental Rights
Where applicable, parents or lawful guardians may request review or deletion of personal data relating to their child, subject to verification of authority.
12.5 Remedial Action
If ITweet becomes aware that data from a child has been collected without required consent, appropriate steps will be taken to delete such data and terminate the account.
ITweet operates under the principle of accountability and implements internal governance structures designed to ensure lawful, fair, and transparent processing of personal data in accordance with applicable laws.
14.1 Data Controller Status
ITweet acts as the Data Controller (or Data Fiduciary under Indian law) with respect to personal data processed through the Services, determining the purposes and means of such processing.
14.2 Compliance Framework
Internal policies, risk assessments, and compliance reviews are conducted periodically to ensure adherence to GDPR, the Digital Personal Data Protection Act, 2023 (India), and other applicable regulations.
14.3 Grievance Redressal (India)
Indian users may submit privacy-related grievances through designated contact channels. ITweet will acknowledge and respond to complaints within the timelines prescribed under applicable law.
14.4 EU Representative
Where required under GDPR Article 27, ITweet may designate a representative within the European Union to serve as a contact point for supervisory authorities and data subjects.
14.5 Amendments
ITweet may update this Privacy Policy periodically. Material changes may be communicated through in-app notifications or registered email communications, where appropriate. Continued use of the Services following such updates constitutes acceptance of the revised Policy.
14.6 Contact Information
ITweet Data Protection Contact: itweet.buisness@gmail.com
Grievance Officer (India): Suranjan — itweet.buisness@gmail.com
14.7 Final Declaration
By accessing or using ITweet, you acknowledge that you have read, understood, and agreed to this Privacy Policy.
ITweet offers eligible creators the ability to earn revenue through subscriptions, Exclusive Content tiers, paid promotions, and advertising programs. This section describes how data is processed in connection with these monetization features.
15.1 Eligibility & Application Data
To join monetization programs, creators must submit an application that may include identity verification, payout details, tax information, and business or contact information. This data is collected solely for eligibility review, compliance, fraud prevention, and lawful payment processing.
15.2 Subscriptions & Exclusive Content
When users subscribe to a creator or unlock Exclusive Content, ITweet processes transaction metadata (amount, currency, timestamp, tier) to deliver the purchased access, calculate creator earnings, and provide users with a record of their purchase. Subscription status is visible to the corresponding creator for the purpose of fulfilling the subscription.
15.3 Revenue Share
Net subscription and content revenue is shared with creators in accordance with the published revenue-share model (currently 70% to the creator and 30% to ITweet, subject to change with notice). Aggregated and per-supporter earnings are made available to creators through the Professional Dashboard.
15.4 Advertising & Boosted Content
Business accounts may run paid promotions, boosted posts, or reel ads through the Ad Manager. To deliver these promotions, ITweet processes campaign settings, audience targeting parameters, billing details, and aggregated performance metrics (impressions, clicks, reach). Personal data is never sold to advertisers.
15.5 Payments & Payouts
Payments are processed via trusted third-party payment providers. ITweet does not store full card numbers or banking credentials on its own servers. Payout records, invoices, and tax documents are retained for the period required by applicable financial and tax regulations.
15.6 Tax Reporting
Where required by law, ITweet may collect tax identification information (such as PAN, GSTIN, VAT, or TIN) from earning creators and share required reports with relevant tax authorities. Creators are responsible for declaring and paying any taxes owed on their earnings.
15.7 Refunds, Disputes & Chargebacks
In the event of a refund request, dispute, or chargeback, ITweet may review the relevant transaction, content, and account activity. Repeated or fraudulent chargebacks may result in suspension of monetization privileges or account access.
15.8 Creator Analytics
Monetizing creators receive aggregated analytics about their supporters and ad performance (such as engagement, geographic distribution, and earnings trends). Individual viewer identities are not exposed beyond what is already publicly visible on the platform (for example, a follower's username).
15.9 Termination of Monetization
ITweet may suspend or terminate access to monetization features if the creator violates the Terms of Service, community guidelines, applicable laws, or program policies. Pending earnings that are lawfully owed will be released in accordance with payout procedures.
15.10 Your Rights
You may, subject to legal and accounting retention requirements, request access to, correction of, or deletion of monetization-related data by contacting itweet.buisness@gmail.com.
Related Pages
ITweet offers eligible creators the ability to earn revenue through our in-app Monetization Program. To qualify for the program, a creator account must meet the following thresholds within a rolling 90-day period:
- 10 million followers gained within the last 90 days.
- 10 million views on content within the last 90 days.
- Either 100 clips created within the last 90 days, or 10 million impressions on content within the last 90 days.
Meeting these thresholds does not guarantee acceptance. All applications are reviewed by our team for compliance with Community Guidelines, authenticity, and content quality. We collect and process monetization-related data — including follower counts, view counts, impression metrics, and content creation activity — solely to evaluate eligibility, calculate earnings, and prevent abuse of the program.
Creators approved for monetization are required to provide accurate payout and tax information. Earnings, payment schedules, and any fees are described in the creator dashboard. We may suspend or revoke monetization privileges if we detect fraudulent activity, repeated policy violations, or manipulation of metrics.
Advertising is what keeps ITweet free to use for everyone. This section explains, in plain language, how ads work on ITweet, what information is and is not used to show them, what control you have, and what we will never do with your data.
