Privacy Policy

Owner: XenHawk Inc ("XenHawk")

Address: 2261 Market Street STE 86383, San Francisco, CA 94114

Contact Email: puneet@xhawk.ai

Introduction

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

This Privacy Policy explains how XenHawk Inc ("we," "us," or "our") collects, uses, discloses, and safeguards your information when you use our Application. Please read this policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Application.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
  • Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to XenHawk, a company registered in Delaware, United States at 131 Continental Dr, Suite 305, Newark, DE 19713. We are the creators of SupaVdo, a video recording and editing software service, with a business address at 2261 Market Street, STE 86383, San Francisco, CA.
  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Country refers to: United States
  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the Website.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Website refers to xHawk.ai, accessible from https://xhawk.ai
  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

Your Data Belongs to You

All code, content, and data you provide to XHawk remains your property. We do not sell, license, or share your personal data with third parties. Your data is used solely to provide the services described on our website.

Your Source Code Is Never Used to Train Our Models

Your source code always stays private and isolated. Whenever your code is accessed for analysis or learning path generation, it runs in ephemeral containers that are completely isolated and destroyed after processing. We never use your source code to train, fine-tune, or improve our AI models. Your intellectual property remains yours alone.

Data We Collect

Information You Provide

  • Account information (email, name, profile details)
  • Code repositories you connect to our service
  • Messages and queries you submit to our AI features
  • Payment information (processed by third-party providers)

Automatically Collected Information

  • Usage data (features used, interactions with the Application)
  • Device information (browser type, operating system)
  • IP address and approximate location
  • Performance metrics and error logs

Consent & Records

Where required, we obtain explicit consent (e.g., a checkbox) for data uses and log user ID, timestamp, IP/user-agent, and the terms/policy version accepted.

Data Retention

  • Raw logs:Retained for up to 90 days
  • Learning paths:Stored while your account is active
  • Your code:Processed in ephemeral containers, never persisted

How We Use Your Data

What We Do:

  • Process your code and repositories to generate personalized learning paths
  • Analyze your codebase to provide intelligent code assistance and insights
  • Store your data securely to deliver the features you use
  • Collect basic usage telemetry (e.g., feature usage, performance metrics) to maintain and improve service reliability

What We Do NOT Do:

  • We do not sell your personal contact information or PII
  • We do not share your code or content with third parties
  • We do not use your data for purposes other than providing the Service

Data Usage by User Type

For Enterprise Customers:

  • We will NOT use any Customer Data or AI Outputs to train or fine-tune our models.
  • We will NOT sell, license, or share any Customer Data or Outputs with third parties, except subprocessors needed to provide the Service.
  • We may process de-identified usage/operational telemetry (e.g., performance metrics, feature flags, error rates) to maintain and improve service reliability, security, and support — not for model training.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Ephemeral container isolation for code processing
  • Automatic detection and removal of secrets (keys, tokens, passwords)

Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Request your data in a portable format
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

You may delete your account and all associated data at any time from your account settings.

Cookies & Tracking

We use cookies and similar tracking technologies to enhance your experience:

  • Essential cookies: Required for the Application to function
  • Analytics cookies: Help us understand how you use our service
  • Preference cookies: Remember your settings and preferences

Third-Party Services

We use third-party services to provide and improve our Application:

  • Authentication providers (Clerk)
  • Cloud infrastructure (Google Cloud Platform)
  • Cloud infrastructure (Render)
  • Cloud infrastructure (Vercel)
  • Payment processors (Stripe)
  • Analytics services (PostHog)
  • Email (Resend)

These providers have their own privacy policies and may collect information as described in their respective policies.

Google User Data

This section specifically addresses how XHawk accesses, uses, stores, and protects data obtained through Google APIs, in compliance with the Google API Services User Data Policy.

Google Data We Access

When you connect your Google account, we may access:

  • Basic Profile Information: Your name, email address, and profile picture for account identification and personalization
  • OAuth Tokens: Securely stored authentication tokens to maintain your connection

How We Use Google Data

We use Google user data solely to:

  • Authenticate your identity and maintain your session
  • Display your profile information within the Application
  • Provide the core features of our service that you have requested

We do NOT use Google user data for:

  • Advertising or marketing purposes
  • Selling or renting to third parties
  • Training AI/ML models (for Enterprise customers)
  • Any purpose other than providing the requested service functionality

Google Data Sharing

We do not sell, rent, or share your Google user data with third parties, except in the following limited circumstances:

  • Legal Requirements: We may disclose data if required by law, regulation, or legal process.
  • With Your Consent: We may share data when you explicitly authorize us to do so.

Google Data Storage & Protection

We implement robust security measures to protect your Google user data:

  • Encryption: All Google user data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Strict role-based access controls limit who can access user data
  • Token Security: OAuth tokens are encrypted and stored securely, never exposed in logs or to unauthorized personnel
  • Regular Audits: We conduct regular security assessments and vulnerability testing

Google Data Retention & Deletion

Retention Period:

  • Google profile information is retained while your account is active
  • OAuth tokens are retained until you disconnect your Google account or revoke access
  • Access logs containing Google-related activity are retained for up to 90 days

How to Delete Your Google Data:

  • Disconnect Integration: Go to Settings → Integrations and disconnect your Google account. This immediately revokes our access and deletes stored tokens.
  • Delete Account: Delete your XHawk account from Settings → Account to remove all associated data, including Google user data.
  • Contact Us: Email support@xhawk.ai to request manual deletion of your Google user data.
  • Google Security Settings: You can also revoke XHawk's access directly from your Google Account permissions page.

Upon deletion request, we will remove your Google user data within 30 days, except where retention is required by law.

Children's Privacy

Our Application is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place for such transfers in compliance with applicable laws.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Latest update" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy, please contact us at: puneet@xhawk.ai

Latest update: Jan 2, 2026

XHawk - Build your code-to-context knowledge graph