Xamseen
Privacy Policy
Xamseen exists so communities can document real problems and turn them into action. That only works if people trust what happens to what they share. This policy explains, in plain language, what we collect, why we process it, who can see it, and what you control.
Last updated 8 August 2026
1. Who we are and how to contact us
Xamseen is a global community reporting platform operated by [to be provided before launch: registered legal entity name], reachable for legal notices at [to be provided before launch: registered or postal address].
For privacy questions or to make a request about your information, contact [to be provided before launch: privacy contact email address]. Where we are required to appoint a data protection officer or representative, that role is held by [to be provided before launch: DPO or representative, or a statement that none is appointed].
2. What information we collect
Almost everything below is information you actively give us. We do not buy personal data about you.
- Account information — your email address, username, and the password hash held by our authentication provider. If you sign in with Google, we receive your basic profile information from Google rather than a password.
- Profile information — the display name, bio, avatar, cover image, website, account type, language, timezone and location description you choose to add. All of this is optional beyond a username.
- Reports and community content — the descriptions, photos, videos and any other media you submit, plus posts, questions, answers, comments, confirmations, votes, bookmarks and project or Space participation.
- Location information — coordinates and a place name attached to a report, only when you choose to use a location feature and your device grants permission. You control the precision Xamseen stores in Settings, including turning coordinate storage off entirely.
- Notification and communication preferences — your in-app, email, push and digest choices, and unsubscribe or suppression records.
- Technical information needed to operate and secure the service — IP address, browser and device characteristics, request and error logs, and security events such as sign-in attempts.
- Support and contact messages — what you send us when you report a problem, appeal a moderation decision or make a privacy request.
- Moderation records — reports of abusive content, moderation decisions and enforcement history, kept so decisions can be reviewed and appealed.
Video you attach to a post, report or official record is stored privately. It is never served from a public, guessable address: playback happens through a short-lived link that is issued only after we re-check that the record it belongs to is visible to the person watching. Camera and microphone access is requested only at the moment you deliberately start a recording, we do not read device metadata beyond the file itself, and deleting your video removes the stored file along with the poster frame taken from it. Audio you attach is treated the same way as other media you submit and is covered by this policy and by your visibility choices.
3. Why we process information
- To provide Xamseen: create your account, show your feed, publish and display community content.
- To authenticate you and keep your account secure, including verification and password reset.
- To publish and process community reports according to the visibility and precision choices you made, and to move them through confirmation, status tracking and resolution.
- To connect you with the communities, Spaces, projects and areas you choose to follow.
- To identify patterns across many reports — repeated locations, recurring categories, hotspots — and turn them into actionable community insight. Wherever the insight does not require identifying an individual, we use aggregated, anonymised or de-identified information.
- To send service communications: verification, password resets, security alerts, activity notifications and digests you opted into. These are operational messages, not advertising.
- To prevent, detect and respond to abuse, spam, false or malicious reports, fraud and security incidents.
- To keep the service reliable, accessible and fast, including diagnosing errors and outages.
- To comply with legal obligations that apply to us, and to establish or defend legal claims.
The legal basis for each purpose depends on where you are and is being confirmed with legal counsel before launch; we will state the applicable bases in this section rather than guess at them.
4. What we do not do
- We do not sell your personal data.
- We do not rent or licence your personal data.
- We do not broker personal data or act as a data broker.
- We do not sell location data or location histories.
- We do not build advertising or ad-targeting profiles from your data.
- We do not run third-party advertising trackers, ad pixels or advertising SDKs in Xamseen.
What we do instead is narrower and more honest: we process the data needed to run Xamseen, and we surface patterns from community reports so the people who can fix a problem can see it.
6. How long we keep information
We keep information only as long as reasonably necessary for the purpose it was collected for, plus any period required for legal obligations, safety, security investigations, dispute resolution or legitimate operational needs.
- Account and profile data is kept while your account exists.
- Reports and community content remain published while relevant to the community and to the tracking of the issue. Deleting your account removes your account and profile; where a report has become part of a shared civic record, we may retain a de-identified version of it.
- Security, error and moderation logs are kept for a limited period appropriate to detecting and investigating abuse.
- Email suppression records (unsubscribes, bounces) are kept for as long as needed to keep honouring your choice.
Exact retention periods per category are being finalised with legal review before launch and will be published here rather than approximated.
7. Security
- Traffic between your device and Xamseen is encrypted in transit using HTTPS.
- Access to data is enforced at the database level with row-level security policies, so a request can only read or change what that account is permitted to.
- Authentication is handled by a managed provider; passwords are stored as hashes and never in readable form, and we support verification and password reset flows with expiring links.
- Privileged administrative access is limited to what is necessary to operate and moderate the service.
- We monitor application errors and security events so we can detect and respond to problems quickly.
No online service can promise perfect security, and we will not pretend otherwise. If a breach affects your information and we are required to notify you, we will.
8. Your rights and controls
Depending on where you live, you may have the right to access your information, correct it, delete it, obtain a portable copy, restrict or object to certain processing, withdraw consent where consent is the basis we rely on, and complain to your local data protection authority.
You can exercise the main ones yourself, right now, in Xamseen:
- Access and portability — Settings → Privacy & your data → Download my data exports your profile, posts, comments, reports and preferences as a JSON file.
- Correction — edit your profile and preferences in Settings at any time.
- Deletion — Settings → Privacy & your data → Delete my account permanently deletes your account, profile and your content.
- Location minimisation — Settings → Privacy & your data → Location precision controls how precisely coordinates are stored on new reports, including not storing them at all.
- Communication choices — Settings → Notifications controls in-app and email notifications per category. Security and account emails are always sent because they protect your account.
For anything not covered by those controls, contact [to be provided before launch: privacy contact email address].
9. International users and transfers
Xamseen is used globally, and our hosting, database, storage and email providers may process information in countries other than the one you live in. When information moves across borders we rely on the safeguards our providers make available, such as contractual data protection terms and provider-level transfer mechanisms.
The specific transfer mechanisms and processing regions that apply to Xamseen are being confirmed with legal counsel before launch, and will be described here precisely instead of in general terms.
10. Age requirement
Xamseen is not intended for children. You must be at least 16 years old to create an account, or older where your country requires a higher age for this kind of service. We do not knowingly collect personal data from children below the applicable age.
If you believe a child has created an account or that we hold a child's personal data, contact [to be provided before launch: privacy contact email address] and we will remove it.
12. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we use your information, we will tell you in the product or by email before it takes effect, where that is appropriate.

