Legal

Privacy Policy

Last updated: 28 September 2026

We treat the protection of personal data as a structural requirement, not a marketing claim. This website is built to collect as little data as is legally and technically possible.

Controller

XBANQ GmbH, Neuhofer Weg 2, 91257 Pegnitz, Germany. E-mail: hello@xbanq.com.

Data protection officer

XBANQ GmbH is not required to appoint a data protection officer under Art. 37 GDPR and §38 BDSG, as the relevant thresholds are not met. Please direct data protection enquiries to hello@xbanq.com.

Hosting

This website is hosted on infrastructure operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; a data processing agreement pursuant to Art. 28 GDPR is in place. Accounts, licences and orders are managed in a Supabase database we operate ourselves on the same infrastructure in Germany — no external database service.

SSL/TLS encryption

This website uses SSL/TLS encryption for security reasons. You can recognise an encrypted connection by the padlock symbol and the https:// prefix in your browser's address bar. Data transmitted between your device and the server cannot be read by third parties.

Server logs

The hosting provider creates technical access logs containing the IP address, timestamp, requested resource, HTTP status code and user agent. These serve security and operational purposes only and are deleted after 14 days at the latest. Legal basis: Art. 6 (1) (f) GDPR.

Account, licences and app downloads

For accounts, licences and app downloads we process the e-mail address you sign in with, the one-time sign-in code, your name if you choose to provide one, your date of birth (optional — solely to verify the minimum age; where a product's minimum age allows it, you may instead declare that you meet it, and we then record only that the declaration was made; for products with a higher minimum age the date of birth is required), and the devices you bind to your licences. The legal basis is Art. 6 (1) (b) GDPR (conclusion and performance of the contract); the age check rests on Art. 6 (1) (c) GDPR. Sign-in codes are sent by Resend Inc. (USA) as our processor under the EU Standard Contractual Clauses (see “Transfers to third countries”). If you sign in with Apple or Google, we receive from that provider the e-mail address and, where the provider shares it, your name; when your account is deleted we also revoke the sign-in tokens stored with the provider, as far as the provider supports this. Accounts, licences and device bindings are kept in the self-operated database in Germany described above. Our desktop apps run on your device and process your content locally; they communicate with our servers only for the purposes described here. XBANQ® Focus offers an optional, end-to-end encrypted synchronisation of notes and settings between your devices — our servers store only the encrypted material and cannot read its content. For store reviews we operate demo accounts that process only the data described here for account operation, hold no paid licences, and whose device sessions expire within 24 hours. To improve the sign-in flow we record pseudonymised flow steps (screen, product, language, a daily-changing pseudonymous hash per flow; legal basis: Art. 6 (1) (f) GDPR) — no person can be traced back from them; they are stored for the duration of operations and not shared. If you delete your account, a fourteen-day grace period applies, after which account data and licences are deleted and, as far as the provider supports it, the sign-in tokens held with Apple or Google are revoked; deletion is blocked while a subscription is still running or certain roles remain (for example last administrator of a team).

Purchase processing

When you buy a paid plan we direct you to the checkout of our payment provider Stripe (Stripe Payments Europe Ltd., Ireland). We store the order (product, plan, price, currency), the invoice, and your consent under § 356 (6) of the German Civil Code — time, version of the consent text, language and billing country, without an IP address — as evidence of the contract. Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for invoice retention. Payment data is processed exclusively by Stripe under its own privacy policy; invoices and accounting records are retained for up to ten years under German commercial and tax retention duties (§ 147 AO, § 257 HGB). The seven-day trial runs without a payment method and without the Stripe checkout; the account rules above apply to it.

Purchases in the Mac App Store

When you buy one of our apps in Apple's Mac App Store (for example XBANQ® Decision), Apple is the merchant: Apple processes the payment under its own privacy policy, and no payment data reaches us. The app transmits Apple's cryptographically signed purchase receipt to our server, where the signature is verified against Apple's public certificates. We then store the transaction and product identifiers, the app, the purchase and expiry dates, the revocation status, the number of devices the licence covers, the assignment to your account and the signed receipt itself — in order to establish and administer your licence entitlement (validation, device bindings, renewals, revocations) across your devices. Apple also notifies us of status changes to the purchase (renewal, refund, revocation). The legal basis is Art. 6 (1) (b) GDPR. This data is retained for as long as the entitlement exists; it is our evidence of the licence granted.

