Privacy Policy
What we collect, why we collect it, and what we will never do with it. Written to be read rather than to be legally impenetrable.
Last updated 15 September 2026
On this page
The short version
We collect the minimum needed to run the service. We do not sell your data, we do not train AI models on your work, and you can delete everything from your account page. Your portfolios belong to you.
What we collect
When you sign in
We use Google Sign-In. Google tells us your name, email address and profile picture. We never see your Google password, and we cannot access anything else in your Google account.
What you make
Your projects — text, layouts, colours and any images you upload — are stored so you can come back to them. They are private unless you publish them.
How the site is used
We record which pages are visited, which features are used, and roughly which country a visit came from, worked out from your device's timezone rather than an IP lookup. This is counted, not tracked: we cannot reconstruct one person's browsing from it.
When content is blocked
If our automatic checks block something — abusive words, an explicit picture, or a page that looks like phishing or a scam — we record the account and email address, the time, the IP address and browser used, and what was blocked. For a blocked publishing attempt we also keep a copy of the pages. This is the only place we record an IP address. It is used to keep XODE safe, to investigate abuse, and to report crimes to the authorities as our Terms describe.
What we do not collect
- Payment card details — these go directly to our payment processor and never touch our servers
- Your Google password, contacts, calendar, or anything else in your Google account
- Precise location
- Anything from third-party trackers or advertising networks — we run none
Why we collect it
| What | Why |
|---|---|
| Name, email, picture | To identify your account and show who you are in the interface |
| Your projects | To save your work and sync it across devices |
| Usage counts | To know which features are worth keeping and where people get stuck |
| Download and publish counts | To apply free-plan limits against your account rather than your browser |
Who we share it with
Three companies, each doing one job:
- Google — sign-in only. Governed by Google's own privacy policy.
- Hostinger — our hosting provider, where the servers physically are.
- Razorpay — payment processing, for Pro subscriptions only.
Nobody else. We do not sell, rent or trade your information, and there is no advertising network involved in this site.
Authorities. When content appears to be a crime or a cyber security incident — phishing, fraud, impersonation, child sexual abuse material — we share the records described above with CERT-In, the police and the courts, and we answer lawful requests from government agencies.
Published portfolios are public
This one matters. When you publish, your page becomes a public web address that anyone can visit and search engines can index. Do not put anything on a published page you would not want a stranger to read — home address, phone number, identity documents.
Unpublished projects stay private to your account.
How long we keep it
- Projects — until you delete them or close your account
- Published pages — until you unpublish them
- Usage figures — 180 days, then deleted automatically
- Payment records — seven years, as tax law requires
- Records of blocked content — at least 180 days, and longer where an investigation or the law requires it; copies of blocked pages for one year
Your rights
You can, at any time:
- See everything we hold about you, from your account page
- Correct anything wrong
- Export your projects as files you own
- Delete your account and everything in it
- Withdraw consent by signing out and deleting the account
Deleting your account removes your projects, your published pages and your personal details within 30 days. It cannot be undone — export anything you want to keep first.
Security
Sign-in tokens are verified on our server, not just in your browser. Personal data is stored outside the publicly served folders and denied at the web server. Payments are handled entirely by our processor.
No system is perfect. If we ever have a breach affecting your data, we will tell you by email within 72 hours of finding it, along with what was affected and what to do.
Children
XODE is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Changes
If this policy changes materially we will say so on this page and email account holders before it takes effect. The date at the top always reflects the current version.
Contact
Questions about any of this, or a request about your data:
Email: xode.enterprises@gmail.com
Post: XODE, Chennai, Tamil Nadu, India
We answer data requests within 30 days, usually much sooner.