Scope and customer confirmation
Data is sent to our cloud only where the product identifies the data and purpose and the customer confirms the action. Signing in or validating a license does not by itself upload local Projects, files, desktop content, browsing history, or ordinary page content.
Free local features that do not need an account remain available without submitting account data.
We do not sell personal data or use account or licensing data for behavioral advertising.
Data, purpose, and necessity
Account and security
Name, email, verification state, hashed password, sessions, IP address, User-Agent, verification or reset records, rate-limit data, and the hash of a random Browser installation identifier approved during App sign-in. These are used to create and protect the account, distinguish signed-in Browsers, and support remote session revocation. Without the required account data, an account cannot be created or used.
Billing
Paddle customer, transaction, subscription, product, price, locale, amount, and billing status needed to complete purchases and provide access. Paddle processes payment methods; XAgent does not store full card numbers.
Licensing and devices
Plan and license status, Activation Key hash and hint, notes, device type, hashed device UUID, label, app version, bindings, and lifecycle events needed to issue, renew, display, and revoke access.
Essential preferences
Locale settings and essential sign-in, security, and checkout cookies. We do not currently use advertising trackers or behavioral analytics.
Depending on applicable law, processing is based on the requested service or contract, service security, legal obligations, or consent where required.
Providers and transfers
Paddle↗
Processes checkout, payment methods, tax, receipts, refunds, and fraud controls as Merchant of Record. XAgent receives the status needed to fulfill the purchase.
Resend↗
Processes recipient addresses, email content, and delivery metadata to send verification and password-reset messages.
Hosting and lawful requests
Hosting, database, network, and security providers process only what is needed to run the service. Necessary data may also be disclosed when required by a valid legal request.
Providers may process data outside your location. We limit this processing through provider terms, access controls, and safeguards required by applicable law.
Retention and protection
- Sign-in sessions last up to 30 days; verification and password-reset links normally expire after one hour.
- Account data is kept while the account is active. Billing and licensing records are kept only as needed to provide access, handle refunds or disputes, prevent abuse, and meet tax, accounting, or legal duties.
- We use access controls, secure hashing where applicable, signed device certificates, request validation, rate limits, and lifecycle records to protect the service.
Data is deleted or de-identified when it is no longer needed, subject to required legal and dispute records.
Your rights and changes
Depending on applicable law, you may request access, correction, export, deletion, or restriction; object to processing or withdraw consent; and complain to a competent data-protection authority. Paddle separately handles rights relating to data it controls.
We update this notice when the data, purpose, recipient, or transfer arrangement materially changes, and request confirmation again where required.
Contact privacy@xagent-forge.com for privacy requests.
Make a privacy request
Ask to access, correct, export, or delete account-linked data by email. We may verify your identity. Records that must be kept for legal, transaction, dispute, or security purposes may not be deleted immediately.