Legal
Privacy Policy
Effective Date: 28 June 2026
Xacy Inc.
British Virgin Islands
This Privacy Policy explains how Xacy Inc. (“Xacy,” “we,” “our,” or “us”) collects, uses, stores, protects, and discloses information when customers access our website, APIs, managed VPN infrastructure, documentation, dashboard, support channels, and related services. Xacy provides managed B2B VPN infrastructure for companies that offer VPN, privacy, security, or related internet services to their own users. Xacy is not a consumer VPN application. By using Xacy, accessing our website, creating an account, integrating with our APIs, or otherwise using our services, you agree to the practices described in this Privacy Policy.
1. Scope of This Policy
This Privacy Policy applies to information we process in connection with:
The Xacy website.
Customer accounts and business relationships.
API access and authentication.
Billing and payment administration.
Customer support and communications.
Service monitoring, security, abuse prevention, and infrastructure operations.
Managed VPN infrastructure provided to business customers.
This Privacy Policy does not replace the privacy policy of our customers. If you are an end user of a VPN app, privacy app, security app, or other service powered by Xacy infrastructure, your relationship is primarily with that company. You should review that company’s privacy policy to understand how it collects and uses your data.
2. Our No-Log VPN Activity Policy
Xacy follows a strict no-log policy for VPN activity.
We do not save, track, monitor, sell, or share VPN activity. This means we do not log:
Websites visited through VPN sessions.
Content viewed or accessed through VPN sessions.
DNS queries made during VPN sessions.
Applications or services used through VPN sessions.
Browsing history.
Traffic content.
VPN activity profiles of end users.
Records linking end-user browsing activity to a specific person.
Xacy is designed as privacy-first infrastructure for business customers. Our goal is to help VPN companies provide secure, high-speed VPN services without requiring Xacy to store VPN activity logs.
However, to operate a reliable B2B infrastructure platform, we may process limited business, account, API, billing, usage-volume, security, and operational information as described below.
3. Information We Collect
We collect only the information needed to provide, secure, bill, support, and improve our services.
3.1 Business Account Information
When a company signs up for Xacy or communicates with us, we may collect:
Company name.
Business contact name.
Business email address.
Business phone number, if provided.
Company website.
Billing address.
Tax or company registration information, if required.
Account login details.
Customer plan, pricing, and service preferences.
Communications with our sales, support, legal, or billing teams.
3.2 API and Authentication Information
To provide secure API access, we may process:
API keys.
Authentication tokens.
Account identifiers.
API request metadata.
Endpoint accessed, such as add-peer or del-peer.
Time of API request.
Response status or error status.
IP address of the customer server or system making the API request.
Rate-limit, abuse-prevention, and security event data.
API metadata is used to operate and secure the service. It is not used to create VPN activity profiles of end users.
3.3 WireGuard Peer Information
To provide VPN infrastructure, customers may submit technical peer information through Xacy’s API, including:
Client WireGuard public key.
Requested country.
Requested server.
Requested nearby location.
Requested exit IP, if applicable.
Peer creation or deletion request.
Technical configuration data required to generate a WireGuard configuration.
Xacy does not require the customer to submit an end user’s real name, email address, phone number, or identity to create a WireGuard peer. Customers should avoid submitting unnecessary personal information through the API.
3.4 Usage and Billing Information
Xacy may process limited usage data required for billing and infrastructure management, including:
Egress traffic volume.
Ingress traffic volume, where needed for infrastructure measurement.
Account-level usage totals.
Server or region-level usage totals.
Billing period.
Invoice amount.
Payment status.
Payment method details processed by our payment provider.
Credits, discounts, refunds, or adjustments.
Xacy charges based on egress traffic, while ingress traffic may be free depending on the applicable plan or customer agreement. Usage-volume data is used for billing, capacity planning, security, and service operation. It is not used to track VPN browsing activity.
3.5 Website and Analytics Information
When you visit our website, we may collect limited technical information, such as:
IP address.
Browser type.
Device type.
Operating system.
Pages viewed.
Referring website.
Approximate location based on IP address.
Date and time of visit.
Cookie or similar tracking information, where used.
