// LEGAL
Services Agreement
The terms that apply when you engage Xocipher's privacy and security services.
Last updated: July 17, 2026
This Services Agreement ("Agreement") governs the defensive privacy and security services (the "Services") that Xocipher, an individual developer based in Sweden ("Xocipher", "we"), provides to you (the "Client", "you"). It applies together with the Terms of Service and the Privacy Policy; where those conflict with this Agreement on the subject of the Services, this Agreement controls. By confirming an engagement, you agree to this Agreement.
Contents
1. The Services
The Services are defensive and may include privacy migration, device and account hardening, fingerprint and telemetry minimization, and threat-model consultation. The specific deliverables, scope, timeline, and price for your engagement are as agreed with you before work begins (an "Engagement"). Xocipher provides the Services with reasonable professional skill and care.
2. Scope & Authorization
Xocipher works only on accounts, devices, profiles, and data that you own or are fully authorized to control, and only within the agreed scope. Before any hands-on work, you must provide written authorization identifying what is in scope, using the Client Authorization form or an equivalent signed record. Work outside the agreed scope is not performed without a further written authorization.
3. Client Responsibilities
You agree that:
- you own or are authorized to control everything in scope, and you will not ask Xocipher to access or change anything belonging to another person without that person's documented authorization;
- you will provide accurate, complete information and reasonable cooperation;
- you have made independent backups before work begins, and you accept that migrations, configuration changes, and hardening carry an inherent risk of disruption or data loss;
- you will not send passwords or full credentials in plain text; where a credential is genuinely required, you will share it through the secure method we specify; and
- you remain responsible for your own lawful conduct and for your accounts after handover.
4. No Guarantee of Results
Privacy and security are ongoing and adversarial. We do not guarantee any specific outcome. In particular, we do not guarantee that your data will be removed from, or stay removed from, every data broker or search site; that you will not be affected by a breach, hack, scam, or identity theft; or that any provider, tool, or configuration is free of vulnerabilities. Timelines and coverage figures are indicative, not promises.
5. Fees, Billing & Recurring Plans
Fees are as quoted for your Engagement or as displayed for a plan at the time of purchase. One-time Services are payable as agreed. Recurring engagements (such as a retainer) bill periodically in advance and renew automatically until cancelled. You can cancel a recurring plan at any time to stop future renewals, effective at the end of the current billing period. Prices may change on renewal with prior notice. As stated on the Site, pricing is kept as accessible as possible, and reduced rates may be offered at Xocipher's discretion for those less able to pay.
6. Cancellation & Withdrawal
If you are a consumer in the EU or EEA, you generally have a 14-day right to withdraw from a distance contract for Services. Because Services are often time-sensitive, you may ask us to begin during that period. If you do:
- you expressly request that performance begin before the withdrawal period ends and acknowledge that, once the Service is fully performed, you lose the right of withdrawal; and
- if you withdraw while a Service is only partly performed, you will pay a proportionate amount for the work already carried out up to the moment you tell us you are withdrawing.
Recurring plans can be cancelled at any time for future periods. Statutory consumer rights are not affected by this section.
7. Data Protection
Personal data handled during the Services is processed in line with our Privacy Policy and the GDPR. Where we process personal data on your behalf as a processor (for example, for a business client), a written data processing agreement under GDPR Article 28 applies and sets out the subject matter, duration, nature and purpose of processing, the types of data and categories of data subjects, and the parties' obligations. We apply data minimization, hold sensitive details and any temporary credentials for the shortest time necessary, and delete them securely once the work is complete.
8. Confidentiality
Xocipher keeps your information confidential and uses it only to provide the Services, except where disclosure is required by law or is necessary to establish, exercise, or defend a legal claim. This obligation continues after the Engagement ends. With your permission, Xocipher may reference the engagement in anonymized, non-identifying terms.
9. Liability
To the maximum extent permitted by law, Xocipher is not liable for indirect, incidental, special, or consequential loss, or for loss of data, profits, or goodwill; for issues, damage, or vulnerabilities that pre-existed the Engagement or arise from your own systems, providers, or actions; or for the acts, outages, or breaches of independent third-party products and services. Where liability cannot be excluded, Xocipher's total aggregate liability for a claim arising from the Services shall not exceed the greater of the fees you paid for the relevant Service in the six (6) months before the claim, or 1,000 SEK. Nothing here limits liability for death or personal injury caused by negligence, for fraud, for gross negligence or intentional misconduct, or for any liability that cannot be limited under mandatory law, including mandatory consumer law.
10. Defensive Use & Right to Refuse
The Services are for lawful, defensive purposes only. Xocipher may carry out light identity and purpose vetting and will refuse or stop any engagement that appears intended to evade the law, surveil, stalk, or harm another person, or access anything you are not authorized to control. Refusing or stopping such work is not a breach of this Agreement by Xocipher.
11. Term & Termination
This Agreement applies from the start of your Engagement until it ends or a recurring plan is cancelled. Either party may end an Engagement on reasonable notice. Xocipher may suspend or end an Engagement immediately where required by law, for non-payment, or where Section 10 applies. If Xocipher ends a prepaid Service without cause on your part, the unused portion is refunded. Terms that by their nature should survive (including confidentiality, liability, and data protection) continue after termination.
12. Governing Law & Contact
This Agreement is governed by the laws of Sweden. If you are a consumer, you keep the benefit of the mandatory consumer-protection rules and, where applicable, the courts of your country of residence; EU consumers may also use the Online Dispute Resolution platform at ec.europa.eu/consumers/odr. Questions about this Agreement can be sent to contact@xocipher.com.