16.1 How Ads Work on ITweet
Advertisers come to ITweet with a message they want to reach a particular kind of audience — for example, a local bakery that wants to reach people in its city, or a music app that wants to reach people interested in independent artists. Advertisers do not choose you personally and they never receive your name, phone number, email address, or account handle from us. Instead, they describe an audience, and our systems decide which ads are eligible to appear in your Home feed, Reels, Stories, Explore, and Search results.
When an ad slot becomes available in your session, an automated auction runs in milliseconds. Each eligible ad receives a score based on the advertiser's bid, our estimate of how relevant the ad is to you, and quality signals such as whether the destination page is safe, whether the ad has been reported by other users, and whether the creative complies with our Advertising Policies. The ad with the highest combined score wins the slot. A higher bid alone does not win — a poor-quality or low-relevance ad can lose to a cheaper, better-matched one. This is why the ads you see are labelled "Sponsored" but otherwise appear in the same format as ordinary posts and Reels.
16.2 Your Information and iTweet Ads
The signals used to select ads fall into a small number of categories: (a) profile information you provided, such as your approximate age band, language, and country or city-level location; (b) your activity on ITweet, such as accounts you follow, posts and Reels you like, save, share, or watch to completion, hashtags you engage with, searches you run, and topics our recommendation systems associate with you; (c) device and connection information, such as device model, operating system, screen size, and general network type, used mainly to deliver the right ad format and to detect fraudulent impressions; and (d) limited measurement signals telling us whether an ad was shown, viewed, tapped, or resulted in an action the advertiser chose to report back.
We do not use the content of your end-to-end encrypted direct messages to target ads — we cannot read it. We do not use precise GPS coordinates for ad targeting. We do not sell your personal information to advertisers or data brokers, and we do not share your contact details with them. Sensitive categories — including health conditions, religious belief, caste or tribe, political affiliation, sexual orientation, and trade-union membership — are not available as targeting options on ITweet, and we do not knowingly build ad audiences around them.
Advertisers receive only aggregated, de-identified reporting: how many people saw the ad, how many engaged with it, and broad breakdowns such as country or age band, suppressed when the underlying group is too small to protect individual privacy.
16.3 Ads for Minors
For accounts we understand to belong to users under 18, ad targeting is restricted to age, country, and language. Interest- and activity-based targeting is disabled, and categories such as gambling, alcohol, tobacco, weight loss, dating, and financial products are not eligible to be shown.
16.4 Your Controls
- Ad topic controls: Settings → Personalization lets you reduce or turn off activity-based ad personalization. You will still see ads, but they will be less relevant.
- Hide and report: Tap the ⋯ menu on any Sponsored post to hide it, tell us why it is not relevant, or report it. Feedback is fed back into your ad profile.
- Interest profile: You can review the topics associated with your account and remove any of them.
- Partner data: Where advertisers upload audience lists, you can opt out of being matched to them.
- Data access: You can download a copy of the advertising signals attached to your account with the rest of your data export.
Turning off personalization does not reduce the number of ads and does not affect measurement needed for billing and fraud prevention. Ad interaction records are retained for a limited period for billing accuracy and abuse investigation, then deleted or aggregated.
Protecting your account and your personal data is a shared responsibility. This section describes the safeguards ITweet operates, how we align with India's Digital Personal Data Protection framework as it applies in 2026, and the practical steps you can take to stay safe.
17.1 Technical and Organisational Safeguards
All traffic between your device and ITweet is encrypted in transit using TLS. Data at rest is encrypted on our infrastructure, and highly sensitive material — authentication secrets, recovery codes, and payout details — is additionally encrypted or hashed with per-record keys. Direct messages in one-to-one chats are protected with end-to-end encryption using device-held key pairs, meaning message content cannot be read by our staff or produced in plaintext in response to a request.
Access to production systems follows least-privilege and need-to-know principles. Staff access requires individual accounts with multi-factor authentication, is scoped by role, is logged, and is reviewed periodically. We operate rate limiting, anomaly detection on login patterns, bot and automation detection, hardware-backed device attestation on Android via Play Integrity, and continuous monitoring with alerting for unusual data access. Backups are encrypted and rotated, and we test restoration. Vendors handling personal data are assessed before onboarding and bound by written data processing terms.
17.2 Account Security Features You Control
- Two-step verification via authenticator app, SMS, or email OTP.
- Backup codes for recovery when your device is lost.
- Login activity and trusted devices: review active sessions and sign out any device remotely.
- Login alerts for sign-ins from new devices or unusual locations.
- IP allow-listing for high-risk or high-value accounts.
- Privacy controls: private account, close friends, restricted and blocked lists, comment filters, message request gates, and story hiding.
17.3 Alignment with the DPDP Act (India), as applicable in 2026
For users in India, ITweet processes personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the rules and amendments in force in 2026. In practice this means:
- Notice and consent: we tell you, in clear language, what personal data we collect and why, at or before the point of collection. Consent is free, specific, informed, unconditional, and unambiguous, and is requested separately from other terms.
- Purpose limitation and data minimisation: we collect only what is needed for the stated purpose and do not silently repurpose it.
- Withdrawal of consent: you can withdraw consent as easily as you gave it, from Settings → Privacy. Processing that relies solely on that consent then stops, and related data is erased unless retention is legally required.
- Rights of the Data Principal: access to a summary of your data and processing, correction and completion, updating, erasure, nomination of another person to exercise your rights in the event of death or incapacity, and grievance redressal.
- Children's data: we do not knowingly process the data of a child under 18 without verifiable parental consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
- Breach notification: in the event of a personal data breach, we notify the Data Protection Board of India and affected users without undue delay, with the nature of the breach, likely consequences, and the mitigation steps taken.
