← Back to Xytro Labs

Privacy Policy

Effective Date: July 23, 2026 · Last Updated: September 26, 2026

Xytro Labs is built on a foundation of privacy. We collect only what is necessary to provide our services. We do not sell, rent, or share your personal data with third parties. We do not display advertisements. We do not track you across the web.

1. Introduction

Xytro Labs ("Xytro," "we," "us," or "our") operates a suite of software services including The Vault (cloud storage), Xytro One (identity), Xena AI (artificial intelligence), Reefs (git repository hosting), Xytro Post (email), NOVA (collaboration), Indent (programming language tooling), and Zor (transpiler tooling) (collectively, the "Services").

This Privacy Policy describes how we collect, use, store, and protect your information when you use our Services. By using the Services, you consent to the data practices described in this Policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

2.1.1 Signing in with Google

You may sign in with a Google account instead of a password. If you do, we store:

We do not receive your Google password, and we request only the openid and email scopes — we do not request access to your Google profile, contacts, Drive, calendar, or any other Google service. You may link Google to an existing Xytro account, and unlinking or deleting your account removes the stored link.

2.2 Content You Create

We store content you intentionally create or upload through our Services:

2.3 API Usage Data

For users of the Xena AI API:

2.4 Technical Data (Essential Only)

We process minimal technical data required for service operation:

2.5 Data Storage

User data — including cloud files, contacts, calendars, and AI chat history — is stored in a unified storage system. Each user's storage quota is enforced according to their plan tier. API conversations with AI models are processed transiently and not permanently stored unless explicitly saved by the user.

The Xena AI chat interface stores a local record of your recent conversations (message history and titles) on our servers so that the interface can restore your ongoing chats. Your AI responses are cached on our servers to improve speed and reduce cost; the response cache, web-search cache, knowledge bases (RAG), and any per-key prompts all live on our AI service and are covered by the retention and deletion terms in this Policy.

3. What We DO NOT Collect

The following is an exhaustive list of data categories we explicitly DO NOT collect, process, or store:

Data CategoryStatus
Tracking cookies or third-party analyticsNOT collected
Advertising identifiers or ad networksNOT collected
Browser fingerprinting or device fingerprintingNOT collected
Cross-site tracking or behavioral profilingNOT collected
Location data (GPS, WiFi, cell tower)NOT collected
Contact lists or address books (unless you explicitly import them)NOT collected
Social media profiles or connectionsNOT collected
Biometric data or facial recognitionNOT collected
Indent language usage data (edits, compilations, run history)NOT collected
Zor transpiler usage data (source code, transpilation logs, build history)NOT collected

3.1 Indent & Zor — Zero Data Collection

Indent and Zor are local developer tools. They operate entirely on your machine. We do not collect, transmit, or store any data about your Indent code, Zor source files, compilation processes, build outputs, or development workflows. These tools function without any telemetry, analytics, or usage tracking of any kind.

4. How We Use Your Information

Your data is used exclusively for the following purposes:

  1. Service Provision: To authenticate you, deliver your emails, store your files, process your AI requests, and enable collaboration.
  2. Service Improvement: To identify bugs, improve performance, and develop new features based on aggregated, anonymized patterns.
  3. Security: To detect and prevent fraud, abuse, unauthorized access, and violations of our Terms of Service.
  4. Communication: To send you essential service notifications (password resets, security alerts, policy updates). We do not send marketing emails.
  5. Billing: To calculate API usage charges and maintain your account balance.

5. Data Sharing & Disclosure

We do not sell, rent, trade, or share your personal information with third parties. The following limited exceptions apply:

5.1 Service Providers

We engage the following third-party services that may process limited data on our behalf:

