Privacy Policy

Applies to XBX Authentication and the XBX Chrome Extension.

Data we collect

  • Account data: your email address, a securely hashed password, and email verification state.
  • Profile data you choose to provide: display name, avatar URL and personal notes.
  • Entitlement data: plan, subscription status, account status and device limit.
  • Security telemetry: authentication event types, coarse timestamps, a hashed IP identifier and a truncated user agent string.

How we use it

  • To authenticate you and issue short-lived access tokens for the XBX extension.
  • To validate entitlements server-side so premium features unlock only for eligible accounts.
  • To detect and rate limit abuse such as credential stuffing and verification-email flooding.

How we protect it

  • Passwords are never stored in plain text and are never transmitted to third parties.
  • Every database table enforces Row Level Security, so a signed-in account can only ever read its own rows.
  • Privileged fields such as plan and account status are rejected at the database layer if a client attempts to change them.
  • Raw IP addresses are hashed before storage; we do not keep browsing history or extension activity.

Sharing

  • We do not sell personal data. Data is shared only with infrastructure providers required to operate authentication, and only to the extent necessary.

Retention and your rights

  • Account data is retained while your account exists. Security events are retained for a limited period for abuse investigation.
  • You may request access, correction or deletion of your data at any time by contacting support.

Contact

Questions about this policy? Email support@xbx.app.