- Erasure on withdrawal or account closure: data is deleted once the purpose is served, subject to statutory retention.
- Grievance Officer: Suranjan — itweet.buisness@gmail.com. We aim to acknowledge within 24 hours and resolve within the statutory period. If unsatisfied, you may escalate to the Data Protection Board of India.
These commitments sit alongside our obligations under the Information Technology Act, 2000 and the Intermediary Guidelines, including publication of grievance contact details, timely action on unlawful content notices, and preservation of records where required by law.
17.4 How to Stay Safe on ITweet
- Use a long, unique password and never reuse it on other sites. Turn on two-step verification today and store your backup codes offline.
- Never share an OTP, password, or backup code — ITweet staff will never ask for them, and no genuine support agent will DM you first.
- Treat "verification badge", "copyright strike", and "account suspension" DMs and emails as phishing until proven otherwise. Check the sender domain and open links only from within the app.
- Be sceptical of investment, crypto, lottery, job-offer, and romance approaches asking for money or personal documents. Report and block.
- Keep your account private if you do not want strangers to see your content, and review your close-friends and follower lists periodically.
- Do not post government IDs, tickets, bank details, or your home or school address, and turn off location sharing on media you post publicly.
- Review Settings → Login Activity monthly and sign out of devices you do not recognise.
- Keep the app and your operating system updated so security fixes reach you.
- Use blocking, restricting, comment filters, and message controls freely — and report abuse rather than engaging with it.
If you believe your account has been compromised, change your password immediately, sign out all sessions, and contact itweet.buisness@gmail.com. Security researchers may report vulnerabilities to the same address; we do not pursue good-faith research conducted without accessing other users' data.
Certain content is not permitted anywhere on ITweet — in posts, Reels, Stories, live streams, comments, bios, usernames, group names, profile media, ads, or message requests. This section lists what is prohibited, explains what data we process when enforcing these rules, and describes your right to appeal. It complements our Community Guidelines and section 4 of the Terms of Use.
18.1 Categories of Prohibited Content
- Child sexual exploitation: any content that sexualises, endangers, or exploits a minor. Zero tolerance — the account is permanently banned and reported to NCMEC and the relevant authorities.
- Non-consensual intimate imagery and sextortion: intimate images shared without consent, threats to publish them, and revenge-porn campaigns. Removed on first report.
- Terrorism, violent extremism, and dangerous organisations: propaganda, recruitment, funding appeals, glorification, and manifesto distribution.
- Credible threats and incitement: threats of violence against people or places, calls to attack an individual or group, and coordinated brigading.
- Hate speech: attacks, slurs, dehumanising statements, or exclusion calls based on religion, caste, race, ethnicity, national origin, disability, disease status, gender, gender identity, sexual orientation, or age.
- Self-harm and suicide promotion: encouragement, instructions, glorification, challenges, and pro-eating-disorder content. Recovery narratives and help-seeking are allowed.
- Adult sexual content and solicitation: pornographic material, explicit sexual services, and escort advertising.
- Graphic and gratuitous violence: real-world mutilation, execution, or animal cruelty shared for shock value.
- Illegal goods and regulated trade: narcotics, prescription medicines, firearms and ammunition, explosives, endangered wildlife, counterfeit goods, forged documents, stolen data, and human trafficking.
- Fraud, scams, and financial deception: phishing, OTP theft, fake investment or loan schemes, Ponzi and crypto-doubling offers, fake job offers, lottery scams, and money-mule recruitment.
- Harmful misinformation: falsehoods likely to cause real-world harm, including dangerous medical claims, crisis and disaster hoaxes, and voter suppression content.
- Doxxing and privacy invasion: publishing another person's phone number, address, government ID, financial details, medical records, or private communications without consent.
- Impersonation and deceptive identity: pretending to be another person, brand, or official body. Clearly labelled parody and fan accounts are permitted.
- Spam, platform manipulation, and inauthentic behaviour: bot networks, bought followers or engagement, mass duplicate posting, engagement pods, and unauthorised automation or scraping.
- Intellectual property infringement: posting content you do not own or have permission to use, and repeat infringement.
- Malware and exploits: malicious links, credential-harvesting pages, and content designed to interfere with devices or ITweet's systems.
- Deceptive synthetic media: AI-generated or manipulated depictions of real people or events presented as authentic, and sexualised deepfakes of any real person.
18.2 Data Processed for Enforcement
To enforce these rules we process the reported content itself, the report and reporter category, moderator decisions and notes, automated classifier scores, hashes of previously removed material (so it cannot simply be re-uploaded), account history, device and integrity signals used to detect ban evasion, and, where a legal notice or law-enforcement request applies, the records we are required to preserve. This processing is necessary to perform our contract with you, to comply with legal obligations, and for the legitimate interest of keeping the platform safe. Enforcement records are retained for a limited period so that appeals can be reviewed fairly and repeat behaviour identified, then deleted.
18.3 Enforcement Outcomes and Appeals
Depending on severity, intent, and history, we may label or age-gate content, reduce its distribution, remove it, remove the ability to comment, live-stream, advertise, or monetise, temporarily restrict the account, or terminate it permanently. Severe violations — child safety, terrorism, non-consensual intimate imagery — result in immediate termination without a warning. Automated systems flag content at scale, but consequential decisions involving account termination receive human review.
