Legal · Data protection
Privacy Policy
This Privacy Policy explains how x2y Devs Tools Ltd handles personal data in connection with our software suite, documentation portals and related services. Its central premise is simple and verifiable: our software collects no telemetry, transmits no analytics, and processes all user-supplied content entirely on your own device.
Overview & scope
This Privacy Policy ("Policy") describes the practices of x2y Devs Tools Ltd ("x2y", "we", "us" or "our") with respect to personal data in connection with the x2y Devs Tools software suite — including x2y AV Ultimate, x2y Authenticator, Code Leak Detector, SiteDirective, x2y SDK, x2y Extractor, x2y Devs Pad and x2y GitIgnore Generator (collectively, the "Software") — and our documentation portals at x2ydevs.xyz and sdk.x2ydevs.xyz (collectively, the "Services"). It applies to every natural person who downloads, installs, accesses or otherwise interacts with the Software or Services ("you" or "your").
This Policy is drafted to satisfy, where applicable, the requirements of the Republic of Kenya's Data Protection Act, 2019 (Cap. 415D), the European Union's General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom GDPR, the ePrivacy Directive (2002/58/EC as amended), and analogous data-protection legislation in other jurisdictions. Where a particular provision of such legislation confers rights or imposes obligations that differ from those described here, the statutory provision prevails to the extent of the inconsistency.
Our software does not collect, transmit or store any telemetry. We do not require an account to use any product. The only personal data we ever hold is what you voluntarily send us — typically a support email, a legal enquiry, or a payment record handled by a third-party distributor. Everything else stays on your machine.
Data controller
For the purposes of the Kenyan Data Protection Act, the GDPR, the UK GDPR and equivalent legislation, the data controller responsible for the personal data described in this Policy is:
| Legal name | x2y Devs Tools Ltd |
|---|---|
| Registered office | Nairobi, Republic of Kenya |
| Registration | Private company limited by shares, incorporated under the Kenyan Companies Act, 2015 |
| Data Protection Officer | Not statutorily required at present; privacy enquiries are handled by the designated privacy contact below |
| Privacy contact | privacy@x2ydevs.xyz |
| General contact | support@x2ydevs.xyz |
Where x2y acts as a data processor rather than a controller — for example, when handling a support ticket on behalf of an organisational customer — the applicable customer is the controller and x2y processes the relevant data on documented instructions, consistent with Article 28 GDPR and Section 41 of the Kenyan Data Protection Act.
The zero-telemetry commitment
The defining characteristic of the x2y suite is that it collects no telemetry. This is an architectural property of the Software, a contractual commitment under our Terms of Use, and a verifiable fact that you can confirm independently.
Concretely, the Software:
- contains no analytics library, software-development kit, crash reporter, exception tracker, performance monitor, attribution pixel, advertising identifier, or equivalent component, whether first-party or third-party;
- makes no outbound network connections during installation, activation, runtime, update or uninstallation, except for connections that you explicitly initiate or that your own application generates through the x2y SDK;
- does not read, transmit, hash, fingerprint or otherwise process device identifiers, hardware serial numbers, MAC addresses, IP addresses, geolocation data, installed-application lists, browser profiles, clipboard contents, keystrokes, screenshots or any analogous signal for the purpose of analytics, diagnostics, marketing or behavioural profiling;
- does not require, request or store any account, registration, email address, telephone number, username or authentication credential in order to download, install, activate or use any product, whether free or paid; and
- processes all user-supplied content — files, archives, source code, secrets, credentials, traffic records, documents and repository metadata — entirely within the memory and storage of your own device, without transmission to x2y or any third party acting on x2y's behalf.
You can independently verify the foregoing using any standard network-inspection tool — Wireshark, mitmproxy, Fiddler, GlassWire, Little Snitch, the Windows Resource Monitor, lsof -i on macOS, or ss/netstat on Linux — while the Software is installed and running. You should observe zero outbound connections attributable to the Software itself, other than those your own workload generates. We encourage security-conscious users to perform this verification and to publish their findings.
