Legal
Privacy Policy
This Privacy Policy explains how XARDAS AI LLC (“we,” “us”) handles personal information in connection with xardas.ai and our products and services. We aim to collect as little personal information as reasonably possible.
1. Information we collect
- Information you provide — e.g., your name, email address, and message when you contact us, request a commission, or buy a product; and details needed to fulfill an order.
- Payment information — payments are handled by our merchant of record, Sold through Link, LLC, operating the Lemon Squeezy/Stripe Managed Payments service. We do not store full card numbers; the payment service handles card data under its own policies, and we receive limited order details (e.g., that a payment succeeded, the product bought, and the buyer’s email for support).
- Automatic information — basic technical data such as IP address and browser type, which may be kept in standard server logs by our hosting provider to keep the site secure and working. We do not run analytics or tracking.
- Our installed software — our downloadable apps run locally on your device and do not send your in-app data to us, create an account, or send usage telemetry. Each app performs a license activation once per registered installation or activation cycle, and what it sends depends on the marketplace that issued your key. For a key issued by Lemon Squeezy — the storefront we sell through today — the app sends your license key and a name for the installation, and nothing else in the request body, to Lemon Squeezy’s public license service; that request contains no key generated on your computer, no product identifiers, and no hardware serial. The closed list is a list of the request-body fields the app controls, not a claim about the connection: ordinary HTTPS connection metadata — your source IP address, TLS parameters, protocol headers, and the timing of the request — is necessarily processed by Lemon Squeezy and the infrastructure that carries the request, as it is for any connection your computer makes. We operate no server of our own in this path — Lemon Squeezy does, and it keeps the license and installation records that result, which we may be able to see through our merchant account with Lemon Squeezy. The app then checks the store, product, and edition details Lemon Squeezy returns against the identifiers built into your copy, on your own computer. Releasing that installation later (Help → “Manage license…”) sends your license key and the registration identifier Lemon Squeezy issued for it, so the storefront can free the slot. For a marketplace we serve through our own activation service the transport is different and is described in Section 2 below. The app is not tied to a single storefront — it accepts a key from whichever authorized marketplace issued it, so we can add a marketplace later without you reinstalling. After activation the app runs locally with no telemetry and no periodic license checks. A license covers up to three activated installations at a time; releasing a computer from inside the app (Help → “Manage license…”) frees a slot and also needs a connection. If your purchase is refunded, reversed, charged back, or your license otherwise terminates, your authorization to use the Software ends immediately and you must stop using and delete all copies. XARDAS AI LLC may disable or revoke the associated license key and deny future activations. Continued technical availability of the Software does not grant or restore authorization to use it.
- Optional features that use the network — licensing aside, our apps reach the network only where a product says so and only when you turn the feature on. Xardas Courses and Xardas Pages have AI features that connect solely to a model endpoint you choose (a model running on your own machine, or a third-party API used with your own key); they are off until you configure one, and we neither receive nor proxy that traffic. Xardas Vault reads your own bank account, over a read-only connection with a token you supply, when you ask it to sync. In Xardas Pages, if you embed remote media in a document (for example a YouTube or Vimeo video), previewing or exporting that document loads the media from that remote host, which receives a standard web request from your device under its own privacy policy; documents without remote embeds render entirely offline. Any app will open a link in your own browser if you click one. None of this sends your in-app data to us.
2. The XARDAS activation service (Gumroad channel)
This section applies only to a purchase from a marketplace we serve through our own activation service, and only while that channel is enabled. The first such marketplace is Gumroad. That channel is not enabled, nothing is sold there today, and we are not announcing a date; a key issued by Lemon Squeezy never touches the service described here. When the channel is enabled, activating or releasing an installation contacts the XARDAS activation service, which checks the license with the marketplace and keeps the record of how many of your three activated installations are in use. It handles the following application-controlled request-body fields, and nothing else. A closed list of request-body fields is not a claim about the connection itself: ordinary HTTPS connection metadata — your source IP address, TLS parameters, protocol headers, and the timing of the request — is necessarily processed by the service and the infrastructure that carries the request, and the last entry below says what becomes of the connecting IP address. The fields are:
Two of the values below are pseudonymous SHA-256-derived references: one computed from your license key, one from the public key your installation generates. They are pseudonymous, not anonymous — anyone holding the original value can recompute the reference and match it to the record, and we treat both as personal data. Only license keys generated at random by the marketplace are supported today; a key you chose yourself would be far easier to guess back, and we would have to reassess this design before accepting one.
