Legal · Privacy
Privacy Policy
Effective 1 August 2026 · Version 1.0. This policy covers the x2y SDK package, this documentation site and the playground.
01The short version
The SDK collects no telemetry whatsoever. It makes no outbound network connections of its own, requires no account, and processes all input — traffic records, source code, files — entirely within your Node.js process. The playground on this site runs fixed fixtures in your browser and transmits nothing.
02What we do not collect
- No analytics, crash reports, stack traces, usage metrics, device fingerprints or diagnostic payloads from the SDK;
- No source code, traffic records, secrets or files — these never leave your process;
- No account, registration or authentication data — none exists;
- No cookies or tracking pixels set by this site; a single strictly-necessary local-storage key remembers your theme preference and is never transmitted.
03What we may hold
Only what you voluntarily send: support or security emails (retained up to 24 months after the last exchange), and the minimum transaction metadata passed by npm or other distributors for paid or donated interactions. Distribution channels (npm, GitHub) handle their own data under their own policies.
04Legal bases & your rights
Where the GDPR, UK GDPR or the Kenyan Data Protection Act, 2019 apply, we rely on contract, legitimate interest or legal obligation as applicable. You may request access, rectification, erasure, restriction, portability or object by writing to privacy@x2ydevs.xyz. We acknowledge within 5 business days and respond within 30. You may also complain to the ODPC (Kenya) or your local supervisory authority.
05Changes
Material changes get at least 30 days' notice via this page and the changelog. Continued use after the effective date constitutes acceptance. The full suite-level policy is available at x2ydevs.xyz/privacy.