July 2026 — the entire x2y suite is now free. Code Leak Detector moves to a one-time $29 on 1 Sep.

View products

Legal · Data protection

Privacy Policy

This Privacy Policy explains how x2y Devs Tools Ltd handles personal data in connection with our software suite, documentation portals and related services. Its central premise is simple and verifiable: our software collects no telemetry, transmits no analytics, and processes all user-supplied content entirely on your own device.

Effective date
1 August 2026
Document version
1.2
Data controller
x2y Devs Tools Ltd
Telemetry collected
0 bytes — by design
01

Overview & scope

This Privacy Policy ("Policy") describes the practices of x2y Devs Tools Ltd ("x2y", "we", "us" or "our") with respect to personal data in connection with the x2y Devs Tools software suite — including x2y AV Ultimate, x2y Authenticator, Code Leak Detector, SiteDirective, x2y SDK, x2y Extractor, x2y Devs Pad and x2y GitIgnore Generator (collectively, the "Software") — and our documentation portals at x2ydevs.xyz and sdk.x2ydevs.xyz (collectively, the "Services"). It applies to every natural person who downloads, installs, accesses or otherwise interacts with the Software or Services ("you" or "your").

This Policy is drafted to satisfy, where applicable, the requirements of the Republic of Kenya's Data Protection Act, 2019 (Cap. 415D), the European Union's General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom GDPR, the ePrivacy Directive (2002/58/EC as amended), and analogous data-protection legislation in other jurisdictions. Where a particular provision of such legislation confers rights or imposes obligations that differ from those described here, the statutory provision prevails to the extent of the inconsistency.

The short version

Our software does not collect, transmit or store any telemetry. We do not require an account to use any product. The only personal data we ever hold is what you voluntarily send us — typically a support email, a legal enquiry, or a payment record handled by a third-party distributor. Everything else stays on your machine.

02

Data controller

For the purposes of the Kenyan Data Protection Act, the GDPR, the UK GDPR and equivalent legislation, the data controller responsible for the personal data described in this Policy is:

Data controller details
Legal namex2y Devs Tools Ltd
Registered officeNairobi, Republic of Kenya
RegistrationPrivate company limited by shares, incorporated under the Kenyan Companies Act, 2015
Data Protection OfficerNot statutorily required at present; privacy enquiries are handled by the designated privacy contact below
Privacy contactprivacy@x2ydevs.xyz
General contactsupport@x2ydevs.xyz

Where x2y acts as a data processor rather than a controller — for example, when handling a support ticket on behalf of an organisational customer — the applicable customer is the controller and x2y processes the relevant data on documented instructions, consistent with Article 28 GDPR and Section 41 of the Kenyan Data Protection Act.

03

The zero-telemetry commitment

The defining characteristic of the x2y suite is that it collects no telemetry. This is an architectural property of the Software, a contractual commitment under our Terms of Use, and a verifiable fact that you can confirm independently.

Concretely, the Software:

  • contains no analytics library, software-development kit, crash reporter, exception tracker, performance monitor, attribution pixel, advertising identifier, or equivalent component, whether first-party or third-party;
  • makes no outbound network connections during installation, activation, runtime, update or uninstallation, except for connections that you explicitly initiate or that your own application generates through the x2y SDK;
  • does not read, transmit, hash, fingerprint or otherwise process device identifiers, hardware serial numbers, MAC addresses, IP addresses, geolocation data, installed-application lists, browser profiles, clipboard contents, keystrokes, screenshots or any analogous signal for the purpose of analytics, diagnostics, marketing or behavioural profiling;
  • does not require, request or store any account, registration, email address, telephone number, username or authentication credential in order to download, install, activate or use any product, whether free or paid; and
  • processes all user-supplied content — files, archives, source code, secrets, credentials, traffic records, documents and repository metadata — entirely within the memory and storage of your own device, without transmission to x2y or any third party acting on x2y's behalf.
How to verify

You can independently verify the foregoing using any standard network-inspection tool — Wireshark, mitmproxy, Fiddler, GlassWire, Little Snitch, the Windows Resource Monitor, lsof -i on macOS, or ss/netstat on Linux — while the Software is installed and running. You should observe zero outbound connections attributable to the Software itself, other than those your own workload generates. We encourage security-conscious users to perform this verification and to publish their findings.

