Most of what CrossXCloud touches never reaches us at all - that's a property of how it's built, not a promise we're asking you to take on trust. Here's what does.
They’re encrypted on your machine and sealed under a passphrase only you know. There is no copy on our servers, and no mechanism by which one could arrive.
The same is true of your vault passphrase and of SSH session content. When our relay brokers a connection, it passes encrypted traffic through without being able to read it.
Section 3Your project definitions, canvas layouts, version history, and the records mapping cloud resources to canvas nodes are stored so they follow you between devices.
That’s a description of what you built. We never access data inside the servers you provision.
Section 4.2We collect eight product events - things like “a provider was connected” or “a plan was applied, with 4 steps, 1 failed”. The provider name is recorded; nothing about your infrastructure is.
Every event passes a filter that drops anything named like a host, URL, IP, path, key, token, or address, and drops any nested value outright - that’s where config blobs would otherwise hide.
You can turn it off completely in Settings, and nothing stops working when you do.
Sections 4.4, 9Accounts, projects, billing, certificates, and hosted telemetry all sit on Hetzner servers in Singapore.
Product analytics are the one thing stored elsewhere, processed by PostHog in the United States. Opting out avoids that entirely.
If you're in the EEA or UK, both are transfers outside your region, covered by Standard Contractual Clauses.
Sections 5, 6Payments go through PayOS. We receive an order reference, an amount, and whether it succeeded - never card or bank details.
Billing records are kept for 10 years because Vietnamese accounting law requires it. That one period can’t be shortened on request; everything else can be deleted.
Sections 4.3, 7That’s the complete list. We don’t sell personal data and don’t share it for advertising.
Section 6Email hello@crossxcloud.dev to access, correct, export, or delete your data, or to object to analytics. We reply within 30 days, free, and won’t treat you differently for asking.
Two honest limits: legally required billing records stay, and we cannot delete your cloud credentials for you - we don’t have them.
Section 8It is written for clarity, not for precision, and it is not the agreement itself. Where this summary and the full text differ, the full text governs.