Privacy
Who operates xito
xito is built and operated by independent developers in India. This notice explains what personal data the product holds, who else processes it, and how to ask about it.
Who is responsible for your data
Under India's Digital Personal Data Protection Act, 2023:
- Your firm is the Data Fiduciary. It decided to use xito, it created your account, and it decides what goes in.
- xito is the Data Processor. We hold and process the data on your firm's instructions, and for no other purpose.
- You are the Data Principal — the person the data is about.
Because your firm decides what is collected, questions and requests about your own data go to your firm first. We help your firm answer them.
What is held
- Who you are — name, work email, employee number, designation, date of birth.
- Your employment — team, branch, and your pay rate. Your firm enters these; you cannot change your own.
- Your work — the hours you log, what you logged them against, and the tasks assigned to you.
- Clients and billing — client contact records, and invoices raised from logged hours.
- What you write and upload — chat messages and attachments, documents added to the knowledge base, and the questions you ask of them.
- Technical records — your session token, push-notification subscriptions, and server request logs.
Pay rates and client records are the most sensitive of these. Who can see them is set by your firm.
Who else processes it
We use these services to run xito. Each receives only what its job needs.
| Service | What it is used for |
|---|---|
| MongoDB Atlas | The database. All product records. |
| Amazon S3 | File attachments and nightly database backups. |
| Amazon SES | Sending email. |
| Contabo | The servers the application runs on. |
| OpenAI, Anthropic | Answering questions about documents you upload. |
| Microsoft Graph | The optional calendar connection, if your firm enables it. |
| Zoho Books | Invoicing. |
| PostHog | Product analytics — how the application is used. |
| Tally | The in-app feedback form. |
| Discord | Internal alerts to us when something breaks. |
| Browser push services | Delivering push notifications you have opted into. |
The meeting-recording and transcript features are being retired. While they remain, they use Vexa and Skribby.
Where it is stored
Email and file storage are in Amazon's Mumbai region (ap-south-1). The database and application servers are in {{DATABASE_AND_SERVER_REGION}}. The services listed above may process data outside India.
How long it is kept
We keep your firm's data for as long as your firm uses xito. If your firm asks us to delete its data, we will do so within 30 days of the request, including from backups at the next backup cycle. We do not automatically delete inactive records; your firm decides what its records should be.
Cookies and local storage
xito's own code sets no cookies. It uses browser local storage for three things: your session token, a running timer, and saved filters. The analytics service listed above sets cookies of its own.
Security
Access is by password and an expiring session token. What each person can see is limited by the role your firm assigns them, and each firm's data is isolated from every other firm's. Traffic is served over HTTPS, and the database and file storage are encrypted at rest by their providers.
Your rights
The DPDP Act gives you the right to know what personal data is held about you, to have it corrected or completed, to have it erased, and to raise a grievance. Because your firm is the Data Fiduciary, exercise these with your firm.
If your firm cannot help, or you want to raise something with us directly, write to our Grievance Officer at privacy@xito.in. We will respond within 30 days.
Changes
If this notice changes, the date at the top changes with it.
Contact
Privacy and grievances — privacy@xito.in
Anything else — support@xito.in