XyroBot

Privacy Policy

Last updated: 14 August 2026

This Privacy Policy explains how Xyro SaaS LLC ("Xyro", "we", "us") collects and uses personal data when you use XyroBot (the "Service"). We are the data controller.

Contact: [email protected] Registered address: [to be added]

Data we collect

  • Account data: your username and email address, and a securely hashed version of your password (we never store passwords in readable form).
  • Usage and security data: sign‑in events, session tokens, IP address, a hardware identifier of the computer the bot runs on, bot and client versions. This is used to run the Service and to detect license sharing and abuse.
  • Payment data: subscriptions are processed by Stripe. We do not receive or store your full card number. We receive limited billing details (such as a payment reference, the outcome of a charge, and your subscription status) needed to activate and manage your license.
  • Support data: the content of messages you send us.
  • Cookies: a small number of strictly necessary cookies to keep you signed in and to protect forms (CSRF). We do not use advertising cookies.

How we use your data

  • To create and secure your account and confirm your email address.
  • To provide the Service, issue and renew your license, and enforce license limits.
  • To process payments and send transactional emails (email confirmation, purchase receipts, renewal and expiry reminders, password resets).
  • To prevent fraud and abuse, and to keep the Service reliable.
  • To respond to your support requests.

Our legal bases (where the GDPR applies) are the performance of our contract with you, our legitimate interests in running and securing the Service, and, where relevant, your consent.

Service providers

We share data only with the processors we need to run the Service:

  • Stripe — payment processing.
  • Resend — sending transactional emails.
  • Cloudflare — content delivery, DNS and security.
  • Our hosting provider.

These providers process data on our behalf under appropriate safeguards. Some may process data outside your country; where required we rely on lawful transfer mechanisms.

How long we keep it

We keep account data while your account exists. Operational records are kept only as long as needed — for example, closed sessions for about 30 days, usage/telemetry for about 90 days, and audit logs for about 365 days — after which they are deleted automatically.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data, and to withdraw consent. To exercise any of these, email [email protected]. You also have the right to complain to your local data‑protection authority.

Security

We protect data with hashed passwords (Argon2id), encrypted transport (HTTPS), sealed secrets, rate limiting, and access controls. No system is perfectly secure, but we take reasonable measures to protect your information.

Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children.

Changes

We may update this policy; the "Last updated" date above reflects the latest version.

Contact

Privacy questions: [email protected].

Terms of Service · Privacy Policy · Refund & Cancellation · Contact support

Discord