Summary (plain English)
1. Who We Are
Xcloak is a penetration testing and security intelligence platform operated independently. When this policy refers to "we", "us", or "our", it means Xcloakand its operators. For privacy enquiries, contact admin@xcloak.tech.
2. What Data We Collect
Account data (when you register)
- โEmail address and username
- โHashed password (we never store plaintext passwords)
- โAccount creation date and tier (free/pro/enterprise)
Scan data (when you run a scan)
- โTarget hostname or IP address
- โScan goal (your plain-English description)
- โTool output, parsed findings, risk scores
- โAI-generated analysis and reports
- โScan timestamp, duration, and status
Payment data (when you subscribe)
- โPayment ID and order ID from Razorpay
- โSubscription tier and payment date
- โWe do NOT store card numbers, CVVs, or bank details โ these are handled entirely by Razorpay
Technical data (automatically collected)
- โIP address at time of login and scan initiation
- โBrowser/client user agent
- โAPI request logs (for rate limiting and abuse prevention)
3. How We Use Your Data
- โTo provide and operate the Service โ running scans, storing results, generating reports
- โTo authenticate you and maintain your session
- โTo enforce scan quotas and tier limits
- โTo process payments and manage subscriptions via Razorpay
- โTo send transactional emails (account confirmation, payment receipts)
- โTo investigate abuse and respond to legal requests
- โTo improve the platform based on aggregated, anonymized usage patterns
We do not use your scan data to train AI models. We do not serve advertising. We do not sell or rent your personal data to any third party.
4. Data Sharing
We share data only in these specific circumstances:
- โRazorpay โ payment processing. Razorpay receives your payment details and is subject to their own privacy policy.
- โAI providers (Anthropic/OpenAI) โ scan findings are sent to AI APIs for analysis. We send only structured finding data, not your personal details. These providers process data under their own policies.
- โLaw enforcement โ we may disclose data when required by a valid court order, subpoena, or legal obligation. We will notify you unless prohibited by law.
We have no advertising partners and do not share data for marketing purposes.
5. Data Retention
- โAccount data: retained until you delete your account
- โScan history and findings: retained for 1 year, then automatically purged
- โPayment records: retained for 7 years as required by Indian tax law
- โAudit logs (IP, timestamps): retained for 90 days
- โDeleted accounts: all personal data removed within 30 days of deletion request
6. Data Security
We protect your data using industry-standard measures:
- โPasswords are hashed using bcrypt โ never stored in plaintext
- โAll API communication uses HTTPS/TLS encryption
- โJWT tokens expire after 8 hours; refresh tokens after 7 days
- โDatabase access is restricted to the application server only
- โScan data is isolated per user โ you cannot access other users' scans
No system is perfectly secure. If you discover a security issue, please report it responsibly to admin@xcloak.tech.
7. Your Rights
You have the following rights regarding your personal data:
- โAccess โ request a copy of the personal data we hold about you
- โCorrection โ update inaccurate account information via Settings
- โDeletion โ request deletion of your account and associated data
- โExport โ download your scan history and findings in JSON or PDF format
- โObjection โ object to processing for purposes other than service delivery
To exercise any of these rights, email admin@xcloak.tech. We will respond within 30 days.
8. Cookies and Local Storage
We use minimal storage:
- โeso_token (cookie) โ your authentication token, expires after 1 day
- โeso_user (localStorage) โ cached profile data for the sidebar; cleared on logout
- โNo advertising cookies. No tracking pixels. No analytics scripts.
9. Children's Privacy
The Service is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a minor has registered, contact us immediately at admin@xcloak.tech and we will delete the account.
10. International Transfers
Our servers are currently located in Germany (Hetzner). Your data may be processed by AI providers whose infrastructure is in the United States. By using the Service, you consent to this transfer. We ensure adequate safeguards are in place with all international processors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before material changes take effect. The "Last updated" date at the top of this page always reflects the most recent version.
12. Contact
For privacy questions, data requests, or concerns:
ยฉ 2026 Xcloak. All rights reserved.