Skip to main content

X API Disclosure

Effective Date: September 26, 2026

Blazium Games uses the X API only to link X to your account and let you log in with it. This page explains what we access and the commitments we make about it.

What we access​

We request the users.read and tweet.read scopes. X requires tweet.read alongside users.read to read your profile; we do not read your posts. With them we make one request, to GET /2/users/me, and read:

  • your X user ID and username.

X also returns your display name with your profile. We ignore it. We do not request offline.access, so X gives us no refresh token.

How we use it​

  • Account linking: when you are signed in and link X at Linked accounts, we attach your X user ID to your account.
  • Sign-in: we look for the account your X user ID is linked to. Signing in never links X or creates an account.
  • No pre-filling: we do not copy your X name, username, or avatar into your profile or the setup form.

That is the only use. We make one X API request per link or sign-in and none after that.

Our commitments​

  • We never store your X access token. It is used during sign-in or linking and then discarded.
  • We never post, like, repost, follow, or send direct messages on X for you.
  • We never read your posts, timeline, bookmarks, or direct messages.
  • We never use X data for advertising.
  • We never use X data to train AI or machine-learning models.
  • We never sell X data or share it with third parties, except the subprocessors that host our service.
  • We only keep your X user ID and username, so the linked account can log in and the settings page can show which one is linked.
  • We will not ask for more scopes without updating this page first.

Revoking access and deleting data​

See also the GitHub API disclosure, the Discord API disclosure, Permissions & Scopes, and the Linked accounts and sign-in guide.

Contact​

Questions about this disclosure: privacy@blazium.games.