XNovoraXNovora
Home/Privacy Policy

Privacy Policy

Last Updated: September 5, 2026. A clear, transparent explanation of how XNovora handles data, browser processing, cookies, and user privacy.

At XNovora, we believe digital utility tools should be powerful, fast, and respectful of personal privacy. We have architected our platform around a client-side first model, minimizing data transmission and providing full transparency when server-assisted operations are necessary.

1. Client-Side First Processing (Default Architecture)

The vast majority of utilities on XNovora—including text counters, code formatters, unit and color converters, cryptographic hashers, and mathematical calculators—run entirely within your web browser using modern JavaScript, HTML5 Canvas, and WebAssembly.

  • Local Execution: Your documents, code snippets, numbers, and inputs are processed locally by your computer’s hardware.
  • Zero Default Uploads: Standard utilities do not transmit your input files or text strings to our servers or third-party databases.

2. Server-Assisted Processing Disclosure

Certain specialized operations require computational power or machine learning models that cannot be run efficiently inside standard browser sandboxes. Specifically:

  • AI Background Removal: When you execute background removal in Image Studio, your image is sent securely via HTTPS to our dedicated server-side neural processing service (U²-NetP).
  • Immediate Deletion: The image data is held only transiently in memory for the duration of processing, converted into the transparent output mask, returned to your browser, and immediately purged. We do not save, archive, index, or use your uploaded imagery to train machine learning models.
  • Advance Disclosure: Any workspace that relies on server-side assistance displays a clear, prominent disclosure notice prior to action execution.

3. Cookie Usage & Tracking Policies

We adhere to a strict policy regarding browser cookies and identifiers:

  • No Tracking Cookies: We do not use cross-site tracking cookies, behavioral tracking pixels, or third-party fingerprinting scripts to profile individual users.
  • Essential Authentication Cookies: Essential HTTP-only session cookies may be used for secure authentication and account sessions, including registered users and authorized administrators.

4. Contextual Advertising

To maintain free public access to our utility catalog without subscription paywalls, XNovora may display non-intrusive contextual advertisements. Advertisements are served based on the topic of the active page rather than behavioral profiling or cross-site tracking of personal browsing habits.

5. Aggregate Performance Telemetry & Analytics

We use aggregated or privacy-minimized technical telemetry for performance and reliability monitoring and do not use it to build behavioral profiles of individual users. This telemetry helps measure Core Web Vitals (such as Largest Contentful Paint and Cumulative Layout Shift), monitor platform health, and resolve operational bugs.

6. Transient Memory Lifecycle

For all browser-executed tools, your working files and text inputs reside temporarily in volatile browser RAM or active Canvas memory. Once you navigate away, refresh the page, or close the browser tab, that transient memory is immediately cleared by your browser’s garbage collector.

7. Local Browser Storage (Client-Side State)

We utilize browser-native storage mechanisms (such as localStorage or sessionStorage) exclusively to remember your explicit interface preferences, including:

  • Light or Dark theme selection.
  • Recent tool history or favorite tool bookmarks stored on your device.
  • Workspace layout preferences.

This data remains exclusively on your physical device and is never synchronized to external servers without your explicit request.

8. Third-Party Service Boundaries

When you access external assets (such as web typography hosted via Google Fonts or open-source libraries), your connection communicates directly with those providers according to standard HTTPS protocols. We encourage you to review their respective privacy policies regarding network-level logging.

9. User Control & Data Purging

You have full control over all data stored on your device. You can clear your browser cookies, local storage, and cached files at any time via your browser’s settings menu, which will completely purge all locally retained preferences and state.

10. Security Standards

All network traffic between your web browser and XNovora is encrypted in transit using industry-standard Transport Layer Security (HTTPS/TLS). Our server endpoints incorporate strict security headers (including X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, and Referrer-Policy: strict-origin-when-cross-origin) to prevent data injection and clickjacking attacks.

11. Contact & Inquiries

If you have questions regarding our privacy architecture, data handling practices, or this policy, please reach out to our team through our Contact Page.