bangers & bash

bangers@bash:~/privacy

Your writing. Your data.

bangers & bash supports local writing and private account access. Settings identifies which storage mode this installation uses. The invited founder pilot can connect X and enable budgeted post analytics. Scheduled delivery and automatic timing are not enabled. Manual publication requires a separate permission upgrade; payment testing uses Stripe test mode.

What is saved

When signed in, your verified email, session records, drafts, planned posts, preferred handle and wallpaper choice are stored by the app in Cloudflare D1. Without account mode, writing and manual observations stay in browser storage. A saved handle is not an authenticated X account.

What leaves your browser

Account mode sends your writing to the app server when you save. Sign-in uses an HttpOnly session cookie, and the configured email provider receives your email address to deliver sign-in codes. Hosted email delivery uses Resend. Failed changes may be kept in this tab’s session storage so you can recover them. The app sends no writing to an AI provider. When you choose Publish now, the reviewed post text, selected images and their descriptions are sent to X. Stripe receives account and subscription identifiers and your email for checkout; it does not receive drafts. Opening a link to X takes you to a separate service governed by its privacy policy.

Your desktop and notes

Notes uses the same drafts as the main app and saves nonempty writing automatically. In account mode, notes are saved to your account; in local mode, they stay in this browser. Unsaved note text may be kept in this tab’s session storage for recovery. Light/dark appearance and window positions are stored on this device. Unfinished compose text and selected image references are kept in browser storage, separately by account and tab, for recovery. Save draft syncs that writing to your account; clearing browser storage removes device recovery. Wallpaper choices follow your workspace’s storage mode.

Scheduled delivery

A confirmed schedule stores its exact text, image references, delivery window, timezone and protection choice in your account. A server job can publish it while your browser is closed. You can cancel before sending begins. Failed or uncertain deliveries remain visible for review; an uncertain response is never automatically resent.

Connecting X

The private founder pilot uses X OAuth to verify your X user ID, handle, display name, profile photo URL and subscription type. Subscription type determines long-post eligibility. Profile photos load from X’s image CDN without a referring page URL. You authorize read access and ongoing access on X; the app never asks for your X password. Access and refresh tokens are encrypted in Cloudflare D1 with a separate server secret. When you start checks, the app imports up to 30 posts from the last seven days, excluding replies and reposts, then checks up to ten recent posts. During the bounded founder research window, checks adapt between five and fifteen minutes; otherwise checks run hourly. Post text, timestamps and returned impression, like, reply, repost and quote counts are stored in D1. Missing metrics stay unavailable. The app requests tweet.write and media.write only when you choose to enable text and image publishing. Publication attempts and X receipts are saved separately so interrupted requests are not blindly repeated.

When account snapshots are enabled, we save one daily follower count and available following/post totals, with the observation time. Daily account snapshots are kept for up to 90 days, included in the workspace export, and removed from the active database on disconnect. We do not collect the full follower list. Net growth cannot identify which post caused a follow or reconstruct earlier follower history.

Disconnect in Settings to remove the stored tokens and cancel pending connection attempts, pause collection, and delete collected posts and observations from the active database. The app also asks X to revoke access; if that request fails, remove the app in your X account settings. The verified user ID and last known profile remain linked to your account to prevent reconnecting the wrong account. Contact alex@arclabshq.com for account removal during the private pilot.

Export and removal

Export saved writing and collected X observations in Settings. Image attachments are represented by account-specific references; the export does not include image files. Keep your source files separately. Remove drafts and queue entries from their screens; Undo is available immediately afterward. In account mode these changes update the server. Clearing browser storage does not delete a server account. Whole-account deletion and the hosted retention policy must be completed before customer onboarding. Export anything you want to keep before clearing local storage.

Previous workspace data

Previous local storage is preserved. When moving into an account, review and select the writing you want to import. Imported dates are planning information; they do not enable publication. Generated post metrics and publication records are not carried into account analytics. Importing a writing export merges drafts and queue entries without connecting an X account.

Collection retention and feedback

Collection keeps at most 30 days of post observations in the active database; scheduled maintenance removes older records. Disconnect removes collected post data immediately from the active database. Backups may retain prior data until the hosting provider’s recovery window expires; deletion must be reapplied after a restore. Feedback stores only the text you submit, the page path and server release, linked to your account. Draft content, screenshots and credentials are not attached automatically. When image storage is enabled, images you add are uploaded to private Cloudflare R2 storage, with descriptions and ownership stored in D1. Only your authenticated account can retrieve them. Your library keeps up to 20 images, each up to 5 MB. Remove unused images in Compose; images referenced by saved writing or an unconfirmed publication must be detached or resolved first. Disconnecting X does not remove your writing or image library. Contact alex@arclabshq.com for full account and image removal.

Inquiries and billing

Early-access and enterprise forms store the email, company, and message you submit for founder review. A salted daily network identifier limits repeated requests; raw IP addresses are not stored by the form. Stripe processes checkout and subscription management; card details are entered on Stripe and never stored by this app. Publication receipts and inquiries remain until account removal or an explicit removal request to alex@arclabshq.com. Disconnecting X removes collected analytics, but retains publication receipts to prevent duplicates.

Before connected accounts launch

OAuth permissions, hosting providers, retention periods, token security, account deletion, support contact and billing disclosures must be finalized before this product accepts connected customers.

Data settings