Cancellations and withdrawals on this website

The forms at /kuendigen and /widerruf take your cancellation (§ 312k BGB) and your withdrawal (§ 356a BGB). We store the name, the e-mail address and the contract or product you name, for cancellations the type and, if given, your reason, for withdrawals the order date — each together with the time of receipt, a reference code, the language of the declaration and the IP address of the sending device, as an entry in an audit ledger in our self-operated database in Germany. To match cancellations, your e-mail address is compared — without a login, read-only — against the accounts and subscriptions stored with us; where an active subscription is found we additionally store the end date derived from it and the references to the matched subscription and its account (company identifier). The ledger is the record that your declaration arrived and when, and is the basis for handling it; we process the IP address to defend against abuse and as evidence of receipt. Legal basis: Art. 6 (1) (b) GDPR, and for the IP address Art. 6 (1) (f) GDPR. Entries are retained for up to ten years under commercial and tax retention duties (§ 147 AO, § 257 HGB). The confirmation of receipt is sent by Resend Inc. (USA) as our processor (see “Transfers to third countries”).

Newsletter

If you subscribe to the newsletter we store your e-mail address. The subscription only takes effect once you confirm it via a confirmation e-mail (double opt-in). The legal basis is Art. 6 (1) (a) GDPR; you withdraw consent at any time via the unsubscribe link in every issue, and unsubscription takes effect immediately. Delivery runs through Resend Inc. (USA; see “Transfers to third countries”). Unsubscribed and deleted addresses are removed; proof of consent is kept until withdrawal.

Storage on your device (§25 TDDDG)

This website stores no information on your device and accesses no information already stored there, as long as you do not make a choice. Everything it ever stores is strictly necessary within the meaning of §25 (2) no. 2 TDDDG and follows an action of yours: choosing a language sets the NEXT_LOCALE cookie; saving a preference sets xbanq_pref; signing in with a passkey sets xa_pk_challenge for a few minutes; while a prelaunch gate is active, redeeming access sets xbanq_prelaunch (details in the cookie statement at /cookies). Choosing light or dark keeps that preference in your browser's local storage and never transmits it to us. No consent under §25 (1) TDDDG is required for any of these.

Cookies

Public pages set cookies only as a consequence of your own action — language (NEXT_LOCALE), a saved preference (xbanq_pref), passkey sign-in (xa_pk_challenge), prelaunch access (xbanq_prelaunch). No analytics, marketing or tracking cookies. Signing in — in the console at /app or for the app download at /download — adds authentication cookies (sb-); details are in the cookie statement at /cookies.

Analytics & tracking

The public pages use no analytics tools, no tracking pixels, no fingerprinting and no third-party scripts.

Contacting us by e-mail

If you contact us by e-mail (for example at hello@xbanq.com), we process the personal data you provide — in particular your e-mail address, your name where given, and the content of your message — solely in order to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to entering into or performing a contract, and otherwise Art. 6 (1) (f) GDPR (our legitimate interest in responding to your enquiry). Your data is not passed to third parties unless we are legally obliged to do so. Business correspondence is retained for up to ten years under commercial and tax retention obligations (§147 AO, §257 HGB); all other enquiries are deleted once they are no longer required for their purpose, and after twelve months at the latest.

External links

External links open in a new tab. We have no influence over the data processing practices of external sites and accept no responsibility for them.

AI systems and the EU AI Act

XBANQ software works with AI systems — agents that research, plan, draft and report. Three things the law and our architecture require, stated plainly: First, the language models powering our own infrastructure run locally on our own hardware in Germany; for the console we do not send your content to cloud AI services. Second, the voices on the public demo (the Intelligence page) are computer-generated — as EU AI Act Article 50 (1) transparency requires, they are labelled “AI voices”. Third, our software makes no fully automated decisions with legal or similarly significant effect in the sense of GDPR Article 22: every outward action — a post, a release, a payment — passes an approval gate and is decided by a human. Where we process data on behalf of a customer, GDPR compliance is secured by a data processing agreement, available on request

Transfers to third countries

Accounts, licences, orders and content remain on our infrastructure in Germany. Two service providers also process personal data outside it: Stripe Payments Europe Ltd. (Ireland) for payment processing — payment data is also transferred to the United States within the processing arrangement, safeguarded by the guarantees Stripe provides (EU Standard Contractual Clauses or the EU-US Data Privacy Framework) — and Resend Inc. (USA), which sends every transactional e-mail for us: the one-time sign-in codes, the confirmation, licence, invoice and newsletter mails, the confirmations of receipt for cancellations and withdrawals, and the deletion and waitlist confirmations, on the basis of the EU Standard Contractual Clauses.

Your rights under the GDPR

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7 (3)). Please address requests to hello@xbanq.com.

Supervisory authority

You have the right to lodge a complaint with the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.