04

What we collect

Because the Software collects no telemetry, the categories of personal data that x2y actually holds are narrow and arise only from direct, voluntary interactions with us or from transactions processed by our distribution partners on our behalf. They are enumerated exhaustively below; if a category is not listed here, we do not collect it.

Categories of personal data held by x2y
CategorySourceHeld by x2y?
Support & legal correspondenceEmails you send to support@, legal@, privacy@ or security@x2ydevs.xyz, and any attachmentsYes
Payment & transaction recordsProcessed by itch.io, Microsoft Commerce and their processors; x2y receives only the minimum settlement and licensing metadata needed to fulfil the licenceMinimal
Vulnerability disclosuresReports sent to security@x2ydevs.xyz, including reporter contact details supplied voluntarilyYes
GitHub interactionsIssues, pull requests, discussions and releases you author on x2y GitHub repositories — governed by GitHub's privacy policyVia GitHub
Documentation portal logsStandard web-server access logs for x2ydevs.xyz and sdk.x2ydevs.xyz (IP address, timestamp, path, user-agent), retained briefly for security and abuse preventionBriefly
Telemetry from the SoftwareNone — the Software transmits nothing0 bytes
Accounts or profilesNone — no account is required or offeredNone
User Data (files, secrets, code, archives, traffic)Processed locally on your device; never transmitted to x2yNever
Device identifiers, fingerprints, geolocationNot collected by the Software or the ServicesNever
Cookies or tracking pixelsNot set by x2y; see Section 15None
05

What we do not collect

For the avoidance of doubt, and because negative statements about data collection are unusually important for a privacy policy, x2y does not and will not, through the Software or the Services:

  • (a)collect, infer or purchase any information about your browsing activity, application usage, contacts, calendar, messages, photos, media library, biometric templates, health data, financial accounts or precise location;
  • (b)build, maintain or contribute to any advertising, marketing, behavioural, psychographic or lookalike profile of you, whether for x2y's own use or for the benefit of any third party;
  • (c)train, fine-tune, evaluate or otherwise use your User Data, prompts, code, files or traffic records to develop, improve or benchmark any machine-learning model, large language model, generative system or analogous technology, whether operated by x2y or a third party;
  • (d)sell, rent, lease, license, barter or otherwise monetise your personal data, in whole or in part, in any form and to any party, including data brokers, advertising networks, analytics vendors or research aggregators; or
  • (e)combine data obtained from the Software or Services with data obtained from other sources for the purpose of identifying, tracking or profiling you across contexts.

The commitments in this Section 5 are contractual as well as descriptive: they are incorporated into the Terms of Use and a material breach of them would constitute a breach of contract actionable under the dispute-resolution provisions of those Terms.

06

Distribution partners

The Software is made available through third-party distribution channels that operate independently of x2y and maintain their own privacy policies, over which x2y exercises no control and for which x2y assumes no responsibility. When you obtain the Software through one of these channels, that channel — not x2y — is the data controller for any personal data it collects in the course of the transaction. The principal channels are:

Distribution channels and their data practices
ChannelTypical data handled by the channelChannel's policy
Microsoft StoreMicrosoft account identifier, billing details, device and store telemetry as described by Microsoftprivacy.microsoft.com
itch.ioAccount email, billing details, download and purchase records as described by itch.ioitch.io/docs/legal/privacy
UptodownDownload logs, device and referral data as described by Uptodownuptodown.com/privacy
APKPureDownload logs, device and referral data as described by APKPureapkpure.com/privacy-policy
npmPackage-download logs, account data for publishers, as described by GitHub/npmdocs.npmjs.com/policies/privacy
GitHubAccount data, repository activity, release-download logs as described by GitHubdocs.github.com/site-policy/privacy-policies

We encourage you to review the privacy policy of whichever channel you use before completing a download or purchase. x2y receives from these channels only the minimum information necessary to fulfil and evidence the licence — typically a transaction identifier, product SKU, Seat count, timestamp and, for paid transactions, a settlement reference. We do not receive your password, full payment-card number, billing address beyond what is required for tax compliance, or any channel-side behavioural telemetry.

07

Voluntary correspondence

When you email x2y at any of the addresses listed in Section 18 — for support, legal, privacy, security-disclosure or general enquiries — we process the content of your message, any attachments, the sender and recipient addresses, timestamps, mail-server headers and any signature-block information you include. We use this data solely to respond to your enquiry, to maintain a record of the interaction for quality and compliance purposes, and, where your message reports a security vulnerability, to coordinate remediation and (with your consent) public disclosure.

