Legal

Privacy Policy

How XCORE collects, uses and protects information about you and about your products' end users.

Effective August 23, 2026

1. Who we are

XCORE ("we", "us") operates the XCORE platform: the public website, the operator console and the product backends we provision for account holders ("customers"). This policy explains what we do with personal data in each of those roles.

2. Two roles: controller and processor

For customers — when you create an account, subscribe, or contact us — we act as a data controller: we decide why and how your account data is processed.

For your products' end users — the people who sign up to a product you build on XCORE — we act as a data processor on your behalf. You decide what data is collected and why; we store and serve it inside your product's isolated backend and only on your instructions.

3. What we collect (as controller)

  • Account data: name, email, password (stored as a salted hash), team memberships and roles.
  • Billing data: plan, subscription state and invoices. Card details are collected and stored by our payment processor (Stripe); we never see full card numbers.
  • Usage and operational data: products you create, API calls and their metadata (key, endpoint, timestamp, outcome), storage and database size samples, audit events.
  • Support and contact messages you send through the website or console.
  • Technical data: IP address, browser type and cookies needed to keep you signed in and to protect against abuse.

4. How we use it

  • To provide, secure and operate the service, including provisioning backends and enforcing plan limits.
  • To bill you and send transactional email (receipts, password resets, provisioning status).
  • To answer your questions and investigate abuse or security incidents.
  • To improve the platform using aggregated, de-identified usage metrics.

We do not sell personal data and we do not use customer or end-user data to train machine-learning models.

5. Data inside your products (as processor)

Every product has its own isolated database. We access its contents only to operate the service (backups, restores, upgrades you request, incident response) or when you explicitly ask us to. Audited "view as user" sessions are initiated by you, not by us. You are responsible for giving your end users an appropriate privacy notice.

6. Sub-processors

We use a small number of infrastructure and payment providers to run the service (hosting, email delivery, Stripe for payments). Each is bound by a data-processing agreement. A current list is available on request via the contact page.

7. Retention

Account data is kept for as long as your account exists. Product backups are retained for the period defined by your plan. When you delete a product or your account, its data is removed from live systems promptly and from backups when they expire. Invoices are retained as required by tax law.

8. Security

Data is encrypted in transit. Credentials and secrets are stored encrypted with rotating keys. Access is scoped per product, per key and per role, and every privileged action is audited. Report a security concern through the contact page.

9. Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, or to object to certain processing. You can change most account data yourself in the console; for anything else, contact us and we will respond within 30 days.

10. Cookies

We use strictly necessary cookies to keep you signed in and to protect forms against cross-site request forgery. We do not use advertising or cross-site tracking cookies on this website.

11. Changes

We will post any changes to this policy here and update the effective date. Material changes will also be announced in the console.

12. Contact

Questions about privacy? Reach us through the contact page.