Who we are

XeoNote is a product of Ether-X Ltd, a company registered in England & Wales (Company No. 17123706). Our registered office is 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom. We are registered with the UK Information Commissioner’s Office under registration ZC138203.

For data-protection purposes, Ether-X Ltd is the data controller of any personal data you give us through xeonote.com or the XeoNote apps. You can reach our data protection contact at [email protected].

What we collect, and why

We try to collect as little as the job needs.

Things you tell us directly

  • When you create an account: your email address, your chosen password (hashed; we never see the plaintext), and an optional display name. Lawful basis: contract — we can’t run an account without it.
  • When you contact us: your name, email, company name (optional), and the contents of your message. Lawful basis: legitimate interests in answering enquiries.
  • When you pay us: billing details handled by Stripe; we receive enough to issue invoices and reconcile payments. Lawful basis: contract and legal obligation (tax records).

Things we collect automatically

  • Server logs: timestamp, requested URL, response code, hashed IP address (sha256 with a daily-rotated salt), and a coarse user-agent string. Kept for 30 days for security and debugging. Lawful basis: legitimate interests.
  • Marketing site analytics: aggregated, cookieless page views via a self-hosted Plausible instance in the UK. We don’t link analytics to individual people. Lawful basis: legitimate interests and Article 6(1)(f) UK GDPR.

Things we deliberately don’t collect

  • The content of your encrypted notes. They’re encrypted on your device with AES-256-GCM before they reach us. We hold ciphertext and could not read your notes if we tried.
  • Behavioural advertising profiles, fingerprinting signals, or cross-site tracking data.
  • Third-party trackers, Facebook Pixel, Google Analytics, session-replay tools, or heatmaps.

How we use your data

  • To provide the XeoNote service you signed up for (sync your notes between devices, share Spaces with your team, send transactional emails like password resets).
  • To improve the product based on aggregated, anonymised usage trends.
  • To respond to support and sales enquiries.
  • To meet our legal obligations (tax, accounting, lawful requests from authorities).

We do not sell your personal data. We do not use your notes to train AI models. We have no advertising business.

Where your data lives

Account data and note ciphertext for the standard XeoNote service is stored in the United Kingdom (London and Manchester data centres, on a MariaDB Galera high-availability cluster).

Team customers can elect for dedicated tenancy in the European Union (Frankfurt). Enterprise customers can elect for dedicated tenancy in the UK, EU, or US. The choice is yours; we honour it. See the Security page.

If we ever need to transfer personal data outside the UK or EEA, we’ll use the UK International Data Transfer Agreement and EU Standard Contractual Clauses as appropriate.

How long we keep your data

  • Account data: while your account is active, plus 30 days after closure to allow recovery. After that, your account record and notes are permanently deleted.
  • Marketing-site enquiries: 24 months from your last contact, then deleted automatically.
  • Server logs: 30 days.
  • Billing records: 7 years from issue, as required by HMRC.
  • Backups: encrypted backups are retained for 35 days on a rolling basis. Deletion requests are honoured at the live tier immediately and propagate through backups within 35 days.

Sub-processors

We keep the list short on principle. Our current sub-processors are:

  • Stripe Payments UK Ltd — payment processing (United Kingdom)
  • ActiveCampaign LLC — transactional email delivery (United States; covered by eu sccs)
  • Apple Inc. — App Store distribution and iOS push notifications (United States; covered by eu sccs)

We notify Team and Enterprise customers in advance of any changes to this list. The current list is also published on the Security page.

Your rights

Under the UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Erase your data ("right to be forgotten"), subject to legal-retention obligations.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw any consent you’ve given.
  • Complain to the Information Commissioner’s Office if you think we’ve got something wrong.

To exercise any of these rights, email [email protected]. We’ll respond within 30 days as the regulation requires, and usually faster. If you’re already a XeoNote customer, you can also raise a request via support.ether-x.com — it lands in the same queue.

You can also complain directly to the Information Commissioner’s Office. We’d appreciate the chance to put things right first, but it’s your call.

Cookies

We use a small number of strictly-necessary cookies for things like keeping you signed in. We do not use third-party advertising or tracking cookies. Because our analytics are cookieless, we do not show a cookie banner and PECR doesn’t require us to.

If you want, you can clear all cookies for xeonote.com from your browser at any time without affecting the marketing site.

Changes to this notice

If we make material changes to this notice we’ll update the date at the top, and (for account-holders) email you a summary at least 30 days before any substantive change takes effect.

Get in touch

For privacy questions, email [email protected]. For everything else, see the contact page.