[xocipher]_
  • Services
  • Software
  • Tools
  • About
  • Get in Touch

// LEGAL

Privacy Policy

How Xocipher collects, uses, and protects your personal data.

Last updated: July 17, 2026

Xocipher ("Xocipher", "I", "me", "we") is operated by an individual developer based in Sweden. This Privacy Policy explains what personal data is collected through xocipher.com (the "Site"), the software distributed from it (the "Tools"), and the privacy and security services we provide (the "Services"), why it is collected, and what rights you have over it under the EU General Data Protection Regulation (GDPR) and applicable Swedish law. Because the Services can involve more sensitive information than a website visit, please read Sections 2 and 3 carefully.

Contents

  1. 1. Controller & Processor Roles
  2. 2. Data We Collect
  3. 3. Special Category Data
  4. 4. Legal Basis for Processing
  5. 5. How We Use Your Data
  6. 6. Sharing & Sub-Processors
  7. 7. International Transfers
  8. 8. Data Retention
  9. 9. Your Rights
  10. 10. Data Breach Notification
  11. 11. Cookies & Tracking
  12. 12. Children's Privacy
  13. 13. Security
  14. 14. Changes & Contact

1. Controller & Processor Roles

For most processing, including the Site, purchases, and direct engagements with individuals, the data controller is the individual developer operating Xocipher, based in Sweden. You can reach the controller using the details in Section 14.

Where Xocipher processes personal data on behalf of and under the documented instructions of a business or organizational client (for example, handling data about that client's staff), Xocipher acts as a data processor for that client under GDPR Article 28, and a written data processing agreement governs that relationship. Nothing here overrides such an agreement.

2. Data We Collect

Xocipher collects only the personal data needed for the interaction you choose:

  • Contact and waitlist: your name, email address, and message content when you use the contact form or email us.
  • Purchases: when you buy a Tool, our payment provider (Gumroad) processes your purchase and shares limited order and email information with us; we do not receive or store your full card details.
  • Account registration and login: if you create an account, we store your name and email, a salted hash of your password (never the password itself), and a session token so you stay signed in. We send verification and password-reset emails, and you can delete your account and its data yourself at any time.
  • Service intake and authorization: to deliver the Services you may provide identifying details (such as name, addresses, phone numbers, dates of birth, and account identifiers), the accounts, devices, or profiles in scope, and your written authorization to act on them.
  • Device and account hardening: technical details about the devices and accounts we harden, and, only where strictly necessary and with your authorization, temporary access to perform the work.

We ask you not to send us passwords or full credentials in plain text. Where a credential is genuinely required to perform a Service, we will tell you how to share it securely and we minimize how long it is held. Fonts on this Site are self-hosted, so no font-related data is sent to any third-party font provider.

3. Special Category Data

We do not seek "special category" data (GDPR Article 9), such as data revealing health, political views, religion, sexual orientation, or biometric identifiers. Please do not include it unless it is genuinely necessary for a Service. Where processing such data is unavoidable to deliver what you have asked for, we will rely on your explicit consent (Article 9(2)(a)) and process only the minimum required.

4. Legal Basis for Processing

We process personal data under the following legal bases (GDPR Article 6, and Article 9 where relevant):

  • Contract (Art. 6(1)(b)): to provide a Tool or Service you have requested and to take steps at your request before entering into a contract.
  • Consent (Art. 6(1)(a); Art. 9(2)(a) for special category data): when you submit the contact or waitlist form, authorize us to act on specific accounts or data, or provide sensitive information. You can withdraw consent at any time (GDPR Article 7).
  • Legitimate interest (Art. 6(1)(f)): to respond to inquiries, keep records of correspondence and engagements, secure the Site, and prevent misuse; balanced against your rights.
  • Legal obligation (Art. 6(1)(c)): to meet accounting, tax, and other legal requirements.

