1. Who we are, and which law applies
CrossXCloud is operated by Honology (“we”, “us”), established in Vietnam. We are the controller of the personal data described in this policy.
Our processing is governed primarily by Vietnamese personal data protection law, including Decree 13/2023/ND-CP and the Personal Data Protection Law.
Where you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR also apply to our processing of your data, and we honour the rights they give you. Where the two regimes differ, we apply whichever gives you the stronger protection.
For anything in this policy, contact us at hello@crossxcloud.dev.
2. What this policy covers
This policy covers the CrossXCloud Client desktop application, the CrossXCloud web application, and our hosted services (relay, monitoring, and data services).
It does not cover the cloud providers you connect - Amazon Web Services, Google Cloud, Microsoft Azure, Hetzner, and others. When CrossXCloud acts on those accounts it does so with your credentials, under your relationship with that provider, governed by their privacy terms.
3. What never reaches us
Three categories of data are structurally incapable of reaching our servers, because the product is built so that they cannot:
- Your cloud provider credentials. Encrypted on your device and sealed under a passphrase only you know.
- Your vault passphrase. Never transmitted, never stored by us, and unrecoverable if lost.
- SSH session content and file transfers. These flow between your machine and your server. Where a connection is brokered by our relay, the relay passes encrypted traffic through without the ability to read it.
4. What we collect
4.1 Account and organisation data
When you create an account we process your email address and display name. Organisations you create carry a name, a URL slug, a billing email, and an avatar colour or uploaded avatar image.
Why: to provide the service and identify you. Basis: necessary to perform our contract with you, and your consent where Vietnamese law requires it.
4.2 Project and infrastructure data
When you use the web application or our data services, we store your project definitions, canvas layouts, version history, project tags, alerts, and correlation records that map resources in your cloud accounts to nodes on your canvas.
This is a description of infrastructure, not its contents. We do not read, copy, or access data stored inside the servers you provision.
Why: to provide the service across devices and sessions. Basis: necessary to perform our contract with you.
4.3 Billing data
For paid plans and credit top-ups we process: your credit balance and transaction history, your subscription plan and period, payment amounts in Vietnamese Dong, payment status, and order references issued by our payment provider.
We never see or store your card or bank details. Payments are handled entirely by PayOS (section 6); we receive only a reference and a status.
Why: to take payment and meet accounting obligations. Basis: necessary to perform our contract, and to comply with our accounting and tax obligations.
4.4 Product analytics
We collect a deliberately narrow set of product events to understand which features are used. The complete list of events we emit is:
provider_connected- with the provider name onlycompute_deployed- with the provider name onlyplan_opened, andplan_applied- with counts of attempted and failed stepsorganization_created,project_createdcommand_palette_opened, and page-view events
Events are associated with your user identifier once you sign in.
How we keep infrastructure details out of analytics. Every event passes through a filter, in both the desktop app and its backend, before transmission. That filter drops any property whose name matches email, name, host, url, ip, secret, token, password, key, transcript, code, path, description, address, or billing, and drops any value that is not a plain string, number, or boolean - so nested objects, which is where configuration blobs and credential maps would hide, are never transmitted at all. Session recording is configured to mask all input fields and text.
Why: to improve the product. Basis: your consent, which you may withdraw at any time. In some jurisdictions we may instead rely on our legitimate interest in understanding product usage, balanced against the narrow event set and the filtering described above. You can switch this off entirely - see section 9.
4.5 Infrastructure telemetry
If you use our hosted monitoring, agents you provision on your servers send us performance metrics - things like CPU, memory, disk, and network measurements - along with identifiers for the machine and project they belong to.
If you run your own collector instead, this data never reaches us. Monitoring is optional and off unless you enable it.
Why: to provide the monitoring service you asked for. Basis: necessary to perform our contract with you, for the monitoring you chose to enable.