What we collect
Because the Software collects no telemetry, the categories of personal data that x2y actually holds are narrow and arise only from direct, voluntary interactions with us or from transactions processed by our distribution partners on our behalf. They are enumerated exhaustively below; if a category is not listed here, we do not collect it.
| Category | Source | Held by x2y? |
|---|---|---|
| Support & legal correspondence | Emails you send to support@, legal@, privacy@ or security@x2ydevs.xyz, and any attachments | Yes |
| Payment & transaction records | Processed by itch.io, Microsoft Commerce and their processors; x2y receives only the minimum settlement and licensing metadata needed to fulfil the licence | Minimal |
| Vulnerability disclosures | Reports sent to security@x2ydevs.xyz, including reporter contact details supplied voluntarily | Yes |
| GitHub interactions | Issues, pull requests, discussions and releases you author on x2y GitHub repositories — governed by GitHub's privacy policy | Via GitHub |
| Documentation portal logs | Standard web-server access logs for x2ydevs.xyz and sdk.x2ydevs.xyz (IP address, timestamp, path, user-agent), retained briefly for security and abuse prevention | Briefly |
| Telemetry from the Software | None — the Software transmits nothing | 0 bytes |
| Accounts or profiles | None — no account is required or offered | None |
| User Data (files, secrets, code, archives, traffic) | Processed locally on your device; never transmitted to x2y | Never |
| Device identifiers, fingerprints, geolocation | Not collected by the Software or the Services | Never |
| Cookies or tracking pixels | Not set by x2y; see Section 15 | None |
What we do not collect
For the avoidance of doubt, and because negative statements about data collection are unusually important for a privacy policy, x2y does not and will not, through the Software or the Services:
- (a)collect, infer or purchase any information about your browsing activity, application usage, contacts, calendar, messages, photos, media library, biometric templates, health data, financial accounts or precise location;
- (b)build, maintain or contribute to any advertising, marketing, behavioural, psychographic or lookalike profile of you, whether for x2y's own use or for the benefit of any third party;
- (c)train, fine-tune, evaluate or otherwise use your User Data, prompts, code, files or traffic records to develop, improve or benchmark any machine-learning model, large language model, generative system or analogous technology, whether operated by x2y or a third party;
- (d)sell, rent, lease, license, barter or otherwise monetise your personal data, in whole or in part, in any form and to any party, including data brokers, advertising networks, analytics vendors or research aggregators; or
- (e)combine data obtained from the Software or Services with data obtained from other sources for the purpose of identifying, tracking or profiling you across contexts.
The commitments in this Section 5 are contractual as well as descriptive: they are incorporated into the Terms of Use and a material breach of them would constitute a breach of contract actionable under the dispute-resolution provisions of those Terms.
Distribution partners
The Software is made available through third-party distribution channels that operate independently of x2y and maintain their own privacy policies, over which x2y exercises no control and for which x2y assumes no responsibility. When you obtain the Software through one of these channels, that channel — not x2y — is the data controller for any personal data it collects in the course of the transaction. The principal channels are:
| Channel | Typical data handled by the channel | Channel's policy |
|---|---|---|
| Microsoft Store | Microsoft account identifier, billing details, device and store telemetry as described by Microsoft | privacy.microsoft.com |
| itch.io | Account email, billing details, download and purchase records as described by itch.io | itch.io/docs/legal/privacy |
| Uptodown | Download logs, device and referral data as described by Uptodown | uptodown.com/privacy |
| APKPure | Download logs, device and referral data as described by APKPure | apkpure.com/privacy-policy |
| npm | Package-download logs, account data for publishers, as described by GitHub/npm | docs.npmjs.com/policies/privacy |
| GitHub | Account data, repository activity, release-download logs as described by GitHub | docs.github.com/site-policy/privacy-policies |
We encourage you to review the privacy policy of whichever channel you use before completing a download or purchase. x2y receives from these channels only the minimum information necessary to fulfil and evidence the licence — typically a transaction identifier, product SKU, Seat count, timestamp and, for paid transactions, a settlement reference. We do not receive your password, full payment-card number, billing address beyond what is required for tax compliance, or any channel-side behavioural telemetry.
Voluntary correspondence
When you email x2y at any of the addresses listed in Section 18 — for support, legal, privacy, security-disclosure or general enquiries — we process the content of your message, any attachments, the sender and recipient addresses, timestamps, mail-server headers and any signature-block information you include. We use this data solely to respond to your enquiry, to maintain a record of the interaction for quality and compliance purposes, and, where your message reports a security vulnerability, to coordinate remediation and (with your consent) public disclosure.