When we take action we notify you in the app with the policy involved. You can appeal from Settings → Account Status; appeals are reviewed by a different reviewer where feasible, and content is restored if we got it wrong. Users in India may also raise a grievance with our Grievance Officer at itweet.buisness@gmail.com, and escalate further under applicable law.
Report content by tapping the ⋯ menu → Report, or email itweet.buisness@gmail.com for urgent safety matters. Reports are confidential — we do not tell the reported account who reported it.
All paid ITweet products — subscription tiers, badges, boosts, and any in-app purchase — are sold and processed exclusively through Google Play Billing. ITweet never sees, receives, or stores your card number, UPI handle, bank details, or CVV. Payment credentials are handled end to end by Google under Google's own payment terms and privacy policy.
19.1 What we receive from Google
- An opaque purchase token and order ID identifying the transaction.
- The product / SKU purchased and its subscription state (active, in grace period, on hold, paused, cancelled, expired).
- Renewal and expiry timestamps, and whether auto-renew is enabled.
- Acknowledgement and refund/chargeback notifications via Google's Real-Time Developer Notifications.
We verify every purchase token server-side before granting entitlements, and we store only the token, the SKU, the state, and the timestamps against your account. That record is what powers your badge, feature gates, and the "Manage subscription" screen.
19.2 Renewals
Subscriptions renew automatically each billing period through Google Play until cancelled. Prices are displayed in INR inside the app; Google converts to your local currency and adds applicable taxes at checkout. Upgrades and downgrades are prorated by Google — upgrades usually take effect immediately, downgrades at the next renewal date.
19.3 How to cancel
- Open the Google Play Store app.
- Tap your profile picture → Payments & subscriptions → Subscriptions.
- Select ITweet and tap Cancel subscription.
Cancelling stops future renewals; you keep paid features until the end of the period already paid for. You can also reach the same Play screen from Settings → ITweet Subscriptions → Manage. Deleting the ITweet app does not cancel a subscription — you must cancel it in Google Play.
19.4 Refunds
Refunds are decided and issued by Google Play, not by ITweet. Request one from Play → Order history → the order → Request a refund. Where Google issues a refund or reverses a charge, Google notifies us and the associated entitlement is revoked automatically. Repeated refund abuse may result in loss of access to paid features.
19.5 Retention of billing records
Purchase tokens, order IDs, and entitlement history are retained for as long as your account is active and afterwards for the period required by tax, accounting, and anti-fraud law. They are never used for advertising and are not shared with third parties except our payment and tax obligations require it.
ITweet is a single app made of many features, and each one touches a different slice of your information. This section walks through them so you can see exactly what a feature does before you use it. Features you never open generally process no data about you beyond what is needed to keep your account signed in.
20.1 Posts, Tweets, and Threads
The core of ITweet is short-form posting: text, images, links, and polls. When you publish, we store the content, its media, the time, your audience setting (public, followers, close friends), and any hashtags or mentions we parse from it. Engagement counters — likes, replies, reposts, bookmarks, views — are stored against the post. If you edit a post within your plan's edit window, we keep the revision history so readers can see that it was changed.
20.2 Reels and the Reel Editor
Reels are short vertical videos with an in-app editor supporting trimming, layered clips, audio tracks, text, stickers, effects, and drafts. Draft projects are saved so you can resume them, including the edit graph and any media you imported; encrypted local autosave protects work in progress. Once published we store the rendered video, its thumbnail, caption, audio attribution, and watch metrics such as completion rate and rewatches — these drive Reels ranking and creator analytics.
20.3 Stories
Stories are ephemeral posts that expire after 24 hours. We keep the viewer list while the Story is live so you can see who watched, and the media itself moves to your private Archive afterwards unless you disable archiving. Close Friends lists, hide-story-from lists, and story replies are all stored as part of this feature.
20.4 Direct Messages and Calls
Messaging supports one-to-one and group chats, reactions, replies, media, voice notes, disappearing messages, and message requests from people you do not follow. One-to-one chats can be end-to-end encrypted, in which case ITweet cannot read the content (see section 9). Voice and video calling uses peer-to-peer media where possible; we store call metadata (participants, start and end time, outcome) but not call audio or video. Typing indicators and read receipts are transient and can be switched off in chat settings.
20.5 Home, For You, Explore, and Search
Your Home feed mixes accounts you follow with recommended content. Explore, Trending, and Reels recommendations are built from what you engage with, how long you dwell on items, what you skip, your search history, and coarse interest labels derived from that behaviour. Search stores recent queries on your device and, where enabled, in your account so results improve. Every recommended item carries a "Why am I seeing this?" explanation, and personalisation signals can be turned off individually under Settings → Personalisation.
20.6 Profiles, Multi-Account, and Presence
Your profile holds your name, username, bio, links, avatar and frame, category, and follower graph. Multi-account lets you keep several signed-in accounts on one device; sessions are kept separate and switching does not merge their data. Online status and last-seen are optional presence signals you control in privacy settings.
20.7 Notifications
Push notifications require a device token registered with Firebase Cloud Messaging. Preferences are granular — likes, replies, follows, mentions, messages, live, and product updates can each be silenced. Web push uses the browser's push service. Removing the app or revoking permission stops delivery and the token is cleaned up.
20.8 Creator Tools, Boosts, and Ads
Creator dashboards show reach, retention curves, audience composition, and earnings. Boosting a post or Reel creates a campaign record with your targeting choices, budget, and delivery results. Business profiles gain contact actions and category information that is public by design.