4.6 Certificate and enrollment records
To authorise relay access we issue short-lived certificates. We store the enrollment request, the public key it was issued against, the organisation it belongs to, and its expiry. Private keys are generated on your device and never transmitted.
Why: to secure access to the relay. Basis: necessary to perform our contract, and to keep the service secure.
4.7 Technical and security logs
Our servers record standard operational data: IP address, timestamp, requested endpoint, response status, and user agent.
Why: to operate the service, diagnose faults, and detect abuse. Basis: necessary to operate the service and keep it secure.
5. Where your data lives
Our primary infrastructure runs on Hetzner servers in Singapore. Account data, project data, billing records, certificate records, and hosted telemetry are stored there.
Product analytics are processed separately by PostHog in the United States (section 6).
If you are in the European Economic Area or the United Kingdom, using CrossXCloud means your personal data is transferred outside that region, to Singapore and the United States. Neither is covered by a European Commission adequacy decision for general transfers, so we rely on the European Commission’s Standard Contractual Clauses, together with the technical measures described in section 3 and section 10, as the safeguard for those transfers. You can eliminate the United States transfer entirely by disabling analytics (section 9); the Singapore transfer is inherent to using the hosted service.
6. Who else processes your data
We use a small number of sub-processors. We do not sell personal data, and we do not share it for advertising.
- Hetzner Online GmbH (Germany; servers in Singapore) - hosting for all of our infrastructure.
- PostHog (United States) - product analytics. Receives only the filtered events in section 4.4. Avoidable by opting out.
- PayOS (Vietnam) - payment processing. Receives what is needed to take payment; we receive only order references and status.
We may also disclose data where legally required, or where necessary to protect our rights, our users, or the security of the service.
7. How long we keep it
Unless a longer period is required by law:
- Account and organisation data - until you delete your account, then removed within 30 days (and from backups within 90 days).
- Project and infrastructure data - until you delete it, then removed within 30 days.
- Billing and payment records - 10 years, as required by Vietnamese accounting law. This period cannot be shortened at request.
- Credit transaction history - retained with billing records for the same reason.
- Product analytics - 14 months from collection.
- Hosted telemetry metrics - per the retention included in your plan; 30 days where no longer period applies.
- Certificate and enrollment records - 12 months after expiry, for security audit purposes.
- Technical and security logs - 90 days.
8. Your rights
Subject to applicable law, you may: access the personal data we hold about you; correct inaccurate data; delete your data; export it in a portable format; object to or restrict processing based on legitimate interests; and withdraw consent where processing relies on it.
Exercise any of these by emailing hello@crossxcloud.dev. We respond within 30 days. We will not charge you for a request, nor treat you differently for making one.
Note that deletion requests cannot extend to billing records we are legally required to retain (section 7), and that we cannot recover or delete your cloud credentials, because we never hold them.
If you believe we have mishandled your data, you may complain to the competent Vietnamese authority. If you are in the European Economic Area or the United Kingdom, you may instead complain to your local supervisory authority.
9. Turning analytics off
Analytics are on by default and can be switched off completely, at any time, in the desktop application under Settings. The setting disables collection in both the app and its backend - not just transmission - and persists across restarts.
Nothing about the product stops working when analytics are off. It is not a condition of use.
10. How we protect your data
Cloud credentials are encrypted on your device using envelope encryption, with the sealing key derived from your passphrase; we hold no copy. Traffic between the application and our services is encrypted in transit. Relay access is authorised by short-lived certificates chaining to an offline root, rather than long-lived shared secrets. Access to production systems is restricted to personnel who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
11. Children
CrossXCloud is not directed at children and is not intended for anyone under 16. We do not knowingly collect their data; if we learn that we have, we will delete it.
12. Changes to this policy
We may update this policy. Material changes will be notified in the application or by email, with an effective date. The version and effective date at the top of this page always identify the current policy.
13. Contact
Honology - hello@crossxcloud.dev
Privacy requests and security reports may both be sent to that address.