5. How We Use Your Data

Personal data is used to:

  • respond to your inquiry and provide the Tool or Service you requested;
  • carry out the migrations and device hardening you have authorized;
  • notify you about tools, waitlists, or updates you asked to hear about;
  • keep records of correspondence, authorizations, and engagements; and
  • meet our legal and accounting obligations.

We do not sell or rent your data, and we do not use it for advertising or automated decision-making that produces legal effects.

6. Sharing & Sub-Processors

We do not share your personal data except with the service providers needed to operate, and only as needed:

  • Cloudflare: hosting the Site and running the serverless function that forwards contact submissions to our inbox.
  • Gumroad: processing payments and delivery for paid Tools.
  • Email provider (Brevo or Resend): sending account verification and password-reset emails; it processes your email address for delivery.
  • Where required by law or to establish, exercise, or defend legal claims.

Each provider processes data under its own terms and, where it acts for us, under a data processing agreement. If we add or change a provider that handles your personal data, we will update this list before it goes live.

7. International Transfers

Some providers (such as Cloudflare and Gumroad) may process data outside the European Economic Area, including in the United States. Where this occurs, transfers rely on an appropriate safeguard under GDPR Chapter V, such as EU-US Data Privacy Framework participation or Standard Contractual Clauses. We keep such transfers to what is necessary to run the Site, the Tools, and the Services.

8. Data Retention

We keep personal data only as long as needed for the purpose it was collected:

  • Contact and waitlist messages: until your request is resolved and for a reasonable reference period afterward, then deleted or anonymized.
  • Service intake, authorizations, and engagement records: for the duration of the engagement and a limited period afterward to evidence the work and authorization, then deleted.
  • Purchase and accounting records: for the period required by tax and accounting law.

Sensitive details and any temporary credentials are held for the shortest time possible and securely deleted once the work is done.

9. Your Rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you (Art. 15);
  • request correction of inaccurate data (Art. 16);
  • request erasure, the "right to be forgotten" (Art. 17);
  • request restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time, without affecting processing already carried out (Art. 7(3)); and
  • lodge a complaint with a supervisory authority: in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se (Art. 77).

To exercise any right, contact us using Section 14. We respond without undue delay and within one month, as required by GDPR Article 12, and may need to verify your identity first. If you have an account, you can also erase it and its data yourself from your account page at any time.

10. Data Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the IMY without undue delay and, where feasible, within 72 hours of becoming aware of it (GDPR Article 33). Where the breach is likely to result in a high risk to you, we will also inform you without undue delay (GDPR Article 34). Where we act as a processor for a client, we will notify that client without undue delay so they can meet their own obligations.

11. Cookies & Tracking

This Site does not set its own analytics, advertising, or tracking cookies, and we do not use session-recording tools. Hosting infrastructure (Cloudflare) may set strictly necessary or security cookies and keep security logs under its own policy. If we ever add optional analytics, we will ask for your consent first, in line with Swedish ePrivacy rules, and update this policy before it goes live.

12. Children's Privacy

The Site, the Tools, and the Services are intended for adults and are not directed at children. In Sweden, the age of digital consent under GDPR Article 8 is 13. We do not knowingly collect personal data from children below that age without appropriate consent; if you believe a child has provided us with personal data, contact us and we will delete it.

13. Security

We apply appropriate technical and organizational measures (GDPR Article 32), including encryption in transit and at rest where appropriate, access control, and data minimization, to protect the personal data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to keep what we hold to a minimum and to protect it.

14. Changes & Contact

We may update this Privacy Policy as the Site, Tools, or Services evolve; the "Last updated" date above reflects the most recent revision, and material changes will be reflected here before taking effect. Questions about this policy, or requests relating to your personal data, can be sent to contact@xocipher.com.

[xocipher]

Security tooling and hands-on privacy engineering.

Site

Home Services Software Tools FAQ About Contact

Legal

Privacy Policy Terms of Service Services Agreement EULA

© Xocipher. All rights reserved.

Services are defensive privacy and security work for lawful clients. Tools are for use only within engagements and bug bounty programs you are personally authorized to test.