20.9 Safety, Wellbeing, and Security Features
Blocking, muting, restricting, comment filters, hidden words, close friends, and private-account mode all shape who can reach you. Time Management shows your usage and can nudge you to take breaks. The Security Centre lists active sessions and login activity, supports two-step verification, trusted devices, backup codes, and IP allow-lists. Device integrity checks (Play Integrity) help us detect tampered clients and automated abuse.
20.10 Location and Maps
Precise location is never collected in the background. If you tag a place or open Map View, we use location only for that action and only with your permission. Coarse, IP-derived region is used for legal compliance, language defaults, and fraud detection.
An account can end in three ways: you deactivate it, you delete it, or we terminate it for violating our rules. Each has a different data outcome and a different path back.
21.1 Deactivation
Deactivation hides your profile, posts, Reels, comments, and likes from everyone. Nothing is deleted. Logging back in restores the account exactly as it was, at any time.
21.2 Deletion
Deletion starts a 30-day grace period during which the account is invisible but recoverable simply by logging in. After 30 days, deletion becomes permanent: profile data, posts, Reels, Stories, messages you sent, and media are removed from live systems and purged from backups on the normal rotation. Records we are legally required to keep — transaction and tax records, enforcement records for severe violations, and material preserved under legal process — survive deletion for the period the law requires. Usernames are not recycled immediately.
21.3 Termination by ITweet
We terminate accounts for serious or repeated violations: child safety, terrorism, non-consensual intimate imagery, credible threats, coordinated fraud, mass spam, ban evasion, or repeated infringement. Termination decisions that follow an automated flag receive human review before the account is removed. You are notified in the app and by email with the policy involved.
21.4 Appeals and recovery
- Open the app and sign in — terminated accounts land on an Account Status screen showing the reason and an Appeal button.
- Appeals are reviewed by a person, wherever feasible a different reviewer than the one who made the original decision.
- Successful appeals restore the account and its content in full; we notify you and the strike is cleared.
- Appeals for child-safety and terrorism removals are reviewed but almost never reversed.
- Creating a new account to evade a termination is itself a violation and results in removal of the new account.
While an appeal is pending we keep the account's data intact so it can be restored. If the appeal fails or the appeal window closes, the account enters the same permanent-deletion pipeline described above. Users in India may escalate to our Grievance Officer, and further under the DPDP Act 2026 and IT Rules.
21.5 Lost access rather than termination
If you simply cannot sign in — forgotten password, lost phone, compromised account — that is recovery, not termination. Use email or SMS OTP, a trusted device, or a backup code; see the Account Recovery guide.
Online abuse is not distributed evenly. Women, and especially women who are visible — creators, journalists, activists, students with a public profile — receive a disproportionate share of harassment, stalking, sexualised abuse, and coordinated pile-ons. We do not treat this as an unavoidable cost of being online. It is a product problem, and we build against it deliberately.
22.1 Our commitments
- Non-consensual intimate imagery is removed on first report, without waiting for a second signal, and the account that posted it is terminated. Hashes of removed material prevent re-upload anywhere on ITweet.
- Sextortion and threats to publish images are treated as emergencies and escalated to a specialist queue, with law-enforcement referral where a person is at risk.
- Sexualised deepfakes of real people are prohibited outright, whether or not they are labelled as synthetic.
- Doxxing — publishing a phone number, address, workplace, college, or ID — is removed and treated as a severe violation because of how directly it enables offline harm.
- Stalking behaviour, including repeated unwanted contact from new accounts, is detected through device and integrity signals so that blocked people cannot simply start again.
22.2 Controls in your hands
Safety that depends on reporting after the fact is not enough, so we give you controls that stop abuse before you ever read it:
- Private account — approve every follower, and keep posts, Stories, and follower lists invisible to everyone else.
- Message controls — restrict DMs to people you follow, send everything else to a request folder, and block media in requests so unsolicited images never render.
- Hidden words and comment filters — automatically hide comments and requests containing slurs, sexual terms, or your own custom word list.
- Restrict — quietly limit an account without alerting them, useful when blocking would escalate a situation with someone you know offline.
- Block, mute, and bulk block — including removing a follower without them being notified.
- Close Friends and hide-story-from — control precisely who sees your Stories.
- Presence controls — turn off online status, last seen, and read receipts so no one can track when you are on the app.
- Location off by default — we never collect precise background location, so your movements are not inferable from ITweet.
- Security Centre — two-step verification, trusted devices, backup codes, active-session review, and immediate sign-out-everywhere if a partner or stranger has had access to your phone.
22.3 How reports about gender-based abuse are handled
Reports involving intimate imagery, sexual harassment, threats, or stalking are routed to a priority queue rather than the general backlog. Reporting is confidential — the reported account is never told who reported them. You do not have to keep the abusive content visible while you report it: mute, restrict, or block first, then report; the content is preserved on our side for review even if you never see it again. Where content is removed, we also look at the reporting user's recent interactions to identify coordinated pile-ons rather than treating each abusive account as an isolated incident.
22.4 Working with the law
In India we operate under the IT Rules and the DPDP Act 2026, including the requirement to remove non-consensual intimate imagery expeditiously once notified. We preserve evidence when a user tells us they intend to file a police complaint, and we respond to valid legal process from law enforcement investigating harassment, stalking, or sexual offences. Emergency requests involving a risk of death or serious physical harm are handled outside normal hours.
22.5 If you are being harassed right now
- Block the account and, if there are several, switch your profile to private.
- Report the content — screenshots help but are not required; report the original post or message.
- Turn on two-step verification and review active sessions in the Security Centre.
