Privacy Policy
Last updated 15 July 2026
1. Who we are
xbackupman (“xbackupman”, “we”, “us”) provides a backup automation service that schedules, encrypts and verifies backups of your databases, servers and sites, and delivers them to storage that you own and control. This policy explains what personal data we process, why, and the choices you have. If you have questions, contact us at [email protected].
2. Data we collect
We collect only what we need to run the service:
- Account data — your name, email address and organization name, created when you sign up. Authentication is handled with Better Auth; passwords are stored only as salted hashes, never in plain text.
- Connection metadata — the configuration you enter to run backups: source hostnames, ports, database names, storage bucket details and schedules. Credentials for your sources and storage are encrypted at rest.
- Billing data — if you subscribe to a paid plan, payments are processed by Stripe. We receive plan status and the last four digits and brand of your card; we never receive or store your full card number.
- Operational logs — job run history (start time, status, size, checksum), plus standard technical logs and IP addresses used for security, debugging and abuse prevention.
3. What we do NOT collect
We do not read the contents of your backups. Every backup is encrypted with AES-256-GCM inside the worker before it is uploaded, and it is written directly to your own S3-compatible storage. The backup payloads do not pass through or reside on our servers as readable data, and the encryption keys required to open them are not stored in your bucket.
4. How we use your data
- To provide, schedule and monitor your backups and restores.
- To authenticate you and secure your account and organization.
- To process payments and manage subscriptions (paid plans).
- To send transactional notifications about backup successes and failures, and important service or security messages.
- To detect, prevent and investigate fraud, abuse and security incidents, and to comply with legal obligations.
We do not sell your personal data, and we do not use your backup contents for advertising or model training.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on: performance of a contract (to deliver the service you signed up for); legitimate interests (securing and improving the service, preventing abuse); consent (where required, e.g. optional communications); and compliance with legal obligations.
6. Storage & encryption model
Your backups live in storage you provide and own — for example AWS S3, Cloudflare R2, Backblaze B2 or self-hosted MinIO. We orchestrate the backup jobs; the encrypted data is delivered to your bucket. This means you retain custody and control of your data at rest, and can revoke our access to your storage at any time by rotating the storage credentials you supplied.
7. Subprocessors
We use a small number of vetted third parties to run the service. Current subprocessors:
- Stripe — payment processing and subscription billing.
- Cloud hosting & CDN — infrastructure hosting for the application and worker, and network/CDN services (e.g. Cloudflare) for delivery and protection.
Your own storage provider is chosen and controlled by you and is not our subprocessor. We will give notice of material changes to this list where required.
8. Retention
We keep account and connection data for as long as your account is active. Backup job metadata (history and checksums) is retained according to your plan and settings. The backups themselves are retained in your storage under the retention policies you configure — pruning happens in your bucket. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain limited records for legal, tax or security reasons.
9. Your rights
Depending on where you live, you may have the right to access, correct, export (portability), or erase your personal data, to restrict or object to certain processing, and to withdraw consent. You can exercise most of these directly in the dashboard, or by contacting [email protected]. You also have the right to lodge a complaint with your local data protection authority.
10. Security
We use encryption in transit (TLS) and at rest for sensitive fields, salted password hashing, tenant isolation scoped to your organization, and least-privilege access controls. No system is perfectly secure, but protecting your data is the core of what we do.
11. International transfers
Our infrastructure and subprocessors may process data in countries other than yours. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app or by email. Continued use of the service after an update constitutes acceptance of the revised policy.
13. Contact
Questions or requests about your privacy? Email [email protected]. See also our Terms of Service and Data Processing Addendum.