Privacy Policy
Version 1.3 · Last updated: 06/09/2026
1. Data Controller
| Field | Data |
|---|---|
| Controller | BAIXOSAMA INVERSIONES, SL |
| Tax ID | B27854181 |
| Address | Rua Condesa Casa Barcenas, 11, 36204 Vigo, Pontevedra |
| Contact email | admin@twinyx.app |
| Website | https://twinyx.app |
For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Spanish Organic Law 3/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights ("LOPDGDD"), the data controller for your personal data is the entity indicated above.
2. Data We Collect
2.1 Registration and account data
- Email address
- Password (stored as a bcrypt hash, never in plain text)
- Preferred language
- Registration date
2.2 Telegram data
- Telegram username and ID (obtained when connecting the bot)
- Telegram Business connection identifier (used to route messages)
2.3 Messages and conversations
- Private messages received and sent through your Telegram account while the service is active
- Conversation history with metadata (sender, date, processing status)
- AI-generated intent classifications
2.4 Service configuration
- Personality context and digital clone instructions
- Example messages provided by you
- Response categories and templates
- Schedules, speed preferences, and bot configuration
- Blocked/allowed/handed-off user lists
2.5 Screenshots (transient processing)
- Images voluntarily uploaded for writing style analysis
- Images are NOT stored: they are processed in RAM, sent to the Google Gemini API for analysis, and immediately discarded
- Only the resulting analysis text (writing style description) is stored
- The system is configured to NOT extract real names, phone numbers, emails, URLs, or any personally identifiable information. Only synthetic examples of writing style are generated.
2.6 Payment data
- Twinyx does NOT store credit card or banking information
- Payments are managed entirely through Stripe, Inc.
- We only store: Stripe customer ID, Stripe subscription ID, subscription status, and period dates
2.7 Technical data
- IP address (in server logs)
- Browser type and browser language
- Anonymized web analytics data (through self-hosted Umami, no cookies)
2.8 Referral data
- Referral code (randomly generated, not personally identifiable information)
- Referrer user ID (if you registered through a referral link)
- Referral conversion status and timestamps
- Milestone achievements
2.9 Push notification tokens
- Technical identifiers generated by your browser or mobile operating system when you enable push notifications for the Service
- Allow delivery of Service alerts to your device
- Automatically removed when they cease to be valid or when you disable notifications from the dashboard or your device settings
2.10 Marketing consent
- Status of your consent (active or withdrawn) to receive commercial communications by email
- Date when this consent was granted or withdrawn
3. Purpose and Legal Basis for Processing
| Purpose | Legal basis (Art. 6 GDPR) | Data involved |
|---|---|---|
| Provision of the contracted service | Performance of contract (Art. 6.1.b) | Registration, Telegram, messages, configuration |
| Payment and subscription management | Performance of contract (Art. 6.1.b) | Email, payment data via Stripe |
| Screenshot analysis | Explicit consent (Art. 6.1.a) | Voluntarily uploaded images |
| Service notifications | Performance of contract (Art. 6.1.b) | Email, Telegram Bot |
| Security and fraud prevention | Legitimate interest (Art. 6.1.f) | IP, technical data |
| Aggregated web analytics | Legitimate interest (Art. 6.1.f) | Anonymized browsing data |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c) | Billing data |
| Referral tracking and reward distribution | Legitimate interest (Art. 6.1.f) | Referral code, referrer-referee relationship, milestones |
| Delivery of Service push notifications | Contract execution (Art. 6.1.b) | Push notification token |
| Sending commercial communications | Consent (Art. 6.1.a) | Email, marketing consent |
4. Data Processing by Artificial Intelligence
4.1 Automatic response generation
The service uses third-party language models (LLMs) to generate responses that mimic your communication style. Data sent to these models includes:
- Your personality context and example messages
- Recent conversation history with each contact
- Response categories you have configured
Every contact who receives a reply generated this way is told beforehand, inside the conversation, that they may be talking to an artificial intelligence assistant. See section 14.
