Privacy

Last updated 30 July 2026.
Draft — pending legal review.

Who operates xito

xito is built and operated by independent developers in India. This notice explains what personal data the product holds, who else processes it, and how to ask about it.

Who is responsible for your data

Under India's Digital Personal Data Protection Act, 2023:

Because your firm decides what is collected, questions and requests about your own data go to your firm first. We help your firm answer them.

What is held

Pay rates and client records are the most sensitive of these. Who can see them is set by your firm.

Who else processes it

We use these services to run xito. Each receives only what its job needs.

ServiceWhat it is used for
MongoDB AtlasThe database. All product records.
Amazon S3File attachments and nightly database backups.
Amazon SESSending email.
ContaboThe servers the application runs on.
OpenAI, AnthropicAnswering questions about documents you upload.
Microsoft GraphThe optional calendar connection, if your firm enables it.
Zoho BooksInvoicing.
PostHogProduct analytics — how the application is used.
TallyThe in-app feedback form.
DiscordInternal alerts to us when something breaks.
Browser push servicesDelivering push notifications you have opted into.

The meeting-recording and transcript features are being retired. While they remain, they use Vexa and Skribby.

Where it is stored

Email and file storage are in Amazon's Mumbai region (ap-south-1). The database and application servers are in {{DATABASE_AND_SERVER_REGION}}. The services listed above may process data outside India.

How long it is kept

We keep your firm's data for as long as your firm uses xito. If your firm asks us to delete its data, we will do so within 30 days of the request, including from backups at the next backup cycle. We do not automatically delete inactive records; your firm decides what its records should be.

Cookies and local storage

xito's own code sets no cookies. It uses browser local storage for three things: your session token, a running timer, and saved filters. The analytics service listed above sets cookies of its own.

Security

Access is by password and an expiring session token. What each person can see is limited by the role your firm assigns them, and each firm's data is isolated from every other firm's. Traffic is served over HTTPS, and the database and file storage are encrypted at rest by their providers.

Your rights

The DPDP Act gives you the right to know what personal data is held about you, to have it corrected or completed, to have it erased, and to raise a grievance. Because your firm is the Data Fiduciary, exercise these with your firm.

If your firm cannot help, or you want to raise something with us directly, write to our Grievance Officer at privacy@xito.in. We will respond within 30 days.

Changes

If this notice changes, the date at the top changes with it.

Contact

Privacy and grievances — privacy@xito.in
Anything else — support@xito.in