Privacy policy

XEYE processes the data it needs to give you an account, provide the search service you contract, charge for it and keep it secure. It does not sell data, build profiles or send advertising. This policy explains, in line with Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD), which data is processed, why, who receives it, how long it is kept and how to exercise your rights.

By Joan Martorell

Who is the data controller?

Joan Martorell Coll, a natural person domiciled in Illes Balears, Spain. Contact for anything related to your data: info@xeye.es. The remaining identification details are in the legal notice. No data protection officer has been appointed because the activity does not require one.

Which data is processed and where does it come from?

CategoryDataSource
AccountFirst name, surname, email, password (hash only), language, email verification status, last sign-in date; if you enable two-step verification, its secret and the recovery codes (hashed); if you sign in with Google or Microsoft, the identifier that account gives us; the signup origin, if you arrived through a campaign link (the name of the campaign, of the linking site and of the landing page, never data about you).Registration form, Account page, identity provider or the URL you arrived through.
Content of your listsName and description of each list; text, description, parameters and AI-generated description of each element; embeddings computed by trainings.What you upload to the console.
Use of the serviceAPI keys (hash and prefix only), trainings (dates, status, model, cost), search logs (search term, list, results returned, duration, date, key used, session identifier if your application sends one).Generated when using the console and the API.
Credit and paymentsCredit movements, credit requests (with the reason you give), top-ups; once online payments are enabled, the payment session identifier, the amount, the invoice and the billing details you give Stripe. XEYE never sees or stores your card number.Console and payment gateway.
CommunicationsEmails you send us and the ones we send you (verification, password reset, training notices, balance alerts, replies to requests).You and the service itself.
Technical dataIP address, date and time, requested path, user agent, application errors. Sign-in security logs keep the IP and a partially masked email.Server and proxy logs.
All the data is provided by you when using the service or generated by that use.

Do not request or upload to XEYE data you do not need: search works with descriptive texts of products, articles or questions. If you include personal data of third parties in your lists, you are the controller of that processing and XEYE acts as processor (see below).

PurposeLegal basis (art. 6 GDPR)
Create and manage your account, provide the service (lists, trainings, searches), send you the operational emails of the service and handle your credit requests.Performance of the contract (6.1.b): the terms of service.
Charge for credit, issue invoices and keep accounting and tax records.Performance of the contract (6.1.b) and legal obligation (6.1.c): tax and commercial law.
Keep the service secure: verify the email, limit sign-in attempts and requests, detect abuse, log errors, make backups.Legitimate interest (6.1.f) in protecting the service and its users, and the legal duty of security (art. 32 GDPR).
Check at registration whether your password appears in known breaches (if this check is enabled).Legitimate interest (6.1.f) in avoiding accounts with compromised passwords. Only the first five characters of the password hash leave the server, never the password.
Reply to the enquiries you send us by email.Legitimate interest (6.1.f) in answering whoever writes to us or, where applicable, pre-contractual steps (6.1.b).
Generate AI descriptions for the elements of a list.Performance of the contract (6.1.b). Enabled and disabled per list from the console.
Know which channels (campaigns, sites linking to xeye.es) bring sign-ups, by counting accounts per origin, and measure visits to the website.Legitimate interest (6.1.f) in measuring the reach of the service. Only the name of the campaign or of the referring site is stored, with no third-party cookies or identifiers; visit measurement identifies nobody. No profiling is done.

No automated decisions with legal effects on you are taken, no profiles are built and no marketing communications are sent. If we ever wanted to send you news about the service, we would ask for your consent first.

The data in your lists and of your users: XEYE as processor

For the content you upload to your lists and the searches your own applications send to the API (for example, what your shop's customers type into the search box), you decide which data is processed and why: you are the controller and XEYE is your processor (art. 28 GDPR). XEYE processes it only to provide the service to you and following your instructions, which are the actions you take in the console and through the API. The conditions of that processing (confidentiality, sub-processors, security, deletion at the end, assistance and breach notification) are in the terms of service.

Who receives the data?