We may use privacy-conscious analytics tools to understand website performance, improve landing pages, measure marketing effectiveness, and protect the website from abuse.
3.6 Support and Communications
If you contact us, we may collect:
Name.
Email address.
Company name.
Support messages.
Technical details provided in the support request.
Attachments or screenshots you choose to provide.
Communication history.
Please do not send sensitive personal data, private keys, passwords, or confidential end-user information through support channels unless specifically requested through a secure process.
4. Information We Do Not Collect
Xacy does not intentionally collect or store:
Customers are responsible for ensuring that they do not send unnecessary personal data to Xacy through API requests, support tickets, or other communication channels.
5. How We Use Information
We use information for the following purposes:
To create and manage customer accounts.
To provide access to Xacy’s managed VPN infrastructure.
To authenticate API requests.
To create, manage, and delete WireGuard peers.
To generate WireGuard configurations.
To route traffic through selected countries, servers, or exit IPs.
To calculate usage and billing.
To issue invoices and process payments.
To provide customer support.
To troubleshoot technical issues.
To protect against fraud, abuse, attacks, and unauthorized access.
To monitor infrastructure health, uptime, and performance.
To improve our website, APIs, documentation, and services.
To communicate service updates, security notices, billing notices, and policy changes.
To comply with legal obligations.
To enforce our Terms of Service and Acceptable Use requirements.
To protect Xacy, our customers, our infrastructure, our providers, and the public.
We do not use VPN activity logs for advertising, profiling, resale, or behavioral tracking because we do not keep VPN activity logs.
6. Legal Bases for Processing
Depending on your location and applicable law, we may process personal information under one or more of the following legal bases:
Contract performance: To provide the services requested by our customers.
Legitimate interests: To secure our infrastructure, prevent abuse, improve services, communicate with customers, and operate our business.
Consent: Where consent is required, such as for certain cookies or marketing communications.
Legal obligation: To comply with applicable laws, court orders, tax rules, sanctions requirements, regulatory obligations, or valid legal requests.
Protection of rights: To protect the rights, safety, property, and security of Xacy, customers, users, providers, and the public.
7. How We Share Information
Xacy does not sell VPN activity data. Xacy does not share VPN activity logs because we do not keep VPN activity logs.
We may share limited business, account, operational, billing, or technical information in the following circumstances:
7.1 Service Providers
We may use trusted service providers for:
Cloud hosting.
Data centers.
Network infrastructure.
Payment processing.
Customer support.
Email delivery.
Security monitoring.
Analytics.
Accounting.
Legal and compliance support.
These providers may process information only as necessary to provide services to Xacy and are expected to protect the information they process.
7.2 Legal and Compliance
We may disclose information if required by law or if we believe disclosure is necessary to:
Comply with a valid legal request.
Respond to a court order, subpoena, regulator, or law enforcement request.
Enforce our Terms of Service.
Investigate fraud, abuse, or security incidents.
Protect the rights, safety, or property of Xacy, customers, providers, or others.
Comply with sanctions, export control, tax, or regulatory obligations.
Because Xacy follows a strict no-log policy for VPN activity, we may not possess VPN activity logs to provide in response to such requests.
7.3 Business Transfers
If Xacy is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and privacy protections.
7.4 With Customer Direction
We may share information when a customer instructs us to do so, or when sharing is necessary to provide services requested by that customer.
8. Customer Responsibilities
Xacy’s customers are responsible for their own products, users, privacy disclosures, and legal obligations.
Customers must:
Maintain their own privacy policy.
Explain to their users how their product collects, uses, and shares data.
Avoid sending unnecessary personal data to Xacy.
Protect API keys and credentials.
Use secure backend integration methods.
Ensure their use of Xacy complies with applicable law.
Respond to end-user privacy requests related to their own product.
Maintain appropriate end-user terms and acceptable use policies.
Ensure that their users do not misuse Xacy-powered infrastructure.
Xacy is not responsible for the privacy practices of customer applications, websites, support systems, analytics tools, payment processors, or end-user data collection practices outside Xacy’s control.
9. Cookies and Similar Technologies
Xacy may use cookies, pixels, local storage, or similar technologies on its website.
These technologies may be used to:
Keep the website functional.
