Xytro Labs is built on a foundation of privacy. We collect only what is necessary to provide our services. We do not sell, rent, or share your personal data with third parties. We do not display advertisements. We do not track you across the web.
Xytro Labs ("Xytro," "we," "us," or "our") operates a suite of software services including The Vault (cloud storage), Xytro One (identity), Xena AI (artificial intelligence), Reefs (git repository hosting), Xytro Post (email), NOVA (collaboration), Indent (programming language tooling), and Zor (transpiler tooling) (collectively, the "Services").
This Privacy Policy describes how we collect, use, store, and protect your information when you use our Services. By using the Services, you consent to the data practices described in this Policy.
When you create an account, we collect:
You may sign in with a Google account instead of a password. If you do, we store:
We do not receive your Google password, and we request only the openid and email scopes — we do not request access to your Google profile, contacts, Drive, calendar, or any other Google service. You may link Google to an existing Xytro account, and unlinking or deleting your account removes the stored link.
We store content you intentionally create or upload through our Services:
For users of the Xena AI API:
We process minimal technical data required for service operation:
User data — including cloud files, contacts, calendars, and AI chat history — is stored in a unified storage system. Each user's storage quota is enforced according to their plan tier. API conversations with AI models are processed transiently and not permanently stored unless explicitly saved by the user.
The Xena AI chat interface stores a local record of your recent conversations (message history and titles) on our servers so that the interface can restore your ongoing chats. Your AI responses are cached on our servers to improve speed and reduce cost; the response cache, web-search cache, knowledge bases (RAG), and any per-key prompts all live on our AI service and are covered by the retention and deletion terms in this Policy.
The following is an exhaustive list of data categories we explicitly DO NOT collect, process, or store:
| Data Category | Status |
|---|---|
| Tracking cookies or third-party analytics | NOT collected |
| Advertising identifiers or ad networks | NOT collected |
| Browser fingerprinting or device fingerprinting | NOT collected |
| Cross-site tracking or behavioral profiling | NOT collected |
| Location data (GPS, WiFi, cell tower) | NOT collected |
| Contact lists or address books (unless you explicitly import them) | NOT collected |
| Social media profiles or connections | NOT collected |
| Biometric data or facial recognition | NOT collected |
| Indent language usage data (edits, compilations, run history) | NOT collected |
| Zor transpiler usage data (source code, transpilation logs, build history) | NOT collected |
Indent and Zor are local developer tools. They operate entirely on your machine. We do not collect, transmit, or store any data about your Indent code, Zor source files, compilation processes, build outputs, or development workflows. These tools function without any telemetry, analytics, or usage tracking of any kind.
Your data is used exclusively for the following purposes:
We do not sell, rent, trade, or share your personal information with third parties. The following limited exceptions apply:
We engage the following third-party services that may process limited data on our behalf:
| Provider | Purpose | Data Processed |
|---|---|---|
| Cloudflare | DNS resolution, DDoS protection, TLS termination | IP address (transient) |
| Google LLC | Optional sign-in with Google (OAuth) | Your Google account identifier (stored by us only as an HMAC-SHA256 hash), your Google email address, and the date you linked it. Requested scopes: openid, email |
| Third-party image providers (e.g. Alibaba Cloud DashScope) | Image generation for Xena image models | Your image prompt, and any reference image you attach. No account identifiers — see 5.1.1 |
| OrioSearch / SearXNG (self-hosted) | Web search queries for Xena AI | Search query text only (processed on our own infrastructure, no user identity) |
| Tavily / DuckDuckGo | Fallback web search when the self-hosted search service is unavailable | Search query text only (no user identity) |
| Xytro AI infrastructure (self-hosted) | AI model inference for models served on our own hardware | Chat messages (processed on our own infrastructure) |
| Groq, Inc. | Inference for the Xena flagship model (GPT-OSS 20B) | Chat messages, anonymised — sent as Xytro with no account identifiers (see 5.1.1) |
| Third-party model providers | AI model inference for models served externally | Chat messages, anonymised — sent as Xytro with no account identifiers (see 5.1.1) |
The Xena AI chat interface is itself derived from the open-source project aiaio (Apache-2.0, by abhishekkrthakur), served as a front-end layer over our own AI service.
Some Xena AI models are served by third-party model providers. Where a model is served externally, we anonymise the request before it is sent:
We do not store your content with third-party model providers; it is transmitted only to generate the response you requested. Models served on our own infrastructure are processed entirely within it.
Xena AI can read and write Reefs repositories on your behalf. When you ask it to work on a repository, the model must be shown the file contents it needs — so the specific files involved are transmitted to the serving model provider in order to carry out the operation you asked for. This happens only when a repository operation is requested, and only for the paths that operation concerns. It is subject to the same anonymisation as 5.1.1: the request carries no account identifiers. Repository tools run on a dedicated code-focused model, and results you accept are written to your repository as a commit.
We may disclose information if required by law, court order, or governmental authority, but only after reviewing the request for legal validity and, where permitted, notifying you.
In the event of a merger, acquisition, or sale of assets, your data may be transferred. You will be notified before any transfer and given the opportunity to delete your account.
All user data is stored on servers operated and controlled exclusively by Xytro Labs. We do not use third-party cloud storage providers for user content. AI requests served by third-party model providers are anonymised before transmission and are never stored by us with those providers — see 5.1.1.
We use a single essential cookie:
| Cookie | Purpose | Duration | Details |
|---|---|---|---|
connect.sid | Session management | 7 days | Contains a random session ID only. HttpOnly (inaccessible to JavaScript). SameSite=Lax. Secure flag in production. Domain: .xytro.site for cross-service SSO. |
We do not use any non-essential cookies, tracking cookies, or third-party cookies.
You may access your personal data at any time through your account settings at xytro.site/account. This includes profile information, connected services, and a summary of stored data.
You may update your profile information, including username, email, and profile picture, through your account settings.
You may export your data in a machine-readable JSON format at any time through your account page.
You may permanently delete your account and all associated data through your account settings. Deletion is irreversible. All emails, files, chats, API keys, and profile data will be permanently removed.
We only send essential service communications. There are no marketing emails to opt out of.
The Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will delete it immediately. If you believe a child under 13 has provided us with personal data, please contact us at [email protected].
All user data is stored on servers within the United States. If you access the Services from outside the United States, you consent to the transfer of your data to the United States, where data protection laws may differ from those in your jurisdiction.
Parts of Xytro run locally rather than in our hosted infrastructure, and data they handle stays on your host:
127.0.0.1 by default.In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of discovery. We will describe the nature of the breach, the data affected, and the measures we are taking to address it.
We may update this Privacy Policy from time to time. Material changes will be communicated via:
Continued use of the Services after changes take effect constitutes acceptance of the updated Policy. If you disagree with the changes, you may delete your account before they take effect.
Xytro Labs
For privacy-related inquiries, data requests, or complaints:
Email: [email protected]
Website: xytro.site
Response time: We aim to respond to all privacy inquiries within 5 business days.
This Privacy Policy is governed by the laws of the United States. Any disputes arising from this Policy shall be resolved in accordance with our Terms of Service.
Xytro Labs — Made for people who value their privacy. No tracking. No ads. No data selling. Ever.