We do not mine, analyse, summarise with automated systems, or repurpose the content of correspondence for marketing, product development, model training or any other secondary purpose. Access to the mailbox is restricted to a small number of authorised personnel bound by confidentiality obligations, and messages are retained only for as long as necessary to resolve the matter and satisfy any applicable legal, regulatory, tax, accounting or limitation-period requirement, after which they are securely deleted.
Legal bases for processing (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies to our processing of your personal data, we rely on the following lawful bases under Article 6(1), as applicable to each category of processing:
| Processing activity | Lawful basis | Notes |
|---|---|---|
| Fulfilling a paid licence and processing the associated transaction | Contract Art. 6(1)(b) | Necessary to perform the licence agreement with you |
| Responding to support, legal, privacy and security enquiries | Legitimate interest Art. 6(1)(f) | Interest in providing effective support and maintaining a record; balanced against your rights, given the narrow scope and short retention |
| Complying with tax, accounting, consumer-protection and data-protection law | Legal obligation Art. 6(1)(c) | Kenyan Tax Procedures Act, Companies Act, Data Protection Act; EU/UK VAT where applicable |
| Defending or pursuing legal claims | Legitimate interest / Legal claims Art. 6(1)(f), Art. 9(2)(f) | Establishment, exercise or defence of legal claims |
| Operating and securing the documentation portals | Legitimate interest Art. 6(1)(f) | Interest in availability, integrity and abuse prevention; brief log retention |
| Processing special-category data, if any is incidentally included in correspondence | Explicit consent / Legal claims Art. 9(2)(a)/(f) | We do not solicit special-category data; if you include it, we process it only to respond and then delete it |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is proportionate, has a minimal impact on your rights, and is something you would reasonably expect in the context of obtaining and using the Software. You may request a copy of the relevant legitimate-interest assessment by writing to the privacy contact in Section 18.
Data retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, and thereafter for as long as is required to satisfy applicable legal, regulatory, tax, accounting, audit and limitation-period obligations. The following table summarises our standard retention periods; shorter periods apply where the purpose is fulfilled earlier, and longer periods apply where a legal obligation or an active legal claim requires it.
| Category | Standard retention |
|---|---|
| Support and general correspondence | Up to 24 months after the last substantive exchange, then securely deleted |
| Legal, regulatory and tax records (incl. paid-licence transactions) | 7 years, in line with Kenyan tax and companies legislation, or longer where required |
| Security-disclosure reports | Until coordinated disclosure is complete plus 12 months, then archived or deleted |
| Documentation-portal access logs | Up to 30 days, then automatically purged |
| Data subject access, erasure and objection requests | Audit record retained for up to 36 months to evidence compliance |
| Telemetry from the Software | Not applicable — none is collected |
At the end of the applicable retention period, personal data is securely and irreversibly deleted, or, where deletion is not immediately feasible for technical reasons (for example, data residing in immutable backup media), it is cryptographically isolated and excluded from restoration until the media is overwritten in the ordinary course.
Sharing & disclosure
x2y does not sell, rent, trade, barter or otherwise monetise personal data, and we do not share it with third parties for their own independent marketing or analytics purposes. We disclose personal data only in the following limited circumstances:
- (a)Service providers acting as processors. A small number of carefully selected providers — email delivery, payment settlement, cloud infrastructure for the documentation portals, and backup — process data on our behalf under written data-processing agreements that impose confidentiality, security and purpose-limitation obligations consistent with Article 28 GDPR and Section 41 of the Kenyan Data Protection Act. These providers are prohibited from using the data for any purpose other than delivering the contracted service.
- (b)Distribution partners. As described in Section 6, the distribution channels are independent controllers for the data they collect themselves; x2y shares with them only the minimum licensing metadata needed to fulfil a transaction.
- (c)Legal compulsion. Where required by a valid court order, subpoena, search warrant, regulatory demand or other binding legal process of competent jurisdiction, or where necessary to comply with applicable law, prevent imminent harm, or protect the rights, property or safety of x2y, our users or the public. Where legally permitted, we will notify you before complying and will seek to narrow the scope of any disclosure.
