Privacy Policy
Effective October 4, 2026
This policy explains what personal data myxconnector.com (also reached at myelonsdistance.com) handles, why, and your choices. “We” means the operator of myxconnector.com. Questions: @rootsaandwings on X.
The short version
- The free tool needs no account. We use your IP address only to rate-limit requests.
- We only use public X data. We never post, and we don't keep access to your X account.
- Every handle looked up appears in the list of the last 10 searches on the front page.
- Dodo Payments handles checkout: we never see your card details and don't store your email address.
- No ads or advertising trackers, and we don't sell personal data. We count visits with our own cookie; no analytics company is involved.
- Delete account on the Account page removes your account and everything tied to it, and cancels any active subscription.
What we collect and why
Elon distance lookups. When you look up a handle, our X data provider gives us that account's public profile (name, handle, profile picture, bio, follower count) and up to its newest 5,000 followers. We compare them with a map of who Elon follows and who those accounts follow, rebuilt regularly from public data. Every lookup appears in the list of the last 10 searches on the front page (handle, display name, profile picture and distance), and its result, with the accounts on the path, can be opened at a link while it is cached. Pressing Share keeps the result public at that link.
IP address. We use it to rate-limit lookups, searches and sign-ins. It is kept only inside short-lived counters (one minute to one hour) and isn't linked to an account.
Sign in with X. Through X's OAuth 2.0 with the read-only scopes users.read and tweet.read, we read your X account id, handle and whether the account is protected, once, then revoke the access token. We never get your password or email and store no X tokens. We keep your X account id and handle, linked to an internal account id.
Path to anyone. A search reads public follows and public posts between you, the target and possible connectors. For each search we store the target's public profile, the reason you give (up to 280 characters), the routes found (connectors' public profiles, tie scores and counts of public replies, mentions and quote posts), the intro kits we draft and the status you set for each route. Locked previews show counts only, never who the connectors are.
Payments. Dodo Payments collects your email address and payment details at checkout, under its own privacy policy. We pass it your internal account id so the payment reaches your account and your subscription can be cancelled when you delete it, and your visit id (see Visit statistics) so the payment counts for your visit. We store the payment and subscription ids, product, amount, date, subscription status, renewal date and your credit balance.
Visit statistics. To see which links and campaigns bring people here and how many go on to look up a handle, sign in or buy, the site sets one cookie of its own, ed_vid, holding a random visit id. With it we store the page you first arrived on, the site that sent you (its domain only), any utm_ campaign tags in that link, your country (worked out from your IP address, which we don't keep) and the first time this browser reached each step: a lookup, a result, Share, Path to anyone, sign-in, a search, checkout and payment, with the payment's amount. When you sign in, we link the visit id to your account. None of this goes to an analytics or advertising company. If your browser sends Global Privacy Control or Do Not Track, we set no cookie and count nothing.
Logs. The app logs events such as lookups (with the handle looked up), sign-ins (with the internal account id), purchases and errors, to run, secure and debug the service and track its costs. Our host also keeps standard request logs.
People who haven't used the service
To compute distances and routes we process public X data about other people: accounts on a follow chain, connectors and targets. We use only what they've made public on X, and a search's connectors are shown only to the account that ran and unlocked it. To have your data removed from our caches or shared results, email us.
Service providers
We share data only with the providers that run parts of the service:
- Vercel: hosting and request logs.
- Neon: the Postgres database (accounts, searches, purchase records, visit statistics).
- Upstash: the Redis cache and job queue (cached results, rate-limit counters).
- twitterapi.io: public X data. Handles you look up or type in the search box are sent to it.
- Anthropic: the Claude API drafts intro kits. It receives the names, handles and bios of you, the connector and the target, your reason and the summary of public interactions.
- Dodo Payments: checkout and billing, as merchant of record.
- X Corp.: Sign in with X. Profile pictures load directly from X's image servers, so X can see your IP address when your browser shows them.
These providers may process data in the United States and other countries. We don't sell or rent personal data or share it for advertising, and we disclose it to others only if the law requires it.
Cookies
We set two strictly necessary cookies, one cookie for visit statistics and no advertising cookies. All are http-only:
- ed_session keeps you signed in. It is signed, holds only your internal account id and lasts 30 days or until you sign out.
- ed_x_oauth lasts up to 10 minutes during sign-in and protects it from forgery.
- ed_vid holds a random visit id for the visit statistics above and lasts 13 months. It isn't set when your browser sends Global Privacy Control or Do Not Track.
How long we keep data
- Cached lookups: 24 hours. Cached profiles: 7 days. Search suggestions: 10 minutes.
- Rate-limit counters: up to one hour.
- Visit statistics: 13 months from your first visit.
- The front page's last 10 searches: until 10 newer searches replace an entry.
- Shared results: until you delete your account or ask us to remove them.
- Your account, searches, routes, intro kits, credits and purchase records: until you delete your account.
- Logs: a limited period set by our host. Dodo Payments keeps its own records as its policy and the law require.
Your choices and rights
Delete account on the Account page permanently removes your account, linked X handle, credits, subscription and purchase records, searches, routes and intro kits, your shared result, your entry in the last 10 searches and your cached lookup. Your visit statistics stay, unlinked from the account, and the ed_vid cookie is cleared. It first cancels any active subscription with Dodo Payments, immediately, so you won't be charged again; if that fails, nothing is deleted and you can try again or email us. Dodo Payments keeps its own payment records, as its policy and the law require.
You can also email us to access, correct, export or delete your data, or to object to how we use it. Depending on where you live (for example the EU, UK or California) you may have further rights, including complaining to your data protection authority. Where the GDPR applies, we rely on contract (providing what you asked for), legitimate interests (security, abuse prevention, measuring how the site is used and processing public X data) and legal obligations.
Security
Sessions are signed, http-only cookies sent over HTTPS, and we store no passwords or X tokens. No system is perfectly secure, so we can't guarantee absolute security.
Children
The service isn't for children. You must be 18 or older to sign in or buy, and we don't knowingly collect personal data from anyone under 16. If you think a child has given us data, email us and we'll delete it.
Changes to this policy
We'll post any update here and change the effective date. For significant changes we'll show a notice on the site before they take effect.
Contact
Privacy questions or requests: message @rootsaandwings on X.