1. Who is responsible
FollowSpark is a web app that lets you inspect public parts of your X graph after you sign in with X. The controller of personal data is:
Carlos Sánchez García
Apartado de Correos 40143, 28007 Madrid, Spain
hi@carlossanchez.me
2. What we process
Depending on how you use FollowSpark, we may process:
- Account identity from Sign in with X: your user id, display name, email if the identity provider supplies one, profile image, and X handle.
- Graph data you ask us to scan: public accounts you follow, public accounts that follow you, follower counts, verification flags, last original public post time, and follow-back flags.
- Technical data needed to run the service: session tokens, security cookies, and basic request logs from the host.
- First-party usage counts: page path, optional referrer, campaign tag (utm_campaign), event type (for example a scan start), a two-letter country code when the host provides one, a coarse device class (phone, tablet, desktop, bot) taken from the user-agent without storing the user-agent itself, and a daily visitor hash. The hash is derived from technical request data and is rotated each day. We do not store your IP address for this purpose. Country is used only to show aggregate stats on where the site is used. If you choose Accept all, we also set a random first-party visitor cookie so we can tell new visits from returning ones. That cookie is not an advertising identifier.
We do not ask you to upload an X archive file. We do not use the official paid X developer API. Public lists and profiles are read from publicly available X data sources. Follow-back tags use X's public guest friendship check.
3. Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b)). Sign-in, identifying your X account, running a scan you start, and showing results.
- Consent (GDPR Art. 6(1)(a)). Optional cookies and loading fonts from Google. You can withdraw this at any time via Cookie settings in the footer.
- Legitimate interests (GDPR Art. 6(1)(f)). Keeping the service secure, preventing abuse, storing a short-lived working copy of a scan so a long crawl can finish during your session, and measuring how the site is used with first-party counts (no advertising, no sale of data).
4. How long we keep it
Scan rosters are session scratch. They are replaced when you start a new scan of the same type and deleted when you sign out. They are not offered as a saved history.
Sign-in records exist so we know who is logged in. Those records last for the life of your session cookie, and are removed when you sign out, subject to short security backups on the host.
First-party usage counts are kept for up to 90 days, then deleted.
A short public-profile cache may be kept to avoid re-fetching the same public X profile during a scan. It is not a personal archive of your graph.
5. Who receives data
- Auth broker (xAI / Grok). Sign in with X is federated through the Grok auth broker. FollowSpark receives a local session. Upstream X tokens stay with the broker.
- Hosting and database. When published, the app and its identity store typically run on the Grok App Builder / Vercel stack with a Postgres database (for example Neon) for login sessions.
- X and public graph sources. We request public following and follower lists, public profiles, and guest friendship flags in order to run the scan you started.
- Google. Only if you accept optional cookies, your browser loads fonts from Google Fonts.
We do not sell your personal data.
6. Transfers outside the EEA
Some processors (including xAI, Vercel, X, and Google if you accept fonts) may be in the United States or other countries. Where GDPR applies, transfers rely on the EU-US Data Privacy Framework where the processor is certified, or on Standard Contractual Clauses plus the processor's supplementary measures.
7. Your rights
If GDPR applies, you can ask to:
- access your data
- correct inaccurate data
- erase data (including by signing out, which wipes your scan)
- restrict or object to processing
- receive a copy (data portability)
- withdraw consent for optional cookies without affecting sign-in
You can also lodge a complaint with your local supervisory authority, including the Agencia Española de Protección de Datos (AEPD).
To exercise rights, email hi@carlossanchez.me or sign out to delete the current scan and session.
8. Children
FollowSpark is not directed at children under 16. Do not sign in if you are below the digital-consent age in your country.
9. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects. Rankings in a scan (quiet accounts, audience size) are tools you requested.
10. Changes
We may update this policy when the product or the law changes. The date at the top is the current version.