- Preserve evidence before deleting anything if you may go to the police.
- In India, contact 1091 (Women's Helpline) or 1930 (cybercrime), and file at cybercrime.gov.in.
We would rather over-react to a safety report than politely under-react. If you feel a decision of ours got this wrong, appeal it — those appeals are read.
We keep information only as long as we need it for the purpose it was collected, plus any period the law requires. "Deleted" in ITweet means removed from live systems immediately and purged from backups on the next rotation — not instantly erased from every disk on earth, which no system can honestly promise. The table below is our working standard.
23.1 Deleted posts, Reels, and Stories
When you delete a post, Reel, or comment it disappears from your profile, feeds, search, and everyone else's app immediately. The underlying row is soft-deleted first so that an accidental deletion can be reversed for a short window and so any open moderation report or appeal about that content can still be reviewed fairly. Soft-deleted content is hard-deleted within 30 days. Media files are removed from origin storage at the same time; cached copies on CDN edges expire within 24–48 hours. Stories expire automatically after 24 hours and, if archiving is on, move to your private Archive which only you can see — deleting from the Archive follows the same 30-day path. Content that was removed by us for a severe violation is not deleted on this schedule: we retain a hash and a minimal enforcement record so the same material cannot be re-uploaded, and so repeat behaviour is visible to reviewers.
23.2 Deleted accounts
Deleting an account starts a 30-day grace period: the account is invisible to everyone but fully recoverable by logging back in. On day 31 the account enters permanent deletion. Profile fields, posts, Reels, Stories, drafts, bookmarks, follows, likes, notifications, and the messages you sent are removed from production databases within 90 days of the grace period ending — the gap between 30 and 90 days exists because deletion cascades through media storage, search indexes, recommendation stores, and analytics pipelines rather than a single table. Content that is inherently shared, such as a message you sent to someone else's inbox, is detached from your identity but may remain in that recipient's copy of the conversation.
Some records outlive account deletion because we are legally obliged to keep them: purchase and tax records (typically 8 years under Indian accounting law), records of severe enforcement action, material preserved at the request of law enforcement, and information needed to defend a legal claim. These are stored in restricted systems, not used for any product purpose, and deleted when the obligation ends.
23.3 Server and application logs
- Request and edge logs (IP, timestamp, endpoint, status, user agent): 30 days.
- Application and error logs, including crash reports: 90 days.
- Authentication and login activity (device, approximate location, time): 12 months, because you need to be able to review your own account history and because it is our primary defence against account takeover.
- Security, abuse, and integrity logs — ban evasion signals, rate-limit trips, fraud detection: up to 18 months.
- Aggregate analytics with identifiers stripped: retained indefinitely, since it is no longer personal data.
Logs are access-controlled, and we do not mine them for advertising. Where a log entry is caught up in an active investigation or legal hold, it is retained until that matter closes.
23.4 Backups
We take encrypted backups so that a hardware failure or a bad deploy cannot cost you your account. Point-in-time recovery snapshots are kept for 7 days; daily backups for 30 days. Backups are write-once by design — we cannot surgically edit a single row out of a snapshot without destroying its integrity as a recovery artifact. That means deleted data can persist inside a backup until that backup ages out, at most 30 days after deletion, after which the snapshot is destroyed and the data goes with it. Backups are encrypted at rest, stored separately from production, restricted to a small set of operators, and are never used to serve product features, analytics, or advertising. If a backup ever had to be restored, we re-apply the deletion queue immediately afterwards so anything you deleted stays deleted.
23.5 Everything else
- Search history: until you clear it, and automatically after 12 months.
- Recommendation and interest signals: rolling 12-month window; cleared immediately if you turn personalisation off.
- Conversation-derived signals: 90 days, and never the raw message text.
- Support tickets and bug reports: 24 months.
- Push notification tokens: until the app is removed or the token is invalidated.
You can export or delete your data at any time from Settings → Account Management.
ITweet offers Creator and Business profiles for people and organisations that use the platform commercially. These accounts get category labels, contact actions, analytics, boosting, external links, and — where eligible — monetisation. With those tools comes a clear allocation of responsibility, and this section sets it out plainly so that neither you nor the people who buy from you are left guessing.
24.1 What a Business profile is
A Business profile is a public commercial presence. Your category, contact buttons, website link, and business information are visible to anyone, including people who are not logged in and search engines that index public pages. Do not put information on a Business profile that you would not publish on a billboard. Switching an account to Business or Creator makes some previously optional fields public by design; you can switch back at any time from Settings → Account Type.
24.2 Businesses are responsible for their own products and services
ITweet is a communications platform, not a merchant, marketplace operator, distributor, escrow agent, or guarantor. When a business posts about a product, takes an order over DM, links to its own website or a third-party checkout, runs a giveaway, offers a service, or advertises a price, that entire commercial relationship exists between the business and the customer. ITweet is not a party to it.
The business alone is responsible for: the accuracy of its product descriptions, pricing, and availability; the quality, safety, legality, and fitness for purpose of what it sells; delivery, fulfilment, and shipping; warranties, returns, refunds, cancellations, and after-sales support; invoicing, GST and other tax compliance; licensing and regulatory permissions for regulated categories such as food, cosmetics, health services, financial products, education, travel, and alcohol; consumer-protection and advertising-standards compliance; and the lawful handling of any customer data it collects.
