Privacy Policy

Last updated: July 6, 2026

This policy explains how xKiro collects, uses and protects your information when you use our platform. We limit collection to what is needed to operate the service.

1. Information we collect

Account information: email, display name, hashed password, or identity from Google/GitHub/Apple sign-in.

Payment information: processed by third-party gateways (PayOS, PayPal, Lemon Squeezy, OxaPay). We do NOT store full card numbers.

Usage data: models called, token counts, timestamps, cost — for metering and billing.

Technical data: IP address, user-agent, request logs (for security, abuse prevention and debugging).

2. Prompt content and output

To route requests, your request content (prompts) is forwarded to the relevant model provider to generate a response.

Zero Data Retention for content: we do NOT persist your request or response bodies, nor request headers. We keep only request metadata (model, token counts, timestamps, cost, outcome) for billing and operations. Limited diagnostic logging may briefly capture content SOLELY to investigate a specific error, and is deleted automatically shortly afterward.

3. How we use information

Provide and operate the service (routing, metering, billing, support).

Security: detect fraud, abuse and terms violations.

Improve reliability and performance.

Send transactional/service notices (e.g. top-up receipts, limit alerts).

4. Sharing with third parties

We share data as needed with:

AI model providers: receive request content to generate responses.

Payment gateways: process transactions.

Infrastructure (hosting, database, email delivery).

We do NOT sell your personal data.

5. Cookies and similar technologies

We use cookies necessary for login, session and remembering preferences (theme, language). You can manage cookies via your browser, but disabling essential cookies may break the service.

6. Data storage and security

We apply reasonable technical and organisational measures: passwords and API keys are stored hashed, transport is encrypted over TLS, and access is restricted.

No system is perfectly secure; we cannot guarantee absolute security but commit to timely incident handling.

7. Data retention

We retain data for as long as needed to provide the service and comply with legal obligations (e.g. financial records). When you delete your account, personal data is anonymised or deleted, except where law requires retention.

8. Your rights

Depending on applicable law, you may have rights to access, correct or delete your data, or to object to/restrict certain processing.

You can edit your profile in the dashboard or contact us to exercise these rights.

9. Children

The service is not directed at children below the legal age to enter contracts. We do not knowingly collect children's data.

10. Changes to this policy

We may update this Policy over time. Material changes will be communicated reasonably and the date at the top updated.

11. Contact

For any privacy questions, please reach us via our Contact page.