Who we are
xauapi operates xauapi.com and the xauapi market data service. This policy explains how we handle personal information when you browse the website, create a workspace, subscribe, use the API or MCP service, or contact us. Contact hi@xauapi.com with privacy questions or requests.
Information we collect
Account and workspace information includes your email address, account name, workspace name, account identifiers, setup progress, and account creation and update times. Passwords are stored as hashes. We keep session records, which may include your IP address and browser user agent, to authenticate you and protect your account.
API key records include a key hash, identifying prefix, label, and lifecycle information. A newly generated key is shown once; we do not store the raw key in our account database. API usage records include account identifiers, endpoint patterns, request times, status codes, duration, and usage counters.
Billing records include Stripe customer and subscription identifiers, plan and subscription status, billing periods, invoice references, payment amounts, and receipt-delivery status. Card details are entered on Stripe-hosted pages and handled by Stripe; they are not stored in the xauapi application database.
If you contact us, we receive your email address, message, and information you choose to provide. Do not send passwords, API keys, or card details in support messages.
How we use information
We use information to create and secure accounts, provide market data access, enforce subscription and usage limits, process subscriptions, send password-reset emails and receipts, respond to support requests, investigate failures, and prevent abuse. We also retain records needed for billing disputes, accounting, and applicable legal obligations.
Where a legal basis is required, providing your account and paid service relies on performing our agreement with you; security, service reliability, and support rely on our legitimate interests in operating and protecting the service; required accounting and compliance rely on legal obligations. If a separate activity requires consent, we will request it for that activity. You may object to processing based on legitimate interests, subject to applicable law.
Error reporting and security
Browser error reports contain a fixed error category and a normalized page path. They do not send exception text, stack traces, query strings, form values, passwords, API keys, or request bodies. Browser reports are anonymous at the application-report level; our infrastructure still receives the network request, including its IP address. A short-lived hash derived from the IP address and time window limits reporting abuse.
Server-side incidents may include the account identifier already known to the server. Authorized administrators can review account, billing, usage, and incident records to operate and support the service. Administrative actions are audited. We use access controls, hashed credentials, and encrypted connections, but no online system can guarantee absolute security.
How long we retain information
We retain account and workspace records while needed to provide the service and handle account requests. Billing, security, and support records may be retained longer where needed for accounting, disputes, fraud prevention, or legal obligations. We assess retention according to the purpose, sensitivity, and applicable requirements rather than promising a single deletion period for all records.
The service keeps the latest 100 authenticated request log entries and 35 daily usage counters per account, alongside allowance counters needed to enforce the billing period. Error incidents inactive for 30 days and incident-action records older than 90 days are scheduled for cleanup. These limits do not describe separate billing records or infrastructure-provider logs.
Password-reset links expire after 30 minutes. Expiration ends their validity and does not imply immediate deletion of every associated database record. Backups and provider records may remain for their retention periods and applicable obligations.
Your choices and requests
Email hi@xauapi.com to request access, correction, account deletion, or a copy of your personal information. Depending on applicable law, you may also have rights to restrict processing, object, request portability, or withdraw consent where processing relies on it. We may verify your identity before acting and explain any records we must retain. You may complain to the relevant data protection authority.
You can manage subscription cancellation in Billing and revoke API keys in your workspace. Cancellation stops future renewal; it is not an account-deletion request. A deletion request may require us to close your account and end access. We do not make decisions with legal or similarly significant effects solely through automated profiling; service controls enforce authentication, billing status, and usage limits.
Policy updates
We will update this page when our practices change and revise the date above. We will provide additional notice of material changes where required. Contact hi@xauapi.com if you need help understanding this policy.
Provider policies: Cloudflare · Stripe
Questions? hi@xauapi.com
Terms of Service →