Privacy
Privacy.
Last updated: August 4, 2026
xCLAUDE was built privacy-first. Here's exactly what happens with your data — in the product, and on this website. Plain language, no legalese.
The short version
The xCLAUDE app runs entirely on your Mac and never sends data anywhere. This website collects your email only if you give it to us, and only uses it to send you the download and the product updates you opted into. We don't track you, we don't sell your data, and we don't share it with anyone except the few service providers we need to run the site.
Who we are
For the purposes of GDPR, the data controllers are Rebeca Zambrano Moreno and Ignacio Lucea Artero, the co-creators of xCLAUDE.
You can reach us about privacy through our contact form.
The xCLAUDE app
The xCLAUDE app you install on your Mac:
- Runs entirely locally on your computer.
- Does not connect to any of our servers.
- Does not send telemetry, analytics, or any other data to us or to third parties.
- Stores its audit log locally under
~/Library/Application Support/xCLAUDE Gateway/on your machine. We never see it. - Stores connector authorization tokens in the macOS Keychain, on your machine only. They are never sent to us.
- Is open source under the MIT license. The complete source code is on GitHub so you can verify these claims yourself.
When xCLAUDE is running, no data about you, your prompts, your tool calls, or your machine reaches us.
Google user data
If you connect Google services (Gmail, Google Calendar, Google Drive) through xCLAUDE, this is how Google user data is handled:
- What is accessed. The app routes tool calls between your AI client (Claude Desktop) and Google's official MCP endpoints, using the OAuth scopes you authorize: Gmail read, draft creation and mail organization (gmail.modify). Google's consent screen presents this scope as “Read, compose, and send emails from your Gmail account” — the permission you grant is broader than what the connector does: Google's Gmail MCP exposes no send tool, so drafting is the most that is possible through xCLAUDE. The scope also covers moving mail to Trash and marking it as spam; only permanent deletion that bypasses Trash is excluded. Calendar read and event management (calendar list and free/busy read-only, plus creating, updating, responding to and deleting events via calendar.events), and Drive read access plus per-file access to files opened or created through the app (drive.readonly, drive.file). The data accessed is whatever your AI assistant requests on your behalf through Google's endpoints: email content and metadata, calendar events, and Drive file listings and contents.
- How it is used. Solely to provide the app's single user-facing feature: recording and classifying each tool call in a local audit log on your machine, so you can review what your AI assistant did with your data. No other use.
- What is transferred. Nothing. Google user data is never transmitted to us or to any third party by xCLAUDE. All processing happens locally on your Mac. The only data flow is the one you initiate between Google and your own AI client.
- How it is protected. OAuth tokens are stored exclusively in your macOS Keychain. The audit log is stored locally under
~/Library/Application Support/xCLAUDE Gateway/and never leaves your machine. The app has no backend, no accounts, and no telemetry. - Retention and deletion. Google user data appearing in the local audit log stays on your machine under your control. By default the app never deletes it; in Settings you can enable automatic retention limits (30, 90 or 365 days), which permanently delete older session log files. You can also delete log files directly from disk at any time, and removing a connector deletes its stored tokens from your Keychain. We hold no copy — there is nothing for us to retain or delete.
Limited Use disclosure. xCLAUDE's use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. xCLAUDE does not use Google user data to develop, improve, or train generalized AI or machine-learning models, and does not transfer Google user data to any third party.
This website
This website (xclaude.ai and any subdomains) is the only place where we collect data. Specifically:
- When you download xCLAUDE: providing your email address is optional. If you give it to us, we use it to send you the download link and, only if you opt in, product updates and security notices.
- When you contact us: if you submit our contact form, we collect the email address, your name (if given), the reason you selected, and the message you wrote.
- Server logs: our hosting provider keeps short-lived technical logs (IP address, user agent, requested URL, timestamp) for operational and security purposes.
We do not use cookies for tracking or advertising, third-party analytics (no Google Analytics, no Plausible, no Mixpanel), or tracking pixels that load remote scripts.
What we do with your email
If you give us your email:
- For downloads: we send you the download link, plus product updates and security notices if you opted in.
- For the contact form: we use your email only to reply to you.
We don't sell your email, don't share it with anyone except the email service we use to send messages (see “Service providers”), and don't use it for anything other than the purposes above.
Retention.
- Email for downloads/updates: kept until you ask us to delete it. You can do that any time through the unsubscribe link in our emails or the contact form.
- Contact form submissions: kept up to 24 months unless you ask us to delete earlier.
Legal basis for processing
We process your data on these GDPR legal bases:
- Consent (Article 6(1)(a)): you give us your email voluntarily when you download xCLAUDE or fill out the contact form, and separately for the marketing opt-in. You can withdraw consent at any time without affecting prior processing.
- Legitimate interest (Article 6(1)(f)): basic server logs to keep the website operational and secure, and replying to contact form submissions you initiated.
Service providers
We use these third-party processors. They process data only as needed to provide their service to us, under data processing agreements where required by law.
| Provider | What it does | Data it receives |
|---|---|---|
| Lovable | hosts this website | standard server log data (IP address, browser type, requested URLs) |
| Resend | sends our emails | the email addresses we send to |
| GitHub | hosts the open-source repositories and the public binary releases | standard logs when users download xCLAUDE directly from GitHub |
International data transfers
Some of our service providers operate from the United States or other countries outside the European Economic Area. When personal data is transferred outside the EEA, we rely on the Standard Contractual Clauses approved by the European Commission, or equivalent safeguards required by GDPR.
Your rights
Under GDPR you have the right to:
Access
ask what data we hold about you.
Rectification
ask us to correct inaccurate data.
Erasure
ask us to delete your data.
Restriction
ask us to limit how we process your data.
Portability
ask for a copy of your data in a machine-readable format.
Object
ask us to stop processing data based on legitimate interest.
Withdraw consent
at any time, without affecting prior processing.
To exercise any of these, use our contact form. We aim to respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority. In Spain that's the Agencia Española de Protección de Datos (www.aepd.es).
Children's privacy
xCLAUDE is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Security
We use HTTPS in transit, encryption at rest with our service providers, and limit access to the people who need it. No system is 100% secure, but we treat the small amount of data we hold with care. If we discover a data breach affecting your personal data, we will notify you and the supervisory authority as required by GDPR.
Changes to this policy
If we change this policy in a way that materially affects you, we will post the new version here with an updated date and notify subscribers by email.
Contact
For any privacy question or to exercise your rights, use our contact form and select “Security or privacy concern” as the reason.
Last updated: August 4, 2026.