Xerg Privacy
Xerg is built around a local-first audit path. This page summarizes the data boundaries that public docs, the CLI, and hosted services should keep aligned.
Local CLI
Local audits run on your machine. Xerg may write local audit snapshots for compare, but local audit data does not leave your environment unless you explicitly use hosted push, connect, or hosted MCP setup flows.
Hosted services
When you push an audit to Xerg Cloud, Xerg receives audit totals, rollups, findings, recommendations, comparison deltas, and source metadata needed to show hosted dashboard and MCP results.
Xerg also uses server-side product analytics to understand aggregate adoption and improve the hosted product. Successful product actions may send PostHog a pseudonymous workspace identifier, workspace plan, event name, status or outcome flags, bounded counts, and coarse consented acquisition fields such as channel, source, medium, and campaign. These events do not include the marketing-site identifier, handoff token, user IDs, names, email addresses, prompts, responses, findings, recommendations, policy values, cost figures, audit-source metadata, URLs, IP addresses, or browser and device metadata. PostHog does not create person profiles for these events, which are retained for no more than 12 months.
If a newly created workspace has not received its first pushed audit after about four hours, Xerg may use Resend to send the workspace creator one transactional setup reminder. The message contains the public skill prompt and activation command. It does not include a workspace key or audit data, and the send does not create a Resend marketing contact.
For workspaces created after Xerg enables its product-signup integration, Xerg may send Cardinal the workspace creator's email address, available first and last name, and the workspace organization's display name. Cardinal uses those details to enrich the signup with business or professional information and support sales follow-up. Xerg does not send Cardinal workspace keys, audit data, prompts, responses, or other product content through this integration.
A workspace administrator may object to future hosted-product analytics by contacting query@xerg.ai. After the request is verified, the setting applies to the whole workspace.
What push payloads exclude
Push payloads exclude raw prompt and response content, local source file paths, local snapshot store paths, and internal-only finding details.
Account and billing providers
Hosted sign-in, workspace management, and billing may be handled by third-party providers such as Clerk and payment processors. Those providers process the account and billing data needed to operate hosted workspaces.
Website
The xerg.ai marketing site uses PostHog analytics and ad measurement pixels from X, Meta, Reddit, and LinkedIn, managed through a consent banner. On production pages, Xerg may also use RB2B after advertisement consent to associate a visit with company or professional identity information for sales and marketing follow-up. RB2B may process cookie and device identifiers, IP address, user agent, current and referring page URLs, visit time, and matched professional or business contact information. The hosted dashboard carries no analytics, advertising, or visitor-identification scripts; the hosted-product analytics described above is sent by Xerg's servers and sets no analytics cookie or browser storage. Details are on the cookies page.
You can opt out of RB2B or Retention.com identity matching through the database opt-out. Visitors covered by GDPR can also use the GDPR opt-out. These vendor choices are in addition to the controls in Xerg's consent banner.
If you allow marketing-site analytics, Xerg stores a first-touch record in your browser for
up to 30 days containing only a normalized channel, strict source/medium/campaign slugs,
and an external referrer hostname. Email-like, URL-like, overlong, or free-form values are
discarded, and Xerg never stores a full referring or landing-page URL. When you continue from
/signup, a random one-time token can link PostHog's anonymous marketing
identifier to successful workspace creation and first audit push. The token expires after
24 hours, the anonymous identifier is cleared from Xerg's database after activation and in
all cases within 30 days, and neither value enters the product-analytics project. If consent
is absent or withdrawn, Xerg does not create this link and removes its first-touch browser
storage. Signup continues normally if tracking is unavailable.
If you request a free agent spend review, Xerg uses the name, work email, optional company, optional agent-stack description, and campaign attribution you submit only to respond to that request. The request is sent to Lightfield for sales follow-up and to Resend for an immediate notification to the founder. It is not added to a newsletter or marketing audience. After a successful request, Cal.com scheduling loads only if you choose to book a time; otherwise no information is sent to Cal.com from this page.
Subprocessors
The full list of third-party providers that may process customer or account data for hosted services is published at xerg.ai/subprocessors.
Contact
Privacy questions can be sent to query@xerg.ai.