Remember preferences.
Improve website performance.
Understand website usage.
Protect against abuse or fraud.
Measure marketing effectiveness.
You can control cookies through your browser settings. Blocking some cookies may affect website functionality. Where required by law, we will request consent before using non-essential cookies.
10. Data Retention
Xacy retains information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention periods may vary depending on the type of information:
Account information may be retained while the customer account remains active.
Billing records may be retained as required for accounting, tax, audit, and legal purposes.
Support communications may be retained for customer service, security, training, and legal purposes.
API security metadata may be retained for a limited period to detect abuse, investigate incidents, and protect infrastructure.
WireGuard peer information may be retained only as needed to provide the service and manage peer creation or deletion.
Legal and compliance records may be retained as required by applicable law.
When information is no longer needed, we may delete, anonymize, aggregate, or securely archive it.
11. Security
Xacy uses reasonable technical, administrative, and organizational measures to protect information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Security measures may include:
API authentication.
Access controls.
Credential protection.
Infrastructure monitoring.
Network security controls.
Encryption where appropriate.
Logging of security-relevant events.
Internal access restrictions.
Provider security reviews.
Incident response procedures.
No system is completely secure. Customers are responsible for securing their own applications, backend systems, API keys, user databases, and integration logic.
12. API Key Security
Customers must keep API keys secure.
Customers must not:
Publish API keys.
Commit API keys to public repositories.
Place secret API keys in client-side applications.
Share API keys with unauthorized parties.
Use weak internal access controls.
Ignore suspected credential compromise.
If an API key is compromised, customers must rotate it immediately and notify Xacy if there is risk of abuse or unauthorized use.
Xacy may revoke, rotate, limit, or suspend API keys if we believe there is a security risk, abuse, billing issue, or violation of our Terms of Service.
13. International Data Transfers
Xacy is incorporated in the British Virgin Islands and may use infrastructure, service providers, personnel, and systems located in different countries.
By using Xacy, you understand that information may be processed in countries other than your own. These countries may have different data protection laws.
Where required, Xacy uses appropriate safeguards for international transfers of personal information.
14. Your Privacy Rights
Depending on your location and applicable law, you may have rights related to your personal information, including the right to:
Request access to personal information.
Request correction of inaccurate information.
Request deletion of certain information.
Request restriction of processing.
Object to certain processing.
Request a copy of certain information.
Withdraw consent where processing is based on consent.
Lodge a complaint with a data protection authority where applicable.
To exercise privacy rights, contact us using the details in the “Contact Us” section.
If you are an end user of a customer’s VPN app or service, you should first contact that company because Xacy may not have enough information to identify or verify you.
15. Marketing Communications
We may send business customers and prospective customers service updates, product information, security notices, pricing information, or marketing communications.
You may opt out of marketing emails by using the unsubscribe link or contacting us. Even if you opt out of marketing emails, we may still send important service, billing, legal, or security communications.
16. Children’s Privacy
Xacy is a B2B infrastructure provider and does not knowingly provide services directly to children.
Our services are intended for business customers. Customers are responsible for ensuring that their own products comply with laws related to children and minors.
If we learn that we have collected personal information from a child where prohibited by law, we will take reasonable steps to delete it.
17. Abuse, Security, and Network Protection
To protect Xacy, our customers, providers, and the public, we may process limited technical and security information to detect, prevent, and respond to:
DDoS attacks.
Malware activity.
Spam.
Credential abuse.
Unauthorized access.
API abuse.
Network attacks.
Fraud.
Infrastructure misuse.
Violations of our Terms of Service.
This security processing is designed to protect the service and does not involve logging VPN browsing activity.
18. Third-Party Links
Our website, documentation, dashboard, or communications may contain links to third-party websites or services.
We are not responsible for the privacy practices, security, or content of third-party websites or services. You should review their privacy policies before providing information to them.
19. Changes to This Privacy Policy
Xacy may update this Privacy Policy from time to time.
If changes are material, we may notify customers by email, dashboard notice, website notice, or another reasonable method.
The updated Privacy Policy will become effective when posted or on the date stated in the updated policy. Continued use of Xacy after the effective date means you accept the updated Privacy Policy.