Xome
FeaturesHow it worksFAQDocsTry Xome →Join waitlist

Legal · Privacy Policy

Privacy. Plainly stated.

Effective July 2, 2026 · Last updated July 2, 2026

The short version. Xome is local-first. Your models can run on your own device, and your conversations, memory, API keys, connection tokens, and wallet all live in your browser, not on our servers. When you use a cloud model or a connected app, your data goes directly to the provider you chose, with your own credentials, and we don’t keep a copy. We can’t read your email, your files, or your wallet, and we never hold your crypto.

This Privacy Policy explains how Xome (“Xome”, “we”, “us”) handles information across the Xome web app at app.xome.bot and this website at xome.bot (together, the “Service”). Xome is designed so that we handle as little of your data as technically possible.

How Xome is built

The Xome app is a local-first agent that runs in your browser. Local (on-device) models run entirely on your machine via WebGPU. Your conversations, memory, preferences, API keys, OAuth tokens, and pasted secrets are stored in your browser’s own storage (IndexedDB and localStorage). When a tool needs to reach an outside service, the request passes through a stateless proxy that attaches your credential for that single call and forwards it, it is not stored, logged, or retained on our servers.

What we collect

From this website, if you join the waitlist we collect the email address you provide, an optional source tag, and basic request metadata used only to prevent abuse: your browser’s user-agent string, the referring page, and a one-way hash of your IP address (we do not store your raw IP). This is kept in our waitlist database and used to contact you about Xome and to protect the signup form. We do not sell your data or use advertising or cross-site tracking cookies.

What we don’t collect

We do not collect or store the content you work with in the app: your emails, calendar, Slack messages, GitHub issues, Notion pages, files, chat history, memory, model API keys, connection tokens, or wallet keys. There is no Xome account, and there is no server-side copy of this data. Clearing your browser’s site data, or using the app’s data controls, erases it.

Cloud AI models

If you choose a cloud model (such as Claude, GPT, or Gemini) instead of an on-device one, your prompts and the relevant context are sent to that provider using the API key you supplied, relayed through our stateless proxy without being stored or logged. Your use of that model is governed by that provider’s own terms and privacy policy, and any usage or billing is between you and them.

Connected services

When you connect an app (for example Google/Gmail and Calendar, Slack, GitHub, Notion, or any MCP server), the access token stays in your browser. When a tool runs, the token is attached to that single request through the proxy and then discarded, we don’t retain it. Xome only requests the permissions needed for the features you use, and you can disconnect a service at any time from the Connections screen, which removes its token from your browser.

Crypto wallets & blockchain

Xome’s Solana features are non-custodial. Your embedded wallet is created and secured through our wallet provider, Privy, and transactions are signed in your browser, we never hold, control, or have access to your private keys or funds. Blockchain transactions are public and permanent by nature: once submitted they cannot be reversed, and the addresses and amounts are visible on the public ledger. Balance lookups, transfers, and swaps use third-party infrastructure (such as a Solana RPC provider and the Jupiter aggregator), whose handling of on-chain requests is outside our control.

Third-party services

Xome is a tool that connects to services you choose. Those providers, AI model vendors, the apps you connect, MCP servers you add, Privy, Solana RPC providers, and DEX aggregators, each have their own terms and privacy practices, and your data flows to them because you directed Xome to act. We are not responsible for how those third parties handle your data.

Your control

Because your app data lives in your browser, you control it. You can delete conversations and memory from within the app, disconnect any service, remove stored keys, or clear the site’s data entirely from your browser. For anything on this website (such as removing your waitlist email), contact us using the details below.

Security

Keeping data on your device and out of our servers removes an entire class of risk, but no method of storage or transmission is completely secure. You are responsible for the security of your device, browser, credentials, and wallet. Xome is provided without any guarantee of security or availability.

Children

Xome is intended only for people aged 18 or older and is not directed to children. We do not knowingly collect information from anyone under 18.

Changes

We may update this Privacy Policy from time to time. When we do, we’ll revise the date above. Continuing to use the Service after a change means you accept the updated policy.

Contact

Questions about privacy? Email contact@xome.bot.

Last updated July 2, 2026.