Privacy policy

Privacy by design,
not by promise.

This page explains exactly what data xCalibre collects, what it doesn't, how long it keeps things, and what you can do about it. No legal fog. If something isn't clear, email us.

Last updated: May 2026 · Applies to xcalibreos.polsia.app and xcalibre.io

What we store

The minimum required to run the platform. Nothing more.

What we never store

These are hard constraints — not aspirational. Enforced by architecture, not just policy.

Retention windows

Data that isn't needed gets deleted, not archived.

Data type Retention Purge trigger
DM messages90 days from last activity in threadAutomatic — thread idle timer
Published postsUntil creator deletesHard purge within 30 days of deletion request
Supporter tier recordsDuration of active subscription + 90 daysPurged 90 days after subscription lapses
Stripe payment token12 months from transactionPurged on account deletion or 12-month expiry
Hashed emailActive account lifetimePurged on account deletion request
Rate-limit IP log15-minute rolling windowAutomatic — in-memory only, not written to disk
Support tickets24 months from resolutionBatch-purged quarterly after expiry
Anonymous page-view countsIndefinite (aggregate only)No user-level data attached; no purge trigger needed

Stripe's role vs. xCalibre's role

Two separate systems. Two separate jobs. They do not share identity data with each other.

Stripe Payment layer
  • Processes card payments and creator payouts
  • Handles KYC and AML verification for creators (legal requirement for payouts)
  • Stores card data under PCI DSS compliance
  • Issues an opaque token to xCalibre when payment succeeds
  • Governed by Stripe's privacy policy
xCalibre Content layer
  • Manages content, messaging, and tier access
  • Receives payment token from Stripe — never card or bank details
  • Never sees creator's real identity (Stripe holds that for KYC)
  • Never sees supporter's payment method or billing address
  • Governed by this privacy page

In plain terms: Stripe knows who paid but not what they read. xCalibre knows what access was granted but not who paid. Neither side can reconstruct the full picture.

Your rights

You have the right to know what we hold, correct it, export it, and delete it.

Access & export

Email privacy@xcalibre.io with the subject line "Data export request" and your handle. We'll send a JSON export of everything tied to your account within 14 days.

Correction

Most data you can update directly in settings (handle, email hash). For anything you can't self-serve, email us and we'll fix it within 7 days.

Deletion — what it actually means

"Delete my account" triggers two things: (1) immediate anonymisation — your handle is replaced with a random token so no content traces back to you; (2) hard purge within 30 days — all rows associated with your account ID are deleted from the database. After the purge window, nothing remains. Stripe's records of payment transactions are governed by their retention policy (typically 7 years for tax purposes) — we cannot delete those on your behalf, but they hold no xCalibre handle or username.

Objection & restriction

You can request we stop processing your data for specific purposes (e.g. aggregate analytics) without deleting your account. Email us and we'll apply a processing flag within 48 hours.

What changes when you fund anonymously

Supporting a creator on xCalibre is designed to leave as small a data footprint as possible.

Guest checkout — data flow

What Stripe collects: your card number, billing address, and email for the payment receipt. Stripe is required by law to collect this for fraud prevention. Stripe's privacy policy governs this data — xCalibre never receives it.

What xCalibre sees: a Stripe payment token (a random string like tok_1Nabcd…), a tier level (e.g. "Standard"), and a timestamp. That's it. No name, no email, no card data.

What the creator sees: a new supporter count increment and tier revenue. No handle if you chose to fund anonymously. No email. No location. Your existence is known; your identity isn't.

DMs from anonymous supporters: if you message a creator, you're assigned an ephemeral handle (e.g. @anon-7f2a) for that thread. It persists for 90 days then is purged along with the thread. The creator cannot link it to your payment.

Questions, requests, or concerns about this policy: privacy@xcalibre.io. We respond within 5 business days. If you believe we've made an error, say so directly — we'd rather fix it than defend it.