bangers & bash

Privacy policy

Your writing. Your data.

bangers & bash is a product by Arc Labs. This notice explains what we collect, how it is used, and the choices you have when visiting this site or using the workspace.

Last updated September 13, 2026

Your drafts stay private.

The app does not send your writing to an AI service.

You control X access.

Connect through X and disconnect in Settings.

Take your writing with you.

Export saved writing and collected measurements.

Information we collect

Account and writing. When you sign in, we save your email, sign-in session, drafts, notes, planned posts and workspace preferences. Images you upload and their descriptions are stored privately for your account. In a local workspace, writing stays in that browser unless you choose to import it into a signed-in account. Settings shows which mode you are using.

X analytics. If you connect X and enable collection, we save your profile details, post text and timestamps, and the reach and interaction counts X returns. Where available, we also save daily follower, following and post totals. We do not collect your full follower list.

Requests and feedback. We save the email, optional company name and message you submit through our contact forms so we can respond. In-app feedback includes your message, account, page and app version. Drafts and screenshots are not attached automatically.

Connecting and posting to X

You authorize access on X; we never ask for your X password. Read access lets us verify your profile and collect available analytics. Ongoing access lets enabled checks continue between visits. Your X subscription type is used to check long-post eligibility. Connection tokens are encrypted in storage.

Publishing requires additional permission. When you choose to publish, the reviewed text, selected image and image description are sent to X. If scheduling is available for your account and you confirm a schedule, we store the content, delivery window, timezone and timing preference so it can run while your browser is closed. Drafts and unconfirmed plans do not send themselves.

We save publication attempts and confirmations to show delivery status and help prevent duplicate posts. Profile pictures load from X’s image service. Visiting X is subject to X’s own privacy policy.

Services we use

We use service providers to run the workspace, deliver sign-in codes and support the features you choose.

Cloudflare
Hosts the connected workspace, stores account and workspace records in D1, and stores uploaded images in private R2 storage.
Resend
Receives your email address to deliver sign-in codes.
X
Handles account authorization, supplies permitted analytics and receives posts you authorize for publication.
Stripe
Handles checkout and subscription management when available. It receives your email and billing identifiers, not drafts. Card details are entered on Stripe and are not stored by this app. Public paid checkout is currently closed; available payment testing uses test mode.

Our hosting services also process technical request information to deliver and protect the site. We use operational logs and usage counts to diagnose errors and manage service limits.

Cookies and device storage

Sign-in uses a session cookie. Browser storage keeps appearance and window preferences, local writing, and recovery copies of unfinished work. Signed-in notes save automatically; unfinished Compose text can remain on your device until you save it to your account.

Clearing browser storage removes local writing and recovery copies. It does not delete a server account. Export anything you want to keep first.

Contact forms use a daily changing, protected network identifier to limit repeated requests. The form does not store your raw IP address in its records.

How long data is kept

  • Post analytics: up to 30 days in the active database, with older records removed by scheduled maintenance.
  • Daily account counts: up to 90 days in the active database.
  • Writing and images: kept until you remove them or request account removal. Images still attached to saved writing or an unresolved publication must be detached or resolved before removal.
  • Account records, inquiries, feedback and publication receipts: these do not currently have an automatic expiry. Contact us to request removal. Disconnecting X keeps publication receipts to help prevent duplicate sends.

Deleting active records does not immediately erase recovery backups. Older copies may remain until the hosting provider’s recovery window expires; deletions need to be reapplied if a backup is restored.

Your choices and requests

Export. In Settings, export saved writing, collected post measurements and available account snapshots. Image references are included, but image files are not; keep your original files separately.

Disconnect X. Settings lets you stop collection, remove stored access tokens and delete collected posts and account snapshots from the active database. Pending schedules that have not begun sending are canceled. Your writing, image library, publication receipts and last verified profile remain in your account. Disconnecting does not delete posts already published on X. If X cannot confirm revocation, remove the app in your X account settings too.

Delete or correct information. You can edit or remove writing in the workspace. Whole-account deletion is not self-service at this time. Email alex@arclabshq.com for account, image or inquiry removal, a correction, or a privacy question. Include the email associated with your account or request so we can verify it belongs to you.

We will update the date above when this notice changes. For help using the product, visit Support.