Legal
Privacy Policy
Last updated 21 August 2026. Written from the actual database schema, not from a template — every retention period below is enforced by a scheduled job you can read in the source.
Draft — legal entity not yet registered. These pages describe how the service actually behaves today and are published in that spirit. The operating entity, its registered address and its VAT details will be stated here once the company is incorporated. Until then this service is operated by an individual and no charges are made.
1 · The most important thing to understand first
The business data you publish here is meant to be public. That is
the product. Your records, business profile, opening hours, prices and contact details are served
to crawlers, AI agents and anyone who requests them, at /b/{your-publisher} and through
the API. Do not publish anything you would not put on a billboard. Everything in the rest of this
page is about the other data — your account, and the operational logs.
2 · Where it is stored
All data is held on a single server in Nuremberg, Germany (Hetzner). Nothing is replicated to another country. Email is sent from that same server.
3 · What we store about you, and why
| Account | Email address, a hashed password (Argon2id — the password itself is never stored and cannot be recovered), display name, timestamps. Needed to give you an account. |
| Sessions | A session cookie, plus the IP address and browser user-agent that created it. Needed to keep you signed in and to let you spot a session you do not recognise. |
| Login attempts | Email, outcome, IP address, timestamp — for successful and failed attempts alike. Needed to lock an account after repeated failures. This is the only place we keep IP addresses for any length of time. |
| Email log | Which system emails were sent to you and when (verification, password reset). Needed to diagnose "I never got the email". |
| Query log | Every request an agent makes to your publisher: the question text, which tool, how long it took, and whether it could be answered. This is what produces your gap report. It records the question, not the person asking — we receive no identity from the agent. |
| Operator actions | Every administrative action taken on your account, and by whom. |
4 · How long each is kept
| Expired and revoked sessions | deleted after 7 days |
| Login attempts (incl. IP) | deleted after 90 days |
| Email log | deleted after 90 days |
| Verification and password-reset tokens | deleted once expired or 7 days after use |
| Impersonation grants | deleted after 7 days |
| Query log | kept in monthly partitions; retained while your account is active |
| Account and published records | kept until you delete them or ask us to |
These are not aspirations. They are enforced by scheduled
database jobs (purge_dead_sessions, purge_login_attempts,
purge_email_log, purge_expired_email_tokens,
purge_impersonation_grants) that run automatically.
5 · Support access to your account
An operator can sign into your account to help you — for example to fix a broken import. When that happens it uses a one-time, time-limited, audited token, and every use is recorded in an audit log tied to your account. Ask us and we will tell you exactly when it happened and why. There is no silent access path.
6 · What we do not do
- No advertising, no ad networks, no tracking pixels, no analytics scripts on any page.
- No selling or sharing of your account data with anyone.
- No card or bank data of any kind — no payment processor is connected.
- No cookies except the one that keeps you signed in. There is nothing to consent to because there is nothing else being set.
7 · Third parties actually involved
| Hetzner (Germany) | the server everything runs on |
| Google Fonts | the page typeface; your browser fetches it from Google, which means Google sees the request. This is the only external request any page makes. |
| Your DNS provider | we perform a public DNS lookup against your domain to verify it |
| Your website | when you ask us to read it (the site scan / prefill features) we fetch your own public pages, and only from the exact host you gave us |
| External AI services | Only when you run a website scan, and only for the site you have verified as yours, we send the address of the page (which is public) and the readable text of that page — the same words any visitor sees to external AI services so they can tell a thing you sell from a section of your website. Your account, your customers, your prices as we store them, and anything you have not published are never included. Nothing they return is saved: every suggested row is shown to you to accept, change or discard, and anything they produce that is not already written on your own page is thrown away before you see it. We use more than one provider and switch between them, so no single one holds a record of your scans. Ask us and we will tell you exactly which ones are in use today. |
8 · Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and everything attached to it. Write to support@x-protocols.com. We will answer within 30 days.
Deletion removes your records from publication and from our database. It cannot reach copies that third parties made while the data was public — see section 1.
9 · Changes
The date at the top changes whenever this page does. If a change materially affects what we store or for how long, we will email the address on your account.
10 · Contact
See also the Terms of Service.