Privacy Policy
Last updated: August 2, 2026
1. Scope
This Privacy Policy explains how Xenith ("Xenith," "we," "us," "our") handles personal information when you use our website and application (the "Service"). It applies to all users of Xenith.
2. Data We Collect
Depending on how you use Xenith, we may collect:
- Account data, such as email address, login credentials, and profile details.
- User-generated data, such as intentions, routines, reflections, notes, projects, and other content you create inside the Service.
- Biometric and health-related inputs, such as weight, height, age, and activity level, if you use tools like the Biometric Wizard — used only to calculate estimated calorie and macro-nutrient targets within Xenith. These are general informational estimates, not medical advice; see Section 12 of our Terms of Service.
- Product and usage data, such as app interactions, performance events, and settings preferences, collected via PostHog. We disable session recording and automatic click/pageview capture, and configure PostHog to respect your browser's Do Not Track setting.
- Billing data, such as your subscription plan, status (active, trialing, past due, canceled), renewal date, and the Stripe customer and subscription identifiers needed to manage your subscription. Your card number, CVC, and other raw payment credentials are entered directly into Stripe's hosted checkout and are never received or stored by Xenith — see Section 5 for how Stripe processes that data.
- Support and communication data, such as feedback messages and customer support requests.
3. How We Use Data
We process personal information to provide and maintain Xenith, authenticate users, secure accounts, improve reliability, personalize user experience, respond to support requests, and comply with legal obligations.
4. Legal Bases
We process data based on one or more of the following grounds, where applicable: performance of our contract with you, legitimate interests in operating and improving the Service, consent (for optional features), and compliance with legal obligations.
5. Sharing and Processors
We do not sell your personal information. We share data only with trusted service providers ("subprocessors") who process it on our behalf, solely to operate and improve Xenith. Current subprocessors include:
- Supabase — database, authentication, and file storage.
- Stripe — subscription billing and payment processing. Stripe collects and stores your payment details (card number, billing address, etc.) directly and processes them under its own privacy policy. We receive back only your subscription status and billing identifiers, never your full card details.
- PostHog — product analytics (page views and in-app events) to understand usage and improve the Service. Session recording and automatic event capture are disabled, and PostHog is configured to respect Do Not Track.
- Vercel — hosting, along with Vercel Analytics and Speed Insights for aggregate, privacy-friendly performance and usage measurement.
- Anthropic — AI processing for features such as insights and growth guidance. Content you submit to an AI feature is sent to Anthropic to generate a response and is not used to train their models.
- Cloudflare — Turnstile bot and abuse protection on sign-up and forms.
- Sentry — error monitoring and diagnostics to detect and fix crashes.
- Google Analytics — aggregate website traffic measurement.
- Resend — transactional and lifecycle email delivery.
- Google and Microsoft — optional third-party sign-in (OAuth) when you choose to authenticate with those accounts.
- Google Calendar and Notion — optional two-way calendar sync when you choose to connect those accounts. See the Limited Use statement below.
- Web push services — browser push providers used to deliver notifications you opt into.
We may also disclose information where required by law or to protect the rights, safety, and security of our users and the Service.
Limited Use disclosure (Google Workspace APIs). Xenith's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data accessed via the Google Calendar API is used exclusively to power two-way calendar sync within Xenith, at your explicit request — it is never used to train, develop, or improve any AI or machine-learning model, and is never sold, shared for advertising, or used for any purpose beyond providing the calendar sync feature itself.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate personal data.
- Request deletion of your account and related data.
- Export your data where technically feasible.
To exercise any of these rights, contact us using the details in the Contact section below.
7. Data Retention
We retain personal data for as long as needed to provide the Service and satisfy legal, tax, accounting, and security obligations. You may request deletion of your account at any time. Approximate retention periods by category:
- Account and user-generated content — retained until you delete your account, at which point it is permanently removed from our production database within 30 days, subject to standard backup rotation.
- Subscription and billing records — retained for the life of your account plus up to 7 years afterward, as required for tax, accounting, and fraud -prevention purposes. Stripe retains payment records under its own policy independent of Xenith.
- Product analytics events (PostHog) — retained for up to 12 months, after which events are deleted or aggregated.
- Error and performance diagnostics (Sentry, Vercel Speed Insights) — retained for up to 90 days.
8. Security
We apply reasonable technical and organizational measures to protect data, including access controls, encryption in transit, and secure infrastructure practices. No system is guaranteed secure, but we continuously improve our controls.
9. Cookies and Local Storage
Xenith uses limited browser storage for essential app behavior: your signed-in session, theme, onboarding state, and a small local cache of your subscription status (plan and Pro/free access) used only to decide what the interface shows optimistically while it re-confirms your real status with our servers — it does not itself grant access to any gated data or action. We also use analytics (PostHog, Google Analytics, and Vercel Analytics) to understand aggregate usage and improve the Service. We do not use third-party advertising trackers for behavioral ad targeting.
On your first visit, a cookie banner lets you accept or reject non-essential (analytics) cookies; essential cookies needed for sign-in and core functionality are always active since the Service cannot work without them. Your choice is stored in local storage and you can change it at any time — see our Cookie & Tracking Policy for the full list of cookies and storage we use and how to manage them.
10. International Use
If you use Xenith from outside your home jurisdiction, you understand your data may be processed in locations where our providers operate. We use contractual and technical safeguards where appropriate.
11. Children's Privacy
Xenith is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If we become aware of such collection, we will delete the data.
12. Policy Updates
We may update this policy periodically. Material changes will be reflected on this page by updating the "Last updated" date.
13. Contact
For privacy-related requests, contact us at [email protected].