24.3 Third-party transactions and external links
Links in bios, posts, Stories, and messages frequently lead off ITweet — to a website, a payment page, a UPI collect request, a form, or another app. Once you leave ITweet you are on someone else's property, governed by their terms and their privacy policy. ITweet does not process, hold, verify, or insure payments made through external links or off-platform arrangements, and is not responsible for third-party transactions initiated through business profiles or external purchase links. We cannot reverse such a payment, adjudicate a dispute over it, or compensate a loss arising from it. The only payments ITweet is involved in are in-app purchases made through Google Play Billing (section 19), and even there refunds are Google's decision.
This is not a technicality — it is the single most common way people are defrauded on social platforms. Before paying anyone you met through ITweet: check the account's age and history, be suspicious of pressure and time limits, refuse "advance fee" and "processing charge" requests, never share an OTP, and prefer payment methods that offer buyer protection. Anyone promising ITweet badges, verification, followers, or account recovery in exchange for money is running a scam. Report them.
24.4 Advertising, sponsorship, and disclosure
Paid partnerships, barter deals, affiliate links, and gifted products must be disclosed clearly and in a way an ordinary viewer would notice — not buried in a hashtag wall. Follow the applicable advertising code in your country; in India, the ASCI influencer guidelines apply. Health, financial, and earnings claims attract particular scrutiny, and unsubstantiated claims may be removed regardless of disclosure. Ads and boosted posts additionally go through our ad review process and must comply with the Prohibited Content rules in section 18.
24.5 Customer data a business collects
If you gather customer information through ITweet — addresses over DM, order details, phone numbers from a lead form — you are the controller of that data under the DPDP Act 2026 and any other applicable law. You must have a lawful basis for collecting it, use it only for the purpose you collected it for, keep it secure, honour deletion requests, and not sell it or add people to marketing lists without consent. ITweet's role is limited to transmitting the message.
24.6 Monetisation and payouts
Where creator monetisation is available, eligibility depends on standing, authenticity, and compliance with our policies. Earnings figures shown in the dashboard are estimates until settled. Payouts require verified identity and tax details; incorrect details are the account holder's responsibility. Fraudulent engagement, artificially inflated metrics, and reused or infringing content result in demonetisation and clawback of amounts already paid.
24.7 Enforcement and indemnity
Business and Creator accounts are held to the same Community Guidelines as everyone else, and to the commercial rules above. Breaches can lead to loss of boosting, loss of monetisation, removal of external-link privileges, or termination. To the extent permitted by law, a business using ITweet agrees to indemnify ITweet against claims arising from its own products, services, transactions, advertising, or handling of customer data. Nothing in this section limits a consumer's rights against that business under applicable consumer-protection law.
You own your content. Nothing in this policy or in the Terms of Use transfers ownership of your posts, Reels, Stories, photographs, videos, audio, captions, comments, or messages to ITweet. You keep every copyright, moral right, trademark, and other intellectual property right you had before you posted, and you remain free to publish the same work anywhere else, sell it, licence it exclusively to someone else, or delete it here.
What we do need is permission — a licence — because a hosting service physically cannot function without one. To show your photo to a follower, our servers must copy it, resize it, transcode it, cache it on a CDN near that follower, and display it. Every one of those acts is legally a reproduction or a communication to the public. Without a licence, running the app would infringe your copyright thousands of times a day. So the licence below exists to let us operate the service you asked us to operate — nothing more.
25.1 The licence you grant
By posting content on ITweet you grant ITweet a non-exclusive, royalty-free, worldwide, transferable and sub-licensable licence to host, store, cache, reproduce, transcode, resize, reformat, adapt for display, publish, publicly perform, publicly display, and distribute your content, and to create derivative works strictly to the extent technically necessary for those purposes (for example generating thumbnails, preview clips, captions, low-bandwidth variants, and search indexes).
- Non-exclusive — you can licence the same work to anyone else, at any time, on any terms.
- Royalty-free — we do not pay you for the licence itself. Separate monetisation programmes, where you are eligible, are how you earn from content.
- Worldwide — because your followers are.
- Transferable and sub-licensable — solely so we can use infrastructure providers (cloud hosting, CDNs, transcoding, media storage) and so content can pass through a corporate reorganisation. It is not permission to sell your work to a third party for their own use.
25.2 Scope — what the licence is limited to
The licence is limited to operating, providing, securing, and improving the Serviceand to promoting the Service itself. Concretely, that means: delivering your content to the audience you selected; ranking it in feeds, Explore, Reels, and search; letting others share, repost, embed, or quote it in the ways the product allows; generating thumbnails and previews for link cards; captioning and translating; enforcing our policies; and, for public content, featuring it in ITweet's own promotional materials.
The licence does not permit us to sell your content to third parties for their advertising or commercial use, to place your content in a third party's advertisement without your agreement, or to use your face or voice as an endorsement without your consent. We do not claim ownership, and we do not assert a right to prevent you from using your own work.
25.3 Audience matters
The licence follows the privacy setting you chose. Content posted to a private account or to Close Friends is licensed only for delivery to that restricted audience — we will not surface it publicly, feature it in promotion, or index it for search. End-to-end encrypted messages are outside the licence in any practical sense: we transmit ciphertext we cannot read.
25.4 When the licence ends
The licence ends when you delete the content or delete your account, subject to three realistic caveats: (a) removal from live systems is immediate but CDN caches take up to 48 hours to expire; (b) copies inside encrypted backups persist until the backup rotates out, at most 30 days (section 23.4); and (c) where someone else lawfully reshared, reposted, or downloaded your public content before you deleted it, we cannot retrieve their copy, and the licence continues for those existing shares. Content we retain for legal or safety reasons — an enforcement hash, a preserved record — is kept under those obligations rather than under this licence.
