Privacy Policy
Last updated: June 2026
1. Introduction
XeraX ("we", "our", "us") operates the XeraX surveillance platform at xeraxapp.com. This Privacy Policy explains what information we collect, how we use it, and your rights under applicable data protection laws including the EU General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following categories of information:
- Account information: Your email address at the time of purchase, used to deliver your access token and communicate subscription updates.
- Payment data: Payment is processed entirely by PayPal. We never see or store your credit card number. We receive only your PayPal email and transaction ID to activate your account.
- Device telemetry: XeraX software installed on a device sends telemetry (battery, GPS, device status) directly to your own server — not to our servers. We have no access to your monitored device data.
- Usage data: We may collect anonymised server logs (IP addresses, request times) for security and performance monitoring. Logs are retained for 30 days.
- Email leads: If you voluntarily submit your email on our homepage, we store it to send the requested guide and occasional product updates. You can unsubscribe at any time.
3. How We Use Your Data
- To deliver your membership token after purchase
- To send subscription renewal and support emails
- To improve our website and services
- To comply with legal obligations
4. Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only with:
- PayPal: For payment processing, subject to PayPal's Privacy Policy.
- Email providers: To deliver transactional emails via our SMTP provider.
- Law enforcement: If required by a valid legal order.
5. Data Security
We use industry-standard measures to protect your data, including TLS encryption in transit and hashed storage of sensitive values. However, no system is 100% secure. We encourage you to use a strong, unique password for your email account.
6. Your Rights (GDPR)
If you are located in the EU or EEA, you have the following rights under the GDPR:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing of your data for marketing.
- Withdraw consent: Where processing is based on consent, you may withdraw at any time.
To exercise any of these rights, email us at support@xeraxapp.com. We will respond within 30 days.
7. Cookies
We use essential cookies to remember your preferences (e.g. cookie consent state, session data). We do not use advertising or tracking cookies. You can disable cookies in your browser settings, though some site features may not function correctly.
8. Data Retention
We retain your account data for as long as your subscription is active and for 12 months after cancellation for audit purposes. Email leads are retained until you unsubscribe. Server logs are purged after 30 days.
9. Third-Party Links
Our website may link to external services (PayPal, Telegram, etc.). We are not responsible for the privacy practices of those services. Please review their privacy policies independently.
10. Changes to This Policy
We may update this policy from time to time. We will notify you by email of material changes and update the "Last updated" date at the top of this page.
11. Contact
Questions about this Privacy Policy? Contact us at support@xeraxapp.com.