← Back to Home

Privacy Policy

Last updated: May 11, 2026 | Effective: May 11, 2026

WENSLink Technologies ("Company", "we", "us") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Xandhi OS platform and related services ("Service"). This policy applies to all users globally and complies with applicable data protection regulations including the Information Technology Act, 2000 (India), GDPR (EU), and other relevant privacy frameworks.

1. Information We Collect

Account Information: When you register, we collect your name, email address, and encrypted password. If you use Google OAuth, we receive your Google profile name and email address. Usage Data: We collect information about how you interact with the Service, including pages visited, features used, build prompts, build frequency, session duration, and interaction patterns. Technical Data: We automatically collect your IP address, browser type and version, operating system, device type, screen resolution, and referring URLs. Payment Information: Payment processing is handled by Razorpay. We do not store your credit card numbers, CVV, or bank account details. We retain transaction IDs, payment status, and subscription details. Generated Content: We may temporarily store prompts and generated code for the purpose of service delivery, debugging, and improvement.

2. How We Use Your Information

We use your information to: (a) provide, maintain, and improve the Service; (b) process payments and manage subscriptions; (c) send transactional emails including account verification, password resets, and payment receipts; (d) send product updates, feature announcements, and marketing communications (with opt-out option); (e) analyze usage patterns to improve our AI models and user experience; (f) detect and prevent fraud, abuse, and security threats; (g) comply with legal obligations and respond to lawful requests; (h) provide customer support and respond to inquiries.

3. Data Storage and Security

Your data is stored on secure servers hosted by Hetzner Online GmbH in Germany. We implement industry-standard security measures including SSL/TLS encryption for all data in transit, encrypted database connections, bcrypt password hashing, JWT token-based authentication with expiration, rate limiting and account lockout mechanisms, regular security updates and patches, automated database backups, and CORS-restricted API access. Despite our security measures, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

4. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We may share data with: (a) AI model providers (OpenRouter, Google, etc.) - prompts are sent for processing but are not used for third-party model training; (b) Razorpay - for payment processing; (c) Google - if you use OAuth authentication; (d) Law enforcement - when required by valid legal process; (e) Service providers - who assist in operating our infrastructure under strict confidentiality agreements.

5. Cookies and Tracking

We use essential cookies for authentication (JWT tokens stored in localStorage). We use analytics tracking to understand page views and user behavior. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but this may affect Service functionality.

6. Your Rights

You have the right to: (a) access your personal data by contacting us; (b) correct inaccurate information in your account settings; (c) request deletion of your account and associated data; (d) export your data in a machine-readable format; (e) opt out of marketing communications using the unsubscribe link in each email; (f) withdraw consent for data processing at any time; (g) lodge a complaint with a data protection authority. To exercise any of these rights, contact: privacy@xandhi.com

7. Data Retention

We retain your account data for as long as your account is active. Build prompts and generated code may be retained for up to 90 days for service improvement. Payment records are retained for 7 years as required by financial regulations. Upon account deletion, personal data is removed within 30 days, though anonymized analytics data may be retained indefinitely.

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.

9. International Data Transfers

Your data may be processed in countries other than your own, including Germany (hosting) and the United States (AI model providers). We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

10. Contact

Data Protection Officer: privacy@xandhi.com
WENSLink Technologies, L24 A South Ex, New Delhi - 110049, India