Xora

Legal

Privacy Policy

What we collect, what we do with it, and what happens to the media you send us. We have tried to make this specific rather than reassuring — vague privacy policies are how you hide things.

Last updated
19 July 2026
Effective
19 July 2026

1. Who we are

Xora is operated by Bit By Bit Labs Private Limited (“we”, “us”), a private limited company incorporated in India, registered office 305, Greater Brajeshwari, Bicholi Mardana, Indore, 452016, Madhya Pradesh, India. This policy covers the Xora website at xora.sh, the dashboard, the API at api.xora.sh, and the media processing behind them.

2. Our role in your data

There are two different relationships here, and they carry different obligations:

  • For your account. When you sign up, we decide what to collect and why, so we are the controller of your account, billing, and usage data.
  • For the media you process. Your files are yours. We process them only on your instructions — the job you submit is the instruction — so for that content we act as a processor on your behalf. If the media contains other people’s personal data, you are the controller of it, and you are responsible for having a lawful basis to process it and for telling those people what you need to.

If you need a Data Processing Agreement for your own compliance, email legal@xora.sh and we will provide one.

3. What we collect

3.1 Account and identity

Your email address, and your name and profile image if your sign-in provider supplies them. Authentication is handled for us by Clerk; if you sign in with Google or GitHub, we receive an identifier and your email from that provider, never your password. We do not store passwords.

3.2 API keys

A name you choose, the time it was created, last used, and revoked — and a SHA-256 hash of the key itself plus a short display prefix. We never store the key in a form we can read, which is why we cannot recover a lost key and can only help you revoke it.

3.3 Job records

For every job: the input URL you supplied, the job configuration you sent, the recipe or FFmpeg arguments, the resulting state and progress, timing, any error, the computed cost breakdown, output filenames and sizes, and the webhook URL and delivered payload if you use webhooks.

Worth knowing: we store the input URL as you sent it. If you use pre-signed URLs, the signature and any credentials embedded in the query string are stored with the job record. Prefer short-lived signed URLs, and do not put long-lived secrets in a URL you send us.

3.4 Usage

Daily aggregates per account — job counts, completed and failed counts, and processing seconds — used for your usage dashboard, plan allowances, and billing.

3.5 Billing

Payments are handled by Paddle as Merchant of Record. Paddle collects and holds your payment details; we never see or store your card number. We receive subscription status, plan, and the billing identifiers we need to reconcile your account.

3.6 Technical logs and support

Standard server logs — IP address, timestamp, endpoint, response status, user agent — kept for security, abuse prevention, and debugging. If you email us, we keep the correspondence so we can follow up.

We do not run analytics, advertising, or tracking scripts on this website. There is no Google Analytics, no advertising pixel, and no third-party tracker.

4. Why we use it

PurposeData usedLegal basis (GDPR)
Running the jobs you submit Job records, media Performance of a contract
Account, authentication, support Account and identity, correspondence Performance of a contract
Billing and tax Usage aggregates, billing identifiers Contract; legal obligation
Security, abuse prevention, debugging Technical logs, job metadata Legitimate interests — keeping the service safe
Service emails (job failures, limits, changes) Email address Contract; legitimate interests
Complying with law and lawful requests Whatever is legally required Legal obligation

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your media or job configurations to train machine-learning models.

5. Your media, specifically

Because this is the part that actually matters for a media API, here is the whole path a file takes:

  • Input. We fetch from the URL you supply. Depending on the job, we either copy the file into the processing environment, or read only the byte ranges we need without copying the whole file.
  • Processing. The job runs on isolated workers. Long jobs are split into chunks processed in parallel, which creates temporary intermediate files.
  • Output. The finished file is delivered to you through an expiring signed URL, and is removed once it is no longer needed to complete your job.

Your media is never public. Output files are private, and access is only ever through a signed URL that expires. We do not browse, index, or review the content of your files, except where we are compelled by law or are acting on a specific abuse or copyright report.

