XActions Privacy Policy
Effective October 5, 2026
XActions, operated by Xintech LLC, delivers user-configured push notifications and optional fallback phone calls.
Data we process
- Random account, session, topic, and publisher identifiers. Session tokens and sign-in challenges are stored as one-way hashes. When you use Apple sign-in, the Apple authorization grant needed for later revocation is stored using authenticated encryption.
- APNs device tokens, device identifiers, topic names and titles, notification titles, bodies, sources, delivery state, acknowledgements, and usage counters.
- For free accounts, a one-way hash of the normalized sign-in email. The delivery provider receives the email address long enough to send a magic link. If you choose Sign in with Apple, Apple may provide a private relay email address; if you choose Google sign-in, Google provides the authentication assertion and basic account identity needed to sign you in.
- If you enable fallback calls, your phone number, verification and consent state, destination country, call timing, provider call identifier, and outcome. Publishers cannot select the destination number.
- Operational request logs may contain IP address and IP-derived coarse location, user agent, app version, endpoint interaction, response status, and timing. Private
/x/topic capabilities and magic-link query values are redacted or omitted from DOL application logs.
How we use data
We use it to authenticate sessions, route notifications, prevent abuse, enforce free limits, diagnose service problems, provide support, and place user-enabled fallback calls. We do not use notification content for advertising.
Service providers
Apple processes push delivery and, when selected, Sign in with Apple. Google processes Google sign-in when selected. Configured email and phone-verification providers process sign-in or verification delivery. Twilio may process verified phone numbers, call audio instructions, and call metadata when fallback calling is enabled. Their own terms and privacy practices also apply.
Retention and deletion
Notification content and its dependent acknowledgement and call-attempt records are retained for up to 30 days for anonymous accounts and 90 days for free accounts, then physically deleted by bounded background cleanup. DOL and hosting access logs are kept for up to 30 days. Expired or consumed sign-in and verification challenges and expired or revoked free-account sessions become eligible for cleanup after 24 hours.
An anonymous account is automatically deleted after 90 days without either a successful authenticated app or management request or a successful publication request, including an idempotent replay, to one of its topics. An anonymous bearer has no separate fixed or idle expiration while that account remains active because it is the account's only recovery and deletion credential. Adding email recovery converts it to a free account. Free-account sessions expire after at most 365 days and after 90 days without authenticated use; email sign-in can create a replacement session.
Topic deletion removes its notification history and disables publication immediately; a minimal topic-deletion marker may remain for up to 24 hours to make retries safe, then is removed. Removing a device or phone removes that registration. In-app account deletion immediately makes the account and its credentials unusable, then a background cascade removes its topics, devices, history, phone and verification state, email identity, challenges, usage records, and sessions. A minimal tombstone containing a random account identifier, plan, and deletion timestamps is retained for up to 30 days to prevent late requests from recreating deleted data. Separately, HMAC-protected phone-destination counters survive account deletion solely to prevent verification and call limits from resetting. Verification counters expire within one day; call counters expire within 35 days. Background cleanup removes expired counters. An access-log record may remain until its 30-day expiration. Service-provider security or delivery records are controlled by those providers' retention policies.
Device-registration retirement proposals expire after 15 minutes if not accepted. Once accepted, the exact registration and cleanup metadata remain until retirement finishes, including when account deletion interrupts cleanup. Minimal completion receipts remain for 90 days so an interrupted account switch can verify its outcome; they contain random account and device identifiers, authorization-binding metadata and timestamps, but no owner or device bearer tokens or APNs tokens. Background cleanup removes expired proposals and receipts.
Your choices
You can disable calls, disable calls for an individual topic, remove your phone, list and remove devices, delete topics, list and revoke free-account sessions, revoke the current session, or delete the account in the app. Linking Apple or Google is an explicit signed-in action; matching email addresses alone are not treated by XActions as consent to merge different Xin accounts. Deleting only XActions data removes the XActions product membership and data but keeps the Xin account and any other Xin products. Deleting the Xin account is a separate global action that removes all Xin product memberships after linked-identity deletion and Apple authorization revocation where applicable. Sensitive account changes require recent authentication. Notifications may be disabled in iOS Settings.
Contact
Questions or deletion assistance: admin@xintechllc.com.