- (d)Business transfers. In connection with a merger, acquisition, reorganisation, sale of substantially all assets, or similar transaction, personal data may be transferred to a successor entity, subject to the successor being bound by this Policy or an equivalent one, and to any notice or consent right conferred on you by applicable law.
- (e)With your explicit consent. In any other circumstance, only where you have given specific, informed and freely given consent, which you may withdraw at any time without affecting the lawfulness of prior processing.
Security measures
We implement appropriate technical and organisational measures to protect the personal data we hold against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR and Section 41 of the Kenyan Data Protection Act. Given the deliberately small volume of data we hold, our measures are proportionate and include:
- encryption of data at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher) for the documentation portals and mail systems;
- strict access controls on a least-privilege basis, with multi-factor authentication for every administrative account and a small, named set of authorised personnel;
- audit logging of access to systems that store personal data, reviewed periodically for anomalous activity;
- regular, encrypted, geographically separated backups with tested restoration procedures;
- a documented incident-response procedure, including notification to the relevant supervisory authority within 72 hours of becoming aware of a notifiable personal-data breach, and to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and
- a public security-disclosure channel at
security@x2ydevs.xyzfor the responsible reporting of vulnerabilities in the Software or Services.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. What we can guarantee — and do — is that the attack surface presented by the Software itself is effectively zero, because the Software holds no data of ours to exfiltrate and establishes no connection to us to intercept.
International transfers
x2y is established in Nairobi, Kenya. If you are located in the European Economic Area, the United Kingdom, Switzerland or another jurisdiction with restrictive rules on international transfers, please note the following. The personal data we hold about you is minimal (see Section 4) and is processed primarily within Kenya. Where we use service providers located outside your jurisdiction — for example, email-delivery or cloud-infrastructure providers in the European Union or the United States — we rely on one or more of the following transfer mechanisms, as applicable:
- an adequacy decision issued by the European Commission, the UK Secretary of State, or the relevant Kenyan authority under Section 49 of the Data Protection Act;
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), including the Annex II technical and organisational measures and a transfer-impact assessment addressing the laws of the destination country;
- the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, where the UK GDPR applies; or
- your explicit consent, or another derogation under Article 49 GDPR / Section 49 of the Kenyan Act, where appropriate.
You may request a copy of the applicable transfer safeguards, redacted where necessary to protect confidential commercial information, by writing to the privacy contact in Section 18.
Your rights
Depending on your location, you may have some or all of the following rights with respect to the personal data x2y holds about you. Because the data we hold is narrow, most of these rights can be exercised quickly and, in practice, often amount to confirming that we hold little or nothing beyond a past email exchange.
Right of access
Obtain confirmation of whether we process your data, and a copy of the data and the surrounding processing details.
Right to rectification
Have inaccurate or incomplete personal data corrected or completed without undue delay.
Right to erasure
Request deletion of your data where the legal basis no longer applies, subject to overriding legal-retention obligations.
Right to restriction
Restrict processing in certain circumstances, for example while accuracy or a lawful basis is contested.
Right to portability
Receive your data in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.
Right to object
Object to processing based on legitimate interests, and to any direct marketing (we conduct none).
Right to withdraw consent
Withdraw any consent you have given, at any time, without affecting the lawfulness of prior processing.
No automated decision-making
We do not carry out profiling or solely automated decision-making producing legal or similarly significant effects.
To exercise any of these rights, please contact the privacy address in Section 18. We will acknowledge your request within five (5) business days and respond substantively within thirty (30) calendar days, extendable by a further sixty (60) days for complex or numerous requests, in which case we will inform you of the extension and the reasons within the initial thirty-day period. We may ask for reasonable proof of identity before acting on a request, proportionate to the sensitivity of the data and the risk of unauthorised disclosure. We do not charge a fee for exercising your rights, except where a request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or refuse to act, with an explanation.
Children's privacy
The Software and Services are not directed to children, and we do not knowingly collect personal data from anyone below the age of digital consent in their jurisdiction (sixteen (16) under the GDPR, unless a member state has lowered it to thirteen (13); eighteen (18) under the Kenyan Data Protection Act for the purposes of contractual capacity). Because the Software collects no telemetry and requires no account, there is no mechanism by which a child could inadvertently create a data relationship with x2y through normal use of the Software.