4.2 Screenshot analysis (Vision AI)
When you upload screenshots, they are processed using Google Gemini Vision to extract exclusively writing style characteristics (tone, emoji usage, typical length, vocabulary). The system is configured to NOT extract real names, phone numbers, emails, URLs, or any personally identifiable information. Only synthetic examples of writing style are generated.
Google processes these images in accordance with its Data Processing Addendum and the Gemini API Additional Terms.
4.3 Automated decisions
The service makes automated decisions about:
- Whether or not to respond to a message (intent classification)
- Whether to hand off the conversation to the creator (purchase intent detection)
- The category of each received message
- Automated filtering of messages considered spam or unwanted, which may not receive a response from the Service
These decisions do not produce legal effects on the user's contacts. The creator can review and modify any decision from the dashboard.
5. Data Processors (Third Parties)
We share data with the following providers, all of which have GDPR-compliant data processing agreements:
| Provider | Service | Shared data | Location | Safeguards |
|---|---|---|---|---|
| Stripe, Inc. | Payments and subscriptions | Email, payment data | USA | Data Privacy Framework (DPF) |
| Google LLC (Gemini API) | Language processing and Vision AI | Messages, context, screenshots | USA | Data Privacy Framework (DPF) |
| OpenAI, Inc. | Language processing (alternative) | Messages, context | USA | Standard Contractual Clauses (SCCs) |
| Telegram | Messaging platform | Messages (through the user's session) | Various | Connection uses the user's own credentials |
| Langfuse | LLM observability platform | Prompts sent to the LLM, generated responses, conversation identifiers, token usage | Self-hosted (own infrastructure) | Legitimate interest (Art. 6.1.f) to improve service quality |
| MailerSend | Transactional email service | Email address, user name, email content (verification, password reset, notifications) | USA | Contract execution (Art. 6.1.b) |
| MailerLite | Email marketing and subscriber list management | Email, preferred language, subscription status | EU / USA | Data Privacy Framework (DPF) |
| ipapi.co | IP-based geolocation to determine pricing region | IP address | USA | Standard Contractual Clauses (SCCs) |
| Google LLC (Firebase Cloud Messaging) | Delivery of push notifications on mobile applications | Push notification token, device identifier | USA | Data Privacy Framework (DPF) |
Note: When logging in via Google OAuth or Telegram Login, these providers share basic authentication data (email, name) with Twinyx in accordance with their own privacy policies.
Note on AI providers: Only one LLM provider is used at a time, configurable by the system administrator. Message data is sent to the active provider to generate responses and is not retained by these providers beyond request processing, in accordance with their respective data processing agreements.
6. International Data Transfers
Some of our data processors are located in the United States. These transfers are covered by:
- Data Privacy Framework (DPF): For providers certified under the EU-US Data Privacy Framework (European Commission adequacy decision of July 10, 2023).
- Standard Contractual Clauses (SCCs): For providers not certified under DPF, in accordance with European Commission Decision 2021/914.
7. Data Retention
| Data type | Retention period | Deletion method |
|---|---|---|
| User account | While the account is active + 30 days after cancellation request | Database deletion |
| Password (hash) | While the account is active | Deleted with the account |
| Business connection ID | While the connection is active | Deleted on disconnect or account deletion |
| Message history | Up to 365 days old; also capped at the most recent 50 (Starter) or 200 (Pro) messages per contact | Automatic purge (by age and per-contact cap); fully deleted with the account |
| AI interaction notice record | While the creator's account is active (one row per contact: identifier, date and a copy of the text sent) | Deleted with the account or with the Telegram connection |
| Screenshots | Seconds (RAM only) | Automatic discard after processing |
| Extracted style text | Until the user deletes it or closes their account | Self-service or account deletion |
| Subscription data | Per tax obligations (minimum 4 years under Spanish law) | Deletion after legal period |
| Server logs | 90 days | Automatic rotation |
| Analytics data | Anonymized, indefinite | Not linkable to user |
| Consent records | 5 years from the last update | Deletion after legal period |
| Referral codes | Indefinite (non-PII) | Not linkable to individual |
| Referral records | While account is active + cascade on deletion | Deleted with the account |
| Milestone records | While account is active + cascade on deletion | Deleted with the account |
7.1 Data in Multiple Telegram Accounts
If you connect multiple Telegram accounts to your Twinyx account (available for Pro users), data for each Telegram account is stored in isolation. This includes conversation history, categories, excluded contacts, and settings. Data retention policies apply per account: when you remove a connected Telegram account, only the data associated with that account is deleted.
