Privacy Policy
Last updated: August 10, 2026. This is a plain-language summary of how xlogs handles your information. It is not legal advice.
The short version
- xlogs is free and needs no account, so we do not ask for your name, email, or payment details.
- We do not store your scans, your findings, your source code, or your data, unless you choose to create a share link (see below).
- We do keep anonymous counts: which builder platform an app appears to use, which checks ran, and whether they found something. No URL, no address, nothing identifying. See "What we count" below.
- We do not set tracking cookies or sell your information to anyone.
What you give us
The only thing you provide to run a scan is the URL of the app you want checked. You do not create an account and we do not ask for personal information.
What we do with it
When you submit a URL, xlogs fetches that public address read-only, the same way a normal visitor's browser would, runs its deterministic checks, and returns the results to your browser. The scan and its findings are generated on request and are not saved on our servers afterward.
Share links (only if you create one)
If you click "Share result", and only then, xlogs re-runs the scan and stores that single result so it can be viewed at an unguessable link you can send to a client or teammate. The link expires automatically after 30 days. You are given a private delete link at the same time that revokes it immediately. The stored result contains the same evidence a scan always shows (table and column names, an approximate row count) and never the contents of your data. If you never create a share link, nothing about your scan is stored.
Your code and data
xlogs reads only what your app already serves publicly. For the database check, it records table and column names and an approximate row count as evidence of an exposure, never the row contents, and it does not retain them after returning your report. xlogs never writes to, deletes, or changes your app or your data.
What we count
We keep a small anonymous tally so we can publish the defect index, which reports how often each AI builder platform ships each kind of security problem. Per scan we increment counters for exactly four things: the month, which builder platform the app appears to use, which check ran, and whether it found something. We also record a coarse bucket for how long the scan took.
Repository scans are counted the same way: the month, which package ecosystem the code belongs to (npm, Python, Go and so on), which check ran, and whether it found something. We do not store the repository name, its owner, or its URL in those counters, and we will never publish a list of repositories that failed.
We do not store the URL, the hostname, an IP address, a timestamp finer than the month, any finding detail, or any data from your app. There is no identifier of any kind in these counters, so there is nothing in them that could be traced back to you or your app, and nothing to delete on request because nothing about you was kept.
We publish counts only, and we will never publish a list of scanned or affected sites.
Server logs
Our hosting provider keeps standard request logs (such as IP address, timestamp, and the request made) for security, abuse prevention, and reliability, as is typical for any website. These are used operationally and are not combined into a profile of you.
Cookies and analytics
xlogs does not use tracking cookies or third-party advertising analytics. If we ever add basic, privacy-respecting usage measurement, we will update this page first and keep essential-only defaults.
Sharing
We do not sell, rent, or trade your information. We share data only where required by law or to operate core hosting.
Changes and contact
If this policy changes, we will update the date above. Questions about your privacy can be sent to hello@xlogs.com.