If you are a parent or guardian and believe that a child under the applicable age has provided us with personal data — for example, through a support email — please contact the privacy address in Section 18 and we will promptly review and, where appropriate, delete the data.
Cookies & local storage
The x2y documentation portals (x2ydevs.xyz and sdk.x2ydevs.xyz) are static, server-rendered sites that do not set any first-party cookies, do not embed third-party analytics, advertising, social-media or tracking scripts, and do not use browser local storage, session storage, IndexedDB or any equivalent client-side persistence for tracking purposes. A single strictly-necessary local-storage key may be used to remember your light/dark theme preference; this key contains no identifier, is never transmitted anywhere, and can be cleared at any time through your browser settings.
The Software itself does not use browser cookies or analogous web-tracking mechanisms, because it does not operate a web session with x2y. Any cookies you encounter while using a distribution channel (Microsoft Store, itch.io, Uptodown, APKPure, npm, GitHub) are set by that channel under its own privacy policy.
Do Not Track & global privacy signals
Because the Software transmits no telemetry and the documentation portals perform no tracking, there is nothing for a Do Not Track (DNT) header or a Global Privacy Control (GPC) / opt-out-preference signal to opt out of. We nonetheless honour the intent of such signals as a matter of policy: we do not track, and we will not begin to track, regardless of the signal state. Where a future version of the Services were to introduce any optional, non-essential processing that could be construed as tracking, we would default it to off and respect DNT/GPC as a binding opt-out without requiring further action from you.
Changes to this policy
We may revise this Policy from time to time to reflect changes in our practices, the Software, the Services, applicable law, regulatory guidance or industry standards. When we make changes that materially affect your rights or the categories of data we process, we will update the "Effective date" and "Document version" at the top of this page, publish a prominent notice on the documentation portals and in the product changelog, and, where required by law, provide advance notice of no less than thirty (30) days before the changes take effect.
Your continued use of the Software or Services after the effective date of a revision constitutes acceptance of the revised Policy. Prior versions are archived and available in machine-readable form upon written request to the privacy contact in Section 18. We encourage you to review this Policy periodically, and we will always indicate the date of the most recent material change at the top of the page.
Contact & supervisory authority
Questions, requests and complaints concerning this Policy or our data practices should be directed to the appropriate channel below. We aim to acknowledge privacy enquiries within five (5) business days and to provide a substantive response within thirty (30) calendar days, subject to the complexity of the matter and any applicable statutory deadlines.
Supervisory authorities
If you are located in Kenya and believe that we have not addressed your concern satisfactorily, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya at odpc.go.ke. If you are located in the European Economic Area, you have the right to lodge a complaint with the data-protection authority of your member state of habitual residence, place of work, or the place of the alleged infringement; a directory is maintained by the European Data Protection Board at edpb.europa.eu. If you are located in the United Kingdom, you may complain to the Information Commissioner's Office at ico.org.uk. We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority.
Revision history
The table below records material revisions to this Policy. Earlier versions are available in machine-readable form upon written request to privacy@x2ydevs.xyz.
| Date | Version | Summary of changes |
|---|---|---|
| 1 Aug 2026 | 1.2 | Added Section 19 (revision history); expanded Section 8 with explicit Article 6(1) mapping; clarified international-transfer mechanisms in Section 12; added GPC/Do Not Track statement in Section 16. |
| 1 Jul 2026 | 1.1 | Reflected transition of the suite to donationware and the introduction of the Code Leak Detector paid tier; confirmed that payment metadata is the only new data category, processed via third-party distributors. |
| 14 Oct 2025 | 1.0 | Initial publication of the Privacy Policy, coinciding with the founding of x2y Devs Tools Ltd and the first public release of x2y AV Ultimate. |
The bottom line
We built software that has nothing to report
The simplest privacy policy is the one with the least to disclose. Our software collects zero telemetry, requires no account, and processes everything on your machine. What remains is a handful of voluntary emails and the minimum transaction metadata our distributors pass us — and that is all this policy has to cover.
| Effective | 1 August 2026 |
|---|---|
| Version | 1.2 |
| Controller | x2y Devs Tools Ltd · Nairobi |
| Telemetry | 0 bytes — by design and by contract |