25.5 Your warranties
By posting, you confirm that you own the content or have all necessary rights to it — including rights to any music, footage, images, fonts, or text you incorporated — and that publishing it does not infringe anyone's copyright, trademark, privacy, or publicity rights. Do not post other people's work without permission, and do not post images of people in private settings without their consent.
25.6 Copyright complaints
Rights holders can report infringement through the in-app report flow or to our Grievance Officer. Valid notices result in removal, and the uploader is notified and may submit a counter-notice. Repeat infringers lose their accounts. Fair dealing, commentary, criticism, review, parody, and news reporting are considered before removal where the claim is arguable.
25.7 Feedback
Suggestions and feature ideas you send us are treated as non-confidential; we may implement them without obligation or compensation. This does not affect the ownership of your posted content.
ITweet uses automated systems throughout the product. We use them for four main purposes:
- Recommendations — ranking your Home and For You feeds, Reels, Explore, suggested accounts, and search results based on what you engage with, dwell on, skip, follow, and search, plus content similarity computed from embeddings.
- Spam and abuse detection — classifying bot accounts, engagement farms, mass duplicate posting, phishing links, scam patterns, and ban evasion using behavioural and device-integrity signals.
- Trending and discovery — detecting which topics, hashtags, sounds, and posts are rising, with de-amplification of manipulated or borderline trends.
- Safety enforcement — flagging content that may violate our policies for removal, age-gating, reduced distribution, or human review, and matching against hashes of previously removed material.
Automation operates at a scale humans cannot match, and it makes mistakes. Decisions with significant consequences — account termination, monetisation removal, permanent restriction — involve human review before or immediately after they take effect. You can appeal any automated outcome from Settings → Account Status and ask for a person to look at it. You can also switch off personalisation signals individually under Settings → Personalisation, in which case your feed falls back to chronological and popularity-based ranking, and every recommended item carries a "Why am I seeing this?" explanation.
We protect your data with layered technical and organisational controls. Without disclosing details that would help an attacker, these include:
- Encryption in transit — TLS for all client-server and service-to-service traffic, with modern cipher suites and certificate pinning on the mobile app.
- Encryption at rest — databases, media storage, and backups are encrypted on disk.
- Password hashing — passwords are stored only as salted hashes using a slow, memory-hard algorithm. We never store, log, or email a plaintext password, and we cannot recover one for you.
- Row-level authorisation — data access is enforced at the database layer, not just in application code, so a bug in one screen cannot expose another user's rows.
- Rate limiting and abuse throttling on authentication, OTP issuance, messaging, and write endpoints to blunt credential stuffing, enumeration, and spam.
- Account security features — two-step verification, backup codes, trusted devices, IP allow-lists, active-session review, login alerts, and sign-out-everywhere.
- Device integrity signals to detect tampered or emulated clients and automated abuse.
- End-to-end encryption for eligible one-to-one messages, where keys never leave your devices (section 9).
- Least-privilege access for staff, with authentication requirements and audit logging on administrative actions.
- Secure development practices — dependency scanning, code review, and periodic security review of new features.
No system is perfectly secure. Use a unique password, enable two-step verification, and treat anyone asking for an OTP as an attacker. Security researchers may report vulnerabilities in good faith through the report-a-bug flow; we do not pursue research conducted without accessing other users' data.
An account is inactive if it has not been signed in to for an extended period. We may, after prolonged inactivity, reduce the visibility of the account in recommendations and search, pause notification delivery to conserve resources, and eventually reclaim the username so it becomes available to others. Where required or appropriate, we will notify the registered email address before taking a step that cannot be undone, and give you a chance to sign in and keep the account.
We may also remove accounts that were never completed at registration, accounts created solely to reserve a username, and accounts inactive for a period long enough that continuing to store their personal data would conflict with storage-limitation principles. Simply opening the app and signing in resets inactivity. Paid subscriptions continue to bill through Google Play regardless of inactivity until you cancel them (section 19).
We use aggregated and de-identified data to understand how ITweet is used and to make it better: which features are adopted, where people drop out of a flow, how fast screens load, how often a safety control is used, and whether a change improved or worsened the experience. This includes A/B tests where a subset of accounts sees a variant of a feature, and product analytics measured at the cohort level rather than the individual level.
Data used for research is stripped of direct identifiers and reported only in aggregate. We do not publish anything that could identify you, and we do not use the content of end-to-end encrypted messages for research of any kind. Where we work with academic or safety researchers, access is limited to aggregated statistics under confidentiality terms. If you have opted out of personalisation, your behavioural signals are not used to train recommendation models; basic aggregate reliability and performance metrics still apply because they carry no personal data once aggregated.
We maintain monitoring, logging, and an incident response process to detect and contain security incidents. If a personal data breach occurs that is likely to result in a risk to your rights and interests, we will notify affected users and the relevant supervisory authority as required by applicable law — including the Digital Personal Data Protection Act 2026 and the CERT-In directions in India, and the GDPR's 72-hour authority notification requirement where it applies.
Notifications will be sent to your registered email address and shown in the app, and will describe in plain language what happened, what categories of data were affected, what we have done to contain it, what we recommend you do (for example changing your password and reviewing active sessions), and how to contact us. We will publish updates as an investigation progresses rather than waiting for a complete picture. We will never ask for your password or an OTP in a breach notification — any message that does is a phishing attempt.
