← Back to Qixoo

Privacy Policy

Effective: 10 July 2026 · Version 1.2

1. Who we are

Qixoo (“we”, “us”) is a software-as-a-service product that lets you add an inline content editor to your existing website. The service is operated from Spain (European Union); the data controller is the operator of Qixoo, reachable at the contact below.

Contact: hello@qixoo.app.

2. What we collect

We collect only what we need to run the service.

Account data

Site data

Visitor data (people who visit YOUR site)

The embed script (qixoo.js) sets no cookies, does no cross-site tracking, and shares nothing with advertisers. By default it only fetches your saved content edits from our API. Two things happen only if you enable them:

For visitor data collected on your site, you are the data controller and Qixoo processes it on your behalf. Make sure your own site's privacy notice covers the forms and analytics you enable.

3. Why we collect it (legal bases)

We do not use your data for advertising, profiling, or any kind of analytics resale, and we do not sell personal data.

4. Where it lives (processors & transfers)

We use a small set of service providers (processors):

Where a provider processes data outside the EU/EEA, transfers rely on an adequacy decision or standard contractual clauses. Fonts and all other page assets are served from our own domain — your browser makes no font requests to Google or any other third party.

5. AI processing

When you use an AI feature (rewriting text, building a site, translating, the support assistant), the content needed for that action — your prompt and the relevant page text or structure — is sent to our AI providers (Google, Anthropic) to produce the result, under their API terms. We don't use your content to train our own models. Please don't put sensitive personal data (health, financial, ID numbers) into AI prompts.

6. How long we keep it

We keep your data for as long as your account exists. When you delete your account (see §8) we hard-delete every row tied to your user — including sites, blocks, uploads, form submissions, and any client-logins you created. Sign-in links expire after 15 minutes (48 hours for client invitations); sign-in sessions expire automatically after at most 30 days (staff sessions after 7 days). Short-lived technical logs (web-server request logs used for debugging and abuse prevention) are kept for up to 30 days.

7. Cookies & local storage

The dashboard uses your browser's localStorage and sessionStorage to keep you logged in and remember preferences (panel position, dismissed welcome banner, current site list). Nothing in there is sent anywhere else. We don't set any cookies at all.

The embed script on your customer-facing site uses sessionStorage only when you open the editor (it holds the short-lived edit token across F5). Regular visitors don't trigger it.

8. Your rights

Under GDPR you have the right to:

9. Security & incident notice

All traffic is encrypted in transit (HTTPS everywhere; our domain is HSTS-preloaded, so browsers refuse unencrypted connections). Sign-in links, session tokens and edit tokens are stored only as one-way hashes, never in plain text; staff passwords are stored with bcrypt. Access to production data is limited to the operator team. If a security incident ever affects your personal data, we will notify you and the relevant supervisory authority without undue delay — within 72 hours where the GDPR requires it.

10. California residents (CCPA/CPRA)

Qixoo does not currently meet the size thresholds that make the California Consumer Privacy Act apply to us — but we honor its rights for California residents anyway:

11. Children

Qixoo is not intended for users under 16. If you believe a child has registered, contact us and we'll remove the account.

12. Changes to this policy

If we update this policy materially, we'll notify active accounts by email at least 14 days before the change takes effect.

If anything here is unclear or you want to invoke one of the rights in §8, just email hello@qixoo.app.