We do not mine, analyse, summarise with automated systems, or repurpose the content of correspondence for marketing, product development, model training or any other secondary purpose. Access to the mailbox is restricted to a small number of authorised personnel bound by confidentiality obligations, and messages are retained only for as long as necessary to resolve the matter and satisfy any applicable legal, regulatory, tax, accounting or limitation-period requirement, after which they are securely deleted.

08

Legal bases for processing (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies to our processing of your personal data, we rely on the following lawful bases under Article 6(1), as applicable to each category of processing:

Lawful bases relied upon under Article 6(1) GDPR
Processing activityLawful basisNotes
Fulfilling a paid licence and processing the associated transactionContract Art. 6(1)(b)Necessary to perform the licence agreement with you
Responding to support, legal, privacy and security enquiriesLegitimate interest Art. 6(1)(f)Interest in providing effective support and maintaining a record; balanced against your rights, given the narrow scope and short retention
Complying with tax, accounting, consumer-protection and data-protection lawLegal obligation Art. 6(1)(c)Kenyan Tax Procedures Act, Companies Act, Data Protection Act; EU/UK VAT where applicable
Defending or pursuing legal claimsLegitimate interest / Legal claims Art. 6(1)(f), Art. 9(2)(f)Establishment, exercise or defence of legal claims
Operating and securing the documentation portalsLegitimate interest Art. 6(1)(f)Interest in availability, integrity and abuse prevention; brief log retention
Processing special-category data, if any is incidentally included in correspondenceExplicit consent / Legal claims Art. 9(2)(a)/(f)We do not solicit special-category data; if you include it, we process it only to respond and then delete it

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is proportionate, has a minimal impact on your rights, and is something you would reasonably expect in the context of obtaining and using the Software. You may request a copy of the relevant legitimate-interest assessment by writing to the privacy contact in Section 18.

09

Data retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, and thereafter for as long as is required to satisfy applicable legal, regulatory, tax, accounting, audit and limitation-period obligations. The following table summarises our standard retention periods; shorter periods apply where the purpose is fulfilled earlier, and longer periods apply where a legal obligation or an active legal claim requires it.

Standard retention periods
CategoryStandard retention
Support and general correspondenceUp to 24 months after the last substantive exchange, then securely deleted
Legal, regulatory and tax records (incl. paid-licence transactions)7 years, in line with Kenyan tax and companies legislation, or longer where required
Security-disclosure reportsUntil coordinated disclosure is complete plus 12 months, then archived or deleted
Documentation-portal access logsUp to 30 days, then automatically purged
Data subject access, erasure and objection requestsAudit record retained for up to 36 months to evidence compliance
Telemetry from the SoftwareNot applicable — none is collected

At the end of the applicable retention period, personal data is securely and irreversibly deleted, or, where deletion is not immediately feasible for technical reasons (for example, data residing in immutable backup media), it is cryptographically isolated and excluded from restoration until the media is overwritten in the ordinary course.

10

Sharing & disclosure

x2y does not sell, rent, trade, barter or otherwise monetise personal data, and we do not share it with third parties for their own independent marketing or analytics purposes. We disclose personal data only in the following limited circumstances:

  • (a)Service providers acting as processors. A small number of carefully selected providers — email delivery, payment settlement, cloud infrastructure for the documentation portals, and backup — process data on our behalf under written data-processing agreements that impose confidentiality, security and purpose-limitation obligations consistent with Article 28 GDPR and Section 41 of the Kenyan Data Protection Act. These providers are prohibited from using the data for any purpose other than delivering the contracted service.
  • (b)Distribution partners. As described in Section 6, the distribution channels are independent controllers for the data they collect themselves; x2y shares with them only the minimum licensing metadata needed to fulfil a transaction.
  • (c)Legal compulsion. Where required by a valid court order, subpoena, search warrant, regulatory demand or other binding legal process of competent jurisdiction, or where necessary to comply with applicable law, prevent imminent harm, or protect the rights, property or safety of x2y, our users or the public. Where legally permitted, we will notify you before complying and will seek to narrow the scope of any disclosure.
  • (d)Business transfers. In connection with a merger, acquisition, reorganisation, sale of substantially all assets, or similar transaction, personal data may be transferred to a successor entity, subject to the successor being bound by this Policy or an equivalent one, and to any notice or consent right conferred on you by applicable law.
  • (e)With your explicit consent. In any other circumstance, only where you have given specific, informed and freely given consent, which you may withdraw at any time without affecting the lawfulness of prior processing.
11

