XAIPT PUBLIC TRUST SURFACE

Privacy Policy

Privacy is part of the security boundary.

Last updated: 29 September 2026. This policy describes the public-launch policy surface for XAIPT Guard. It must be reconciled against the exact qualified Android release, SDK inventory and any admitted backend before Google Play submission.

What XAIPT Guard processes

XAIPT may process local product state needed for configured protection targets, authority state, Recovery, Vault metadata and security evidence. The final Play Data Safety declaration must identify any data that leaves the device, why it is collected, whether it is shared, and the behavior of every included SDK.

Sensitive permissions and APIs

The Android product uses camera access when the user chooses to scan a Recovery QR. The protection architecture may use Android AccessibilityService for narrow target/window transition observation and enforcement health. XAIPT must provide the required in-app disclosure and affirmative consent before enabling any sensitive capability for which Google Play requires it.

What XAIPT does not need for the current product claim

XAIPT Guard does not require a bank password, UPI PIN, ordinary OTP history or raw biometric template for the current standalone product. Platform biometric results and device-held cryptographic operations are used without XAIPT receiving a reusable biometric template.

Retention and deletion

Local state can be removed through supported app/product flows or by uninstalling the application, subject to Android behavior. If a future public release enables XAIPT account creation or server-held account data, the deletion process and retention rules must be disclosed here and exposed both in-app and through the public deletion resource.

Security

XAIPT aims to minimize sensitive data, separate authority domains, and avoid storing secrets in consumer-visible evidence. No software can promise universal protection against a compromised operating system, privileged malware, or third-party systems that do not participate in XAIPT.

Contact

Privacy questions: support@xaipt.com. Security reports: security@xaipt.com.

Before publication, replace conditional/future wording with the exact final data inventory and developer legal identity used in the Play listing.