- Your license key — transiently. Purpose: to verify your purchase with the marketplace. Recipients: Cloudflare, which hosts the service, and Gumroad, which we query through its public verification endpoint, without any seller credential and without incrementing your key’s use counter. Retention: the key itself is never stored — it is used for that one request and discarded. Only a pseudonymous SHA-256-derived reference to it is kept, so installations can be counted against the right license without the service holding the key.
- The marketplace’s answer — transiently. Purpose: to confirm the purchase is genuine, is for that product, and has not been refunded, charged back, or lost in a dispute. Recipients: Cloudflare. Retention: used in the request and not stored.
- The product identifier (“xpid”) and the marketplace name. Purpose: to tell the service which product you are activating and whether that channel is enabled for it. Neither is derived from you or from your computer — the product identifier is the same constant in every copy of that product, and the marketplace name is the storefront’s. Recipients: Cloudflare. Retention: kept with the activation record.
- A name for the installation. The app sends a fixed, readable label built from the product’s own name (for example, “Xardas Vault installation”). You are never asked to name your computer, and the app does not read its name. Purpose: one request format serves every marketplace, so the label travels with the request; on this path it is used for nothing. Recipients: Cloudflare. Retention: not stored — the activation service neither records the label nor passes it on to the marketplace.
- The public key generated on your installation. Purpose: so the service can tell that a later release request really comes from the installation that holds the slot, which is what stops anyone else from releasing your activation. The matching private key never leaves your computer. Recipients: Cloudflare. Retention: the public key itself is not stored either — the ledger keeps only a pseudonymous SHA-256-derived reference to it, alongside the slot it belongs to.
- The protocol version number and the installation’s signature. Purpose: the version number tells the service which message format it is reading; the signature is made on your computer with the private key described above, over the single-use challenge, and is what proves that an activation or release request really comes from the installation it claims to be. Recipients: Cloudflare. Retention: neither is stored — both are checked while the request is handled and then discarded.
- Pseudonymous ledger identifiers. The record of an activation consists of the two pseudonymous SHA-256-derived references above, a randomly generated routing handle and activation identifier, the time it was created, whether it has been released, an operations log of what happened (the event, its outcome, the time, and the license reference), and the short-lived single-use challenge values issued for each request (valid for two minutes). Purpose: to enforce the three-installation limit, to let you release an installation, and to investigate failures. They contain no name, email address, postal address, IP address, computer name, hardware serial, or the name sent for the installation. Recipients: Cloudflare. Retention: an active slot record lives as long as the activation does; a released one is deleted 90 days after release, the operations log after 30 days, and a spent challenge 60 seconds after it expires. The whole record can be deleted sooner on request, as described below.
- A record of support actions we take on your license. If we act on your license at your request — releasing an installation you can no longer reach, or surrendering the license — the service records what was done, whether it succeeded, when, and the pseudonymous license reference it applied to. Purpose: so that a change to your installations is accountable and can be explained back to you, and so that a mistake can be traced. It records no name, no email address, and never your license key. Recipients: Cloudflare. Retention: 180 days, longer than the other logs precisely because it is the record of a deliberate change to your entitlement. It is kept even where the underlying slot record has been deleted, so that a deletion we performed remains explainable; it names no one, and it cannot by itself re-create an installation or an entitlement.
- IP-derived data used for rate limiting and abuse protection. Purpose: as with any internet service, the connecting IP address must be processed to deliver the request and to stop one source from flooding the service. Recipients/processors: Cloudflare, under its own terms, which routes the request and applies its standard network-level protections. Retention: the activation service does not write your IP address anywhere. It derives a salted, pseudonymous SHA-256-derived reference from it, counts requests against that reference in 10-minute windows, and deletes those counters after 20 minutes; anything else IP-derived lives only in Cloudflare’s own short-lived platform logs. We do not use any of it for advertising or profiling.
Deletion and surrendering a license. Releasing an installation from inside the app (Help → “Manage license…”) frees the slot immediately and marks that record released. That is the route for moving to another computer. Deletion is a different thing, and it is tied to surrendering the license: if you want the record removed entirely — because you have surrendered the license, been refunded, or stopped using the product — email [email protected] and we will delete the activation records for that license, including the license and installation references, the operations-log entries, and any remaining challenge values. Because the ledger identifies a license only by a pseudonymous SHA-256-derived reference, we can locate your records only if you give us what is needed to recompute it, or enough order detail for the marketplace to identify the purchase; we will tell you which we need rather than guess.
