XAIAK PUBLIC TRUST SURFACE

Privacy Policy

Relationship context should be useful without becoming invisible collection.

Last updated: 29 September 2026. This page describes the current public-launch policy direction for XAIAK. It must be reconciled against the exact qualified Android release, backend, SDK inventory and production provider configuration before public distribution.

What XAIAK may process

XAIAK may process account identity, Business identity, profile information, relationship state, Catalog/Product/Service data, conversation content, enquiry context, team membership, session state, notification preferences and product-security evidence required to operate admitted features.

Public and relationship-private context

Public Business and Catalog information is separated from relationship-authorized commercial information. Relationship-private pricing, terms or other private context should not be exposed through public projections.

Connected services

Google Identity and notification delivery may be integrated when configured. System Mail, Android sharing and WhatsApp handoff can use platform capabilities without making those providers the source of XAIAK truth. Optional Gmail, Drive, Calendar, Google Business Profile, IndiaMART, Meta, CRM or ERP adapters must be disclosed separately if and when they are actually admitted.

What XAIAK does not silently do

XAIAK does not need to silently ingest private WhatsApp conversations or broadly harvest an address book or Drive merely to create a Relationship Network. Provider scopes should be requested only for the capability the user chooses.

Retention and deletion

Account and server-held data retention must match the exact production backend and legal requirements. Users should have clear in-product controls for privacy requests and account/session management, plus an external deletion resource where required by the distribution platform.

Security

XAIAK uses authorization boundaries between Member and Business roles and should treat the server as authoritative for protected state. No software can promise protection against every compromised device, privileged malware or external provider failure.

Contact

Privacy questions: support@xaiak.com. Security reports: security@xaiak.com.

Before Play publication, replace conditional wording with the exact final data inventory, retention rules, production developer identity and SDK/provider disclosures of the qualified release.