Privacy Policy
Effective: 10 July 2026 · Version 1.2
1. Who we are
Qixoo (“we”, “us”) is a software-as-a-service product that lets you add an inline content editor to your existing website. The service is operated from Spain (European Union); the data controller is the operator of Qixoo, reachable at the contact below.
Contact: hello@qixoo.app.
2. What we collect
We collect only what we need to run the service.
Account data
- Email address — used to send sign-in links and service notifications. If you sign in with Google, we receive your email address (and its verified status) from Google — nothing else from your Google account.
- Plan, tokens + billing state — current plan tier, billing interval, current period end, and an AI-token ledger (what was granted and spent). No card data is stored by Qixoo; when card payments launch they will be processed by Stripe and only the Stripe customer ID will be kept.
- Support & communications — messages you send to in-app support, support tickets and our replies.
Site data
- Site metadata — the URL, display name and an internal API key for each site you connect.
- Content edits — the text, images, and link URLs you change through the editor (so we can re-apply them on every visitor's page load).
- Uploaded media — image files you upload through the editor. Stored on Supabase Storage in the EU region.
- Form submissions — if your site uses our form handler, we store each submission so you can read it in the dashboard.
Visitor data (people who visit YOUR site)
The embed script (qixoo.js) sets no cookies, does no cross-site tracking, and shares nothing with advertisers. By default it only fetches your saved content edits from our API. Two things happen only if you enable them:
- Form submissions — if a visitor submits a form on your site, the submitted fields are stored so you can read them in your dashboard, and you get an email notification.
- Analytics (optional module) — counts visits with a cookie-free, daily-rotating anonymous hash; the raw IP address is never stored and individual visitors are not identified.
For visitor data collected on your site, you are the data controller and Qixoo processes it on your behalf. Make sure your own site's privacy notice covers the forms and analytics you enable.
3. Why we collect it (legal bases)
- To provide the service (contract) — applying your edits to your site requires storing them.
- To authenticate you (contract) — sign-in tokens are hashed and time-limited.
- To run AI features you invoke (contract) — see §5.
- To answer support requests (contract / legitimate interest).
- To enforce plan limits and prevent abuse (legitimate interest) — usage counts, and IP-based rate-limiting of failed sign-in attempts.
- To send transactional email (contract) — sign-in links, notifications, invitations, support replies.
We do not use your data for advertising, profiling, or any kind of analytics resale, and we do not sell personal data.
4. Where it lives (processors & transfers)
We use a small set of service providers (processors):
- Supabase — database + file storage, hosted in the EU.
- Render — application hosting, EU region (Frankfurt).
- Resend — transactional email delivery (US-based; EU-approved safeguards such as standard contractual clauses apply).
- Google — verifying Google Sign-In, and AI processing for AI features (§5).
- Anthropic — AI processing for certain AI features (§5).
- Stripe — card payments, once online payment launches.
- Cloudflare — DNS for our domain and routing of inbound email: messages you send to our
@qixoo.appaddresses pass through Cloudflare Email Routing and are delivered to a Google (Gmail) mailbox we control.
Where a provider processes data outside the EU/EEA, transfers rely on an adequacy decision or standard contractual clauses. Fonts and all other page assets are served from our own domain — your browser makes no font requests to Google or any other third party.
5. AI processing
When you use an AI feature (rewriting text, building a site, translating, the support assistant), the content needed for that action — your prompt and the relevant page text or structure — is sent to our AI providers (Google, Anthropic) to produce the result, under their API terms. We don't use your content to train our own models. Please don't put sensitive personal data (health, financial, ID numbers) into AI prompts.
6. How long we keep it
We keep your data for as long as your account exists. When you delete your account (see §8) we hard-delete every row tied to your user — including sites, blocks, uploads, form submissions, and any client-logins you created. Sign-in links expire after 15 minutes (48 hours for client invitations); sign-in sessions expire automatically after at most 30 days (staff sessions after 7 days). Short-lived technical logs (web-server request logs used for debugging and abuse prevention) are kept for up to 30 days.
7. Cookies & local storage
The dashboard uses your browser's localStorage and sessionStorage to keep you logged in and remember preferences (panel position, dismissed welcome banner, current site list). Nothing in there is sent anywhere else. We don't set any cookies at all.
The embed script on your customer-facing site uses sessionStorage only when you open the editor (it holds the short-lived edit token across F5). Regular visitors don't trigger it.
8. Your rights
Under GDPR you have the right to:
- Access — download a full JSON dump of everything we store about you. Dashboard → Settings → Export my data, or hit
GET /api/user/export. - Portability — each site you connect gives you a ZIP backup of its edits and uploads on Personal+ tiers.
- Erasure — delete your account and every associated row from the database. Dashboard → Settings → Delete account, or hit
DELETE /api/user/deletewith body{"confirm":"DELETE MY ACCOUNT"}. - Rectification — change your email or site metadata at any time through the dashboard.
- Objection / complaint — contact us, or your local data-protection authority. Our lead supervisory authority is the Spanish AEPD (aepd.es); EU/EEA residents may also complain to the authority of their own country.
9. Security & incident notice
All traffic is encrypted in transit (HTTPS everywhere; our domain is HSTS-preloaded, so browsers refuse unencrypted connections). Sign-in links, session tokens and edit tokens are stored only as one-way hashes, never in plain text; staff passwords are stored with bcrypt. Access to production data is limited to the operator team. If a security incident ever affects your personal data, we will notify you and the relevant supervisory authority without undue delay — within 72 hours where the GDPR requires it.
10. California residents (CCPA/CPRA)
Qixoo does not currently meet the size thresholds that make the California Consumer Privacy Act apply to us — but we honor its rights for California residents anyway:
- Categories we collect: identifiers (email address), commercial information (plan and purchase history), internet/app activity (actions in your own dashboard), and user content (your sites' edits, uploads, form submissions). We do not collect sensitive personal information as defined by the CPRA.
- No sale, no sharing: we do not sell personal information and do not share it for cross-context behavioral advertising — there is nothing to opt out of, so no “Do Not Sell or Share” link is required. There is likewise no ad-tracking for a Global Privacy Control signal to disable.
- Your rights — to know/access, correct, delete, and port your data: use the same self-service tools as §8 (Settings → Export my data / Delete account) or email us. We verify requests via your signed-in account or the email on file.
- Non-discrimination: exercising privacy rights never affects your service or pricing.
- Authorized agents may submit a request on your behalf with proof of authorization.
11. Children
Qixoo is not intended for users under 16. If you believe a child has registered, contact us and we'll remove the account.
12. Changes to this policy
If we update this policy materially, we'll notify active accounts by email at least 14 days before the change takes effect.
If anything here is unclear or you want to invoke one of the rights in §8, just email hello@qixoo.app.