Security measures

We implement appropriate technical and organisational measures to protect the personal data we hold against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR and Section 41 of the Kenyan Data Protection Act. Given the deliberately small volume of data we hold, our measures are proportionate and include:

  • encryption of data at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher) for the documentation portals and mail systems;
  • strict access controls on a least-privilege basis, with multi-factor authentication for every administrative account and a small, named set of authorised personnel;
  • audit logging of access to systems that store personal data, reviewed periodically for anomalous activity;
  • regular, encrypted, geographically separated backups with tested restoration procedures;
  • a documented incident-response procedure, including notification to the relevant supervisory authority within 72 hours of becoming aware of a notifiable personal-data breach, and to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and
  • a public security-disclosure channel at security@x2ydevs.xyz for the responsible reporting of vulnerabilities in the Software or Services.

No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. What we can guarantee — and do — is that the attack surface presented by the Software itself is effectively zero, because the Software holds no data of ours to exfiltrate and establishes no connection to us to intercept.

12

International transfers

x2y is established in Nairobi, Kenya. If you are located in the European Economic Area, the United Kingdom, Switzerland or another jurisdiction with restrictive rules on international transfers, please note the following. The personal data we hold about you is minimal (see Section 4) and is processed primarily within Kenya. Where we use service providers located outside your jurisdiction — for example, email-delivery or cloud-infrastructure providers in the European Union or the United States — we rely on one or more of the following transfer mechanisms, as applicable:

  • an adequacy decision issued by the European Commission, the UK Secretary of State, or the relevant Kenyan authority under Section 49 of the Data Protection Act;
  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), including the Annex II technical and organisational measures and a transfer-impact assessment addressing the laws of the destination country;
  • the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, where the UK GDPR applies; or
  • your explicit consent, or another derogation under Article 49 GDPR / Section 49 of the Kenyan Act, where appropriate.

You may request a copy of the applicable transfer safeguards, redacted where necessary to protect confidential commercial information, by writing to the privacy contact in Section 18.

13

Your rights

Depending on your location, you may have some or all of the following rights with respect to the personal data x2y holds about you. Because the data we hold is narrow, most of these rights can be exercised quickly and, in practice, often amount to confirming that we hold little or nothing beyond a past email exchange.

Access

Right of access

Obtain confirmation of whether we process your data, and a copy of the data and the surrounding processing details.

Rectification

Right to rectification

Have inaccurate or incomplete personal data corrected or completed without undue delay.

Erasure

Right to erasure

Request deletion of your data where the legal basis no longer applies, subject to overriding legal-retention obligations.

Restriction

Right to restriction

Restrict processing in certain circumstances, for example while accuracy or a lawful basis is contested.

Portability

Right to portability

Receive your data in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.

Objection

Right to object

Object to processing based on legitimate interests, and to any direct marketing (we conduct none).

Withdrawal

Right to withdraw consent

Withdraw any consent you have given, at any time, without affecting the lawfulness of prior processing.

Automated decisions

No automated decision-making

We do not carry out profiling or solely automated decision-making producing legal or similarly significant effects.

To exercise any of these rights, please contact the privacy address in Section 18. We will acknowledge your request within five (5) business days and respond substantively within thirty (30) calendar days, extendable by a further sixty (60) days for complex or numerous requests, in which case we will inform you of the extension and the reasons within the initial thirty-day period. We may ask for reasonable proof of identity before acting on a request, proportionate to the sensitivity of the data and the risk of unauthorised disclosure. We do not charge a fee for exercising your rights, except where a request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or refuse to act, with an explanation.

14

Children's privacy

The Software and Services are not directed to children, and we do not knowingly collect personal data from anyone below the age of digital consent in their jurisdiction (sixteen (16) under the GDPR, unless a member state has lowered it to thirteen (13); eighteen (18) under the Kenyan Data Protection Act for the purposes of contractual capacity). Because the Software collects no telemetry and requires no account, there is no mechanism by which a child could inadvertently create a data relationship with x2y through normal use of the Software.