XEYE does not disclose data to third parties for their own purposes. To operate it uses providers that process data on behalf of XEYE (processors and sub-processors), under contracts that bind them to process it only to deliver their service:

ProviderWhat it doesWhere it processes the data
IONOS SE (Germany)Hosts the database, the backend and the search engine, and sends the service emails.European Union.
Cloudflare, Inc. (USA)DNS, delivery network and protection of xeye.es; serves the website and the console; check against automated sign-ups (Turnstile) if enabled; visit measurement without cookies or identifiers (Web Analytics); stores the backups, encrypted before they leave the server.Global network; certified under the EU-US Data Privacy Framework.
RunPod, Inc. (USA)Runs each training in a GPU container created and destroyed for that job. It receives the texts of the list and returns the embeddings.RunPod data centres, which may be outside the EU; standard contractual clauses.
Google LLC (USA)Gemini API, which generates the AI descriptions. It only receives the text and description of the elements of lists with AI enabled, under the paid tier of that API: Google processes them as a processor and does not use them to train or improve its models. With a Google account it can also be your identity provider if you sign in with Google.Certified under the EU-US Data Privacy Framework.
Microsoft Corporation (USA)Identity provider if you sign in with a Microsoft account (name, email and identifier).Certified under the EU-US Data Privacy Framework.
Functional Software, Inc. (Sentry, USA)Application error logging (error message, path, browser; no passwords or keys).Sentry EU region (Germany); also certified under the Data Privacy Framework.
Stripe Payments Europe, Ltd. (Ireland)Payment gateway and invoicing of top-ups, once online payments are enabled.European Union; Stripe, Inc. (USA) certified under the Data Privacy Framework.
Superlative Enterprises Pty Ltd (Have I Been Pwned, Australia)Breached-password check, if enabled. It receives only a fragment of the hash, which cannot reconstruct the password or identify you.Receives no personal data.

Public authorities, courts or law enforcement may also receive data when a law requires it. If the list of providers changes, this page will be updated; registered users will be notified by email when the change affects the processing on their behalf.

International transfers

The data is hosted in the European Union. Where a provider is in the United States, the transfer relies on the European Commission adequacy decision for entities certified under the EU-US Data Privacy Framework (Decision (EU) 2023/1795: Cloudflare, Google, Microsoft, Sentry, Stripe) or, failing that, on the standard contractual clauses approved by the Commission (Decision 2021/914), complemented with measures such as encryption in transit (RunPod). You can request a copy of those safeguards at the contact email.

How long is it kept?

DataPeriod
Account, lists, elements, embeddings, API keysWhile the account exists. Deleting it from the console removes them immediately.
Search logsDeleted automatically after 180 days, and earlier if you delete the list or the account.
Trainings no longer in useDeleted automatically after 90 days, with their embeddings.
Credit movements, top-ups and invoicesWhile the account exists and, afterwards, for as long as accounting and tax law requires (up to six years), limited to that purpose.
Technical and security logsServer logs rotate within days; error events are kept in Sentry for up to 90 days.
BackupsEncrypted; daily copies are kept for two weeks and monthly ones for up to six months. Deleted data disappears from them when the copy expires.
Contact emails and requestsUp to one year from the last communication, unless they must be kept to handle a claim.

Your rights

You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you may have given. From the Account page of the console you can change your name, email and password, and delete the whole account. For everything else, write to info@xeye.es from your account email (or attach something that identifies you if you write from another address). We reply within one month at most.

If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, through its electronic office). We would appreciate it if you wrote to us first so we can try to resolve it.

Security

All communication is encrypted (HTTPS). Passwords are stored with a slow hash (BCrypt) and API keys only as a hash: nobody can recover them, not even XEYE. You can enable two-step verification. Server access is restricted by key, backups are encrypted before they leave the server and secrets never travel in the code. Should a security breach affecting your data occur, we would notify the supervisory authority and, where the law requires it, you.

Minors

The service is aimed at people over 18. If we detect an account belonging to a minor, we will close it and delete its data.

Changes to this policy

This page shows the date of its latest version. If a change is significant (new purposes, new providers with access to your data), we will notify registered users by email before applying it.

Keep reading