8. User Rights
Under the GDPR and LOPDGDD, you have the right to:
- Access: Request a copy of all your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): Request the deletion of your data when it is no longer necessary.
- Restriction of processing: Request the restriction of the use of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Withdrawal of consent: Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Not to be subject to automated decisions: Request human intervention in decisions that significantly affect you.
How to exercise your rights
Send an email to admin@twinyx.app stating:
- Your full name and registration email
- The right you wish to exercise
- Documentation proving your identity (ID/passport)
We will respond within a maximum of 30 days. If you believe we have not properly addressed your request, you can file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
9. Data Security
We implement the following technical and organizational measures:
- Passwords protected with bcrypt (12 rounds of hashing)
- Communications encrypted with TLS/HTTPS
- Signature verification on Stripe webhooks
- Parameterized SQL queries to prevent injections
- Server-side input validation with Zod
- Uploaded file validation (MIME type + magic bytes)
- JWT tokens with configurable expiration and automatic invalidation on password change
- Email account enumeration prevention
10. Minors
Twinyx is intended exclusively for users over 18 years of age. We do not knowingly collect data from minors. If you become aware that a minor has provided personal data, please contact us at admin@twinyx.app so we can proceed with its deletion.
11. Cookies and Similar Technologies
Please see our Cookie Policy for detailed information about the cookies and similar technologies we use, including the google_oauth_state cookie used during the Google login flow.
12. Changes to this Policy
We reserve the right to modify this policy. When we do:
- We will update the "Last updated" date at the top
- If the changes are substantial, we will notify you by email or through a notice in the service
- We will ask you to accept the new version to continue using the service
13. Contact
For any questions related to this policy or the processing of your data:
- Email: admin@twinyx.app
- Postal address: Rua Condesa Casa Barcenas, 11, 36204 Vigo, Pontevedra
14. Information for Telegram Contacts (Art. 14 GDPR)
When a contact sends a message to a creator using Twinyx, we process certain contact data to provide the auto-response service:
Data processed
- Telegram user identifier (telegram_user_id)
- Telegram username (if available)
- Content of messages sent to the creator
- Operational interaction classification (lead_temperature: cold/warm/hot)
Legal basis: Creator's legitimate interest (Art. 6.1.f GDPR) to manage their communications efficiently.
Purpose: Data is used exclusively to generate automated responses on behalf of the creator. The lead_temperature classification is an operational per-interaction categorization, not a persistent profile of the contact.
Retention: Data is retained while the creator's account is active, plus 30 days after deletion. Message history is automatically purged after 365 days and capped at the most recent 50 or 200 messages per contact depending on the plan.
AI interaction notice (Art. 50 AI Act)
Before the first automatically generated reply, we send the contact a message inside the conversation itself telling them that replies may come from an artificial intelligence assistant. The notice is sent once per contact and is active on every account: the creator can reword it, but cannot switch it off.
So the notice is not repeated on every message, we record that it was delivered: the contact's Telegram identifier, the date and time of the send, and a copy of the text delivered. That copy is kept unchanged even if the creator later edits the wording, because it is the evidence that the contact was informed and of what they were told. This data is retained while the creator's account is active and is deleted along with it.
Rights: Telegram contacts may exercise their rights of access, rectification, erasure, objection, and portability by contacting admin@twinyx.app