If you are a parent or guardian and believe that a child under the applicable age has provided us with personal data — for example, through a support email — please contact the privacy address in Section 18 and we will promptly review and, where appropriate, delete the data.

15

Cookies & local storage

The x2y documentation portals (x2ydevs.xyz and sdk.x2ydevs.xyz) are static, server-rendered sites that do not set any first-party cookies, do not embed third-party analytics, advertising, social-media or tracking scripts, and do not use browser local storage, session storage, IndexedDB or any equivalent client-side persistence for tracking purposes. A single strictly-necessary local-storage key may be used to remember your light/dark theme preference; this key contains no identifier, is never transmitted anywhere, and can be cleared at any time through your browser settings.

The Software itself does not use browser cookies or analogous web-tracking mechanisms, because it does not operate a web session with x2y. Any cookies you encounter while using a distribution channel (Microsoft Store, itch.io, Uptodown, APKPure, npm, GitHub) are set by that channel under its own privacy policy.

16

Do Not Track & global privacy signals

Because the Software transmits no telemetry and the documentation portals perform no tracking, there is nothing for a Do Not Track (DNT) header or a Global Privacy Control (GPC) / opt-out-preference signal to opt out of. We nonetheless honour the intent of such signals as a matter of policy: we do not track, and we will not begin to track, regardless of the signal state. Where a future version of the Services were to introduce any optional, non-essential processing that could be construed as tracking, we would default it to off and respect DNT/GPC as a binding opt-out without requiring further action from you.

17

Changes to this policy

We may revise this Policy from time to time to reflect changes in our practices, the Software, the Services, applicable law, regulatory guidance or industry standards. When we make changes that materially affect your rights or the categories of data we process, we will update the "Effective date" and "Document version" at the top of this page, publish a prominent notice on the documentation portals and in the product changelog, and, where required by law, provide advance notice of no less than thirty (30) days before the changes take effect.

Your continued use of the Software or Services after the effective date of a revision constitutes acceptance of the revised Policy. Prior versions are archived and available in machine-readable form upon written request to the privacy contact in Section 18. We encourage you to review this Policy periodically, and we will always indicate the date of the most recent material change at the top of the page.

18

Contact & supervisory authority

Questions, requests and complaints concerning this Policy or our data practices should be directed to the appropriate channel below. We aim to acknowledge privacy enquiries within five (5) business days and to provide a substantive response within thirty (30) calendar days, subject to the complexity of the matter and any applicable statutory deadlines.

Data controllerx2y Devs Tools Ltd
Registered officeNairobi, Republic of Kenya
Privacy & data rightsprivacy@x2ydevs.xyz
Data Protection Officerdpo@x2ydevs.xyz
Security disclosuressecurity@x2ydevs.xyz
General & supportsupport@x2ydevs.xyz

Supervisory authorities

If you are located in Kenya and believe that we have not addressed your concern satisfactorily, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya at odpc.go.ke. If you are located in the European Economic Area, you have the right to lodge a complaint with the data-protection authority of your member state of habitual residence, place of work, or the place of the alleged infringement; a directory is maintained by the European Data Protection Board at edpb.europa.eu. If you are located in the United Kingdom, you may complain to the Information Commissioner's Office at ico.org.uk. We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority.

19

Revision history

The table below records material revisions to this Policy. Earlier versions are available in machine-readable form upon written request to privacy@x2ydevs.xyz.

Revision history of the Privacy Policy
DateVersionSummary of changes
1 Aug 20261.2Added Section 19 (revision history); expanded Section 8 with explicit Article 6(1) mapping; clarified international-transfer mechanisms in Section 12; added GPC/Do Not Track statement in Section 16.
1 Jul 20261.1Reflected transition of the suite to donationware and the introduction of the Code Leak Detector paid tier; confirmed that payment metadata is the only new data category, processed via third-party distributors.
14 Oct 20251.0Initial publication of the Privacy Policy, coinciding with the founding of x2y Devs Tools Ltd and the first public release of x2y AV Ultimate.

The bottom line

We built software that has nothing to report

The simplest privacy policy is the one with the least to disclose. Our software collects zero telemetry, requires no account, and processes everything on your machine. What remains is a handful of voluntary emails and the minimum transaction metadata our distributors pass us — and that is all this policy has to cover.

Policy metadata
Effective1 August 2026
Version1.2
Controllerx2y Devs Tools Ltd · Nairobi
Telemetry0 bytes — by design and by contract