ProviderPurposeData Processed
CloudflareDNS resolution, DDoS protection, TLS terminationIP address (transient)
Google LLCOptional sign-in with Google (OAuth)Your Google account identifier (stored by us only as an HMAC-SHA256 hash), your Google email address, and the date you linked it. Requested scopes: openid, email
Third-party image providers (e.g. Alibaba Cloud DashScope)Image generation for Xena image modelsYour image prompt, and any reference image you attach. No account identifiers — see 5.1.1
OrioSearch / SearXNG (self-hosted)Web search queries for Xena AISearch query text only (processed on our own infrastructure, no user identity)
Tavily / DuckDuckGoFallback web search when the self-hosted search service is unavailableSearch query text only (no user identity)
Xytro AI infrastructure (self-hosted)AI model inference for models served on our own hardwareChat messages (processed on our own infrastructure)
Groq, Inc.Inference for the Xena flagship model (GPT-OSS 20B)Chat messages, anonymised — sent as Xytro with no account identifiers (see 5.1.1)
Third-party model providersAI model inference for models served externallyChat messages, anonymised — sent as Xytro with no account identifiers (see 5.1.1)

The Xena AI chat interface is itself derived from the open-source project aiaio (Apache-2.0, by abhishekkrthakur), served as a front-end layer over our own AI service.

5.1.1 Anonymised AI Requests

Some Xena AI models are served by third-party model providers. Where a model is served externally, we anonymise the request before it is sent:

We do not store your content with third-party model providers; it is transmitted only to generate the response you requested. Models served on our own infrastructure are processed entirely within it.

5.1.2 When Repository Contents Are Sent

Xena AI can read and write Reefs repositories on your behalf. When you ask it to work on a repository, the model must be shown the file contents it needs — so the specific files involved are transmitted to the serving model provider in order to carry out the operation you asked for. This happens only when a repository operation is requested, and only for the paths that operation concerns. It is subject to the same anonymisation as 5.1.1: the request carries no account identifiers. Repository tools run on a dedicated code-focused model, and results you accept are written to your repository as a commit.

5.2 Legal Obligations

We may disclose information if required by law, court order, or governmental authority, but only after reviewing the request for legal validity and, where permitted, notifying you.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. You will be notified before any transfer and given the opportunity to delete your account.

6. Data Storage & Security

6.1 Storage Location

All user data is stored on servers operated and controlled exclusively by Xytro Labs. We do not use third-party cloud storage providers for user content. AI requests served by third-party model providers are anonymised before transmission and are never stored by us with those providers — see 5.1.1.

6.2 Encryption

6.3 Access Controls

6.4 Data Retention

7. Cookies

We use a single essential cookie:

CookiePurposeDurationDetails
connect.sidSession management7 daysContains a random session ID only. HttpOnly (inaccessible to JavaScript). SameSite=Lax. Secure flag in production. Domain: .xytro.site for cross-service SSO.

We do not use any non-essential cookies, tracking cookies, or third-party cookies.

8. Your Rights & Choices

8.1 Access

You may access your personal data at any time through your account settings at xytro.site/account. This includes profile information, connected services, and a summary of stored data.

8.2 Correction

You may update your profile information, including username, email, and profile picture, through your account settings.

8.3 Export

You may export your data in a machine-readable JSON format at any time through your account page.

8.4 Deletion

You may permanently delete your account and all associated data through your account settings. Deletion is irreversible. All emails, files, chats, API keys, and profile data will be permanently removed.

8.5 Communication Preferences

We only send essential service communications. There are no marketing emails to opt out of.

9. Children's Privacy

The Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will delete it immediately. If you believe a child under 13 has provided us with personal data, please contact us at [email protected].

10. International Data Transfers

All user data is stored on servers within the United States. If you access the Services from outside the United States, you consent to the transfer of your data to the United States, where data protection laws may differ from those in your jurisdiction.

10.1 Local Components on Your Own Machine

Parts of Xytro run locally rather than in our hosted infrastructure, and data they handle stays on your host:

11. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of discovery. We will describe the nature of the breach, the data affected, and the measures we are taking to address it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via:

Continued use of the Services after changes take effect constitutes acceptance of the updated Policy. If you disagree with the changes, you may delete your account before they take effect.

13. Contact Information

Xytro Labs

For privacy-related inquiries, data requests, or complaints:

Email: [email protected]

Website: xytro.site

Response time: We aim to respond to all privacy inquiries within 5 business days.

14. Governing Law

This Privacy Policy is governed by the laws of the United States. Any disputes arising from this Policy shall be resolved in accordance with our Terms of Service.

Xytro Labs — Made for people who value their privacy. No tracking. No ads. No data selling. Ever.