6. How long we keep it

WhatHow long
Job output files Until you delete them, or your account is closed
Copied inputs and intermediate chunk files Temporary; deleted with the job’s files or on account closure
Job records and usage aggregates For the life of the account, so your history and billing reconcile
Technical logs Up to 90 days
Billing and tax records As long as tax and accounting law requires

You can delete output files at any time through the dashboard or the Files API, and deletion is immediate and permanent. We do not currently apply an automatic expiry window to a job’s output — files stay until you remove them or close the account. If we introduce automatic expiry, we will give notice before it takes effect so nothing disappears unexpectedly.

When you close your account we delete your media and job data, other than records we must keep for legal, tax, or fraud-prevention reasons. Backups roll off on their own cycle, within 35 days.

7. Who we share it with

We share data with a small number of infrastructure providers who process it on our behalf under contract. They may use it only to provide their service to us.

Sub-processorWhat it doesWhere
Amazon Web Services Media processing workers, job state United States (us-east-1)
Cloudflare Website and API hosting, application database, CDN Global edge network
Clerk Authentication and identity United States
Paddle Payments as Merchant of Record, invoicing, tax United Kingdom / United States

We will also disclose data where we are legally required to — a valid court order or lawful request — and we will tell you unless we are prohibited from doing so. If the business is acquired or merged, data may transfer as part of that transaction, and this policy continues to apply until you are told otherwise.

We give notice of new sub-processors by updating this page. Email legal@xora.sh to be told when it changes.

8. Where it is processed

We are based in India, our media processing runs in the United States, and Cloudflare serves the site from edge locations worldwide. Using Xora therefore involves international transfers of data, including out of the EEA, the UK, and India.

Where personal data is transferred out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with our providers’ own transfer frameworks. Ask legal@xora.sh if you need the specifics for a vendor review.

9. Security

  • Everything is encrypted in transit with TLS, and media at rest is encrypted by our infrastructure provider.
  • API keys are stored only as SHA-256 hashes.
  • Jobs run in isolated workers, and FFmpeg arguments arrive as a JSON array rather than a shell string, so there is no shell to inject into.
  • Access to production systems is limited to people who need it.
  • Output files are private by default and reachable only through expiring signed URLs.

No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law and without undue delay. Report a vulnerability to security@xora.sh — we will not pursue good-faith researchers who report responsibly.

10. Your rights

Wherever you live, you can ask us to:

  • Access the personal data we hold about you, or get a portable copy;
  • Correct anything inaccurate;
  • Delete your data — you can delete media yourself, and close your account at any time;
  • Restrict or object to processing we carry out under legitimate interests;
  • Withdraw consent where we relied on it, without affecting what came before.

Email privacy@xora.sh. We respond within 30 days, and we will not charge you or treat you differently for asking.

If you are in the EEA or UK, you may also complain to your local supervisory authority. If you are in India, you have rights under the Digital Personal Data Protection Act, 2023, including the right to nominate someone to exercise them on your behalf, and the right to escalate an unresolved grievance to the Data Protection Board of India after raising it with our Grievance Officer below. If you are in California, you have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for exercising any right.

11. Cookies

We use strictly necessary cookies only. Clerk sets a session cookie so you stay signed in to the dashboard, and we may store a preference such as your theme. That is all — there are no analytics, advertising, or tracking cookies, which is why you are not being asked to dismiss a cookie banner. Blocking essential cookies will stop you signing in.

12. Children

Xora is a developer tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact privacy@xora.sh and we will delete it.

13. Changes

We will update this policy as the service changes. The “last updated” date at the top always reflects the current version. For material changes — a new category of data, a new purpose, a new sub-processor handling your media — we will give notice by email or in the dashboard before they take effect.

14. Contact and grievances

Bit By Bit Labs Private Limited
305, Greater Brajeshwari, Bicholi Mardana, Indore, 452016, Madhya Pradesh, India
Privacy and data rights: privacy@xora.sh
Legal and DPAs: legal@xora.sh
Security: security@xora.sh
Support: support@xora.sh

Grievance Officer (Digital Personal Data Protection Act, 2023): Abhinav, privacy@xora.sh. We acknowledge grievances within 7 days and aim to resolve them within 30.

See also our Terms of Service and Refund Policy.