Be clear about what deletion does and does not do. It removes the service’s record of your activated installations. It does not reach the copies already installed on your computers: the app does not re-check its license, so an activated copy keeps running offline whether or not the record still exists, and we have no way to switch it off. For that reason we handle deletion as part of surrendering, refunding, or ceasing use of a license — not as a way to clear the three-installation limit while activated copies are still in use. You keep your privacy rights either way; we will simply also ask you to stop using and remove the copies the deleted records covered.
3. Third-party services on this site
Fonts, styles, and other assets are served directly from this site — we do not load fonts, analytics, advertising, or tracking from any third-party CDN, so no visitor data is sent to such parties. To operate, we rely on a small number of service providers, each of which processes data under its own privacy policy: Cloudflare (hosting and the serverless functions that serve the site and receive our two form submissions — the commission request and the “notify me” waitlist; if we enable Cloudflare’s optional Turnstile anti-spam check it would receive your IP address and a challenge token on those form submits), Resend (delivers the email for those two forms, and receives the name, email, and message you submit), and, for purchases, our merchant of record, Sold through Link, LLC, operating the Lemon Squeezy/Stripe Managed Payments service (which handles order and payment communications). We do not use these providers for advertising or cross-site tracking.
4. How we use information, and our lawful bases
To provide and improve the Services; process and deliver orders; respond to inquiries and support; operate, secure, and troubleshoot the site; send transactional messages (and, only if you opt in, occasional updates); keep records; and comply with law.
Where EU/UK data-protection law (the GDPR or UK GDPR) applies, our lawful bases are: performance of a contract (Art. 6(1)(b)) — processing orders, delivering downloads, license activation, and providing support you request; legitimate interests (Art. 6(1)(f)) — keeping the site and Services secure, preventing fraud and abuse, and maintaining ordinary business records, balanced against your rights; consent (Art. 6(1)(a)) — optional updates you sign up for, which you can withdraw at any time; and legal obligation (Art. 6(1)(c)) — tax, accounting, and other records the law requires us to keep.
5. How we share information
We do not sell your personal information. We share it only with service providers who help us run the business (hosting; payments and order delivery via our merchant of record, Sold through Link, LLC, operating the Lemon Squeezy/Stripe Managed Payments service; email), when required by law or to protect rights and safety, or in connection with a business transfer. Service providers are expected to protect the data and use it only to provide their services to us.
6. Cookies
This site does not set cookies, use local or session storage, or run analytics or tracking pixels. Payment checkout is handled on Lemon Squeezy’s own pages, which may use their own cookies under their privacy policy. If we add any cookies or analytics in future, we will update this policy first.
7. Data retention & security
We keep personal information only as long as needed for the purposes above or as required by law. The criteria we use to decide how long: order, invoicing, and tax records are kept for as long as tax and accounting law requires (typically up to seven years); support and contact-form correspondence is kept while we are helping you and for a reasonable period afterward so we can follow up, then deleted; license-activation records are kept for the life of the license so we can validate and restore it; and server security logs are short-lived and rotate automatically. When information is no longer needed under these criteria, we delete or de-identify it. We use reasonable administrative and technical safeguards, but no method of transmission or storage is completely secure.
8. Your choices and rights
You may request access to, correction of, or deletion of your personal information, and you may opt out of non-essential messages, by emailing [email protected]. We will honor applicable rights and will not discriminate against you for exercising them.
EU/UK residents. Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time where processing is based on consent (without affecting processing before withdrawal). We do not use automated decision-making that produces legal or similarly significant effects. You also have the right to lodge a complaint with a supervisory authority — in the EU, the data-protection authority of your member state; in the UK, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first at [email protected], but you may complain to a regulator at any time.
California residents. You may have rights under the CCPA/CPRA, including to know, access, correct, and delete personal information. We do not sell or “share” personal information for cross-context behavioral advertising. Do Not Track and Global Privacy Control: because this site does not track visitors across sites and runs no analytics, there is nothing for a Do-Not-Track or GPC signal to switch off — we treat every visitor as if such a signal were present.
9. Children
The Services are not directed to children under 13 (or under 16 where applicable), and we do not knowingly collect their personal information. If you believe a child provided us information, contact us and we will delete it.
10. International users & transfers
We are based in the United States and process information there, so if you use the Services from outside the U.S. your information will be transferred to and processed in the U.S. Where EU/UK law applies to a transfer, we rely on appropriate safeguards: our service providers (hosting, payments, email) commit to Standard Contractual Clauses (and the UK Addendum or IDTA where applicable) in their data-processing terms, and/or participate in the EU-U.S. Data Privacy Framework. You can request more information about these safeguards at [email protected].
11. Changes
We may update this Policy; the “Last updated” date reflects the current version.
12. Contact
Privacy questions: [email protected] (XARDAS AI LLC).