What we collect, why, and what we do — and don't — do with it. For the technical detail on encryption and exactly what we can read, the companion Security & Trust page is the honest deep-dive.
Last updated: June 2026
The short version: we collect what's needed to run the app and keep it safe. We do not sell information that identifies you personally. Our optional "Fair Data" program sells only aggregate, anonymized insights (protected with differential privacy, which bounds how much any single person's data can influence a released number — it limits what can be inferred about you rather than making re-identification impossible), and only for accounts that opt in — you can opt out anytime. End-to-end-encrypted messages we genuinely can't read. AI only accesses your data with consent (the owner and people who opt in).
| Category | Examples |
|---|---|
| Account info | Name, phone, email (if provided), hashed PIN/password, profile and avatar. |
| Activity & content | Listings, deals, gigs, reviews, messages, balances and transactions, and other things you create or do in the app. |
| Verification data | For age-restricted features, identity/age verification. ID images you submit are encrypted at rest while they wait, decrypted only for the single human who reviews them, and the stored image is deleted the moment your submission is approved or rejected — we do not keep a copy. The live count of retained ID images is published on the verification page and must be zero. In Illinois, Texas, and Washington, biometric/camera features are restricted. |
| Payment data | Card payments are handled by our payment provider's hosted checkout — we never see or store your card number. Manual top-ups record only the reference you submit. |
| Technical data | IP address, device/browser info, and basic logs used for security, fraud prevention, and keeping the service running. |
| Optional analytics | Privacy-respecting product analytics to improve the app. Personal identifiers are hashed where used. |
AI assistants only access personal data on a consent-gated basis — the account owner and users who explicitly opt in. We don't quietly feed your private content into AI training. AI usage is metered to your own activity and billed from your XCash balance.
We do not sell information that identifies you personally. The optional Fair Data program sells only aggregate, differential-privacy-protected insights for opted-in accounts — never your personal records, and you can opt out in settings (we also honor Global Privacy Control signals). Otherwise we share data only with: service providers who run parts of the app for us (e.g. payment processing, infrastructure) under contract; other users, but only the things you choose to make visible (public profile, listings, messages you send); and authorities when we're legally required to, or to prevent fraud or harm. For end-to-end-encrypted messages, we store scrambled text we can't read — so there's nothing in plaintext to hand over.
Encryption protects message contents in end-to-end mode, but not metadata — who you messaged, when, and amounts sent are visible to us. Anything you post publicly (profile, listings, reviews) is public. The Security & Trust page lays out, line by line, exactly what is and isn't private.
We keep data for as long as your account is active and as needed for the purposes above, then delete or anonymize it where we can. We use encryption in transit (HTTPS/TLS) and field-level encryption at rest for sensitive data, plus regular database backups to protect against loss. No system is perfectly secure — see Security & Trust for the honest limits.
XSCN is not for anyone under 18. We don't knowingly collect data from minors; if we learn we have, we delete it.
We may update this policy; material changes will be surfaced in the app. Questions or requests about your privacy? Reach us through the app's Support section.