Privacy Policy
Applies to XBX Authentication and the XBX Chrome Extension.
Data we collect
- Account data: your email address, a securely hashed password, and email verification state.
- Profile data you choose to provide: display name, avatar URL and personal notes.
- Entitlement data: plan, subscription status, account status and device limit.
- Security telemetry: authentication event types, coarse timestamps, a hashed IP identifier and a truncated user agent string.
How we use it
- To authenticate you and issue short-lived access tokens for the XBX extension.
- To validate entitlements server-side so premium features unlock only for eligible accounts.
- To detect and rate limit abuse such as credential stuffing and verification-email flooding.
How we protect it
- Passwords are never stored in plain text and are never transmitted to third parties.
- Every database table enforces Row Level Security, so a signed-in account can only ever read its own rows.
- Privileged fields such as plan and account status are rejected at the database layer if a client attempts to change them.
- Raw IP addresses are hashed before storage; we do not keep browsing history or extension activity.
Sharing
- We do not sell personal data. Data is shared only with infrastructure providers required to operate authentication, and only to the extent necessary.
Retention and your rights
- Account data is retained while your account exists. Security events are retained for a limited period for abuse investigation.
- You may request access, correction or deletion of your data at any time by contacting support.
Contact
Questions about this policy? Email support@xbx.app.