Xerg Privacy
Xerg is built around a local-first audit path. This page summarizes the data boundaries that public docs, the CLI, and hosted services should keep aligned.
Local CLI
Local audits run on your machine. Xerg may write local audit snapshots for compare, but local audit data does not leave your environment unless you explicitly use hosted push, connect, or hosted MCP setup flows.
Hosted services
When you push an audit to Xerg Cloud, Xerg receives audit totals, rollups, findings, recommendations, comparison deltas, and source metadata needed to show hosted dashboard and MCP results.
Xerg also uses server-side product analytics to understand aggregate adoption and improve the hosted product. Successful product actions may send PostHog a pseudonymous workspace identifier, workspace plan, event name, status or outcome flags, bounded counts, and coarse consented acquisition fields such as channel, source, medium, and campaign. These events do not include the marketing-site identifier, handoff token, user IDs, names, email addresses, prompts, responses, findings, recommendations, policy values, cost figures, audit-source metadata, URLs, IP addresses, or browser and device metadata. PostHog does not create person profiles for these events, which are retained for no more than 12 months.
Local CLI commands remain telemetry-free and add no analytics call. Explicit hosted pairing and push requests include a fixed, content-free execution-context envelope. Xerg stores successful hosted pairing and audit-storage metadata in a separate operational D1 ledger for up to 365 days, including for workspaces that object to product-project PostHog delivery. That ledger excludes content, findings, costs, paths, source identifiers or hostnames, URLs, IP/geography, names, email addresses, user IDs, and Clerk organization IDs.
If a newly created workspace has not received its first pushed audit after about four hours, Xerg may use Resend to send the workspace creator one transactional setup reminder. The message contains the public skill prompt and activation command. It does not include a workspace key or audit data, and the send does not create a Resend marketing contact.
For workspaces created after Xerg enables its product-signup integration, Xerg may send Cardinal the workspace creator's email address, available first and last name, and the workspace organization's display name. Cardinal uses those details to enrich the signup with business or professional information and support sales follow-up. Xerg does not send Cardinal workspace keys, audit data, prompts, responses, or other product content through this integration.
A workspace administrator may object to future hosted-product analytics by contacting hello@xerg.ai. After the request is verified, the setting applies to future product-project PostHog delivery for the whole workspace; it does not disable the D1 operational ledger needed to measure and repair successful hosted actions. A verified deletion request covers that ledger and each applicable PostHog identity under Xerg's documented deletion procedure.
What push payloads exclude
Push payloads exclude raw prompt and response content, local source file paths, local snapshot store paths, and internal-only finding details.
Account and billing providers
Hosted sign-in, workspace management, and billing may be handled by third-party providers such as Clerk and payment processors. Those providers process the account and billing data needed to operate hosted workspaces.
Website
On production xerg.ai pages, Xerg uses PostHog analytics and may use ad measurement pixels from X, Meta, Reddit, and LinkedIn. Xerg may also use Cardinal Website Visitors, powered by RB2B, to associate a visit with company or professional identity information for sales and marketing follow-up. RB2B may process cookie and device identifiers, IP address, user agent, current and referring page URLs, visit time, and matched professional or business contact information. Xerg treats the advertising pixels and Cardinal/RB2B as selling or sharing personal data for targeted-advertising opt-out purposes.
CookieYes applies two regional consent rules. In the United States, ordinary PostHog analytics, autocapture, advertising pixels, and Cardinal/RB2B are initially enabled with disclosure and opt-out controls, without requiring a response to a first-visit notice. The lower-left privacy icon opens the full CookieYes settings. Everywhere outside the United States, optional analytics, advertising, and visitor identification stay blocked until the applicable category is accepted. PostHog session recording always starts disabled and requires an explicit Analytics acceptance in every country; form inputs are masked by default. Optional marketing trackers are omitted entirely from local development and staging.xerg.ai.
Xerg honors Global Privacy Control as a persistent opt-out from advertising sale/share tracking. While GPC remains active, CookieYes cannot enable the advertising pixels or Cardinal/RB2B. Use either privacy control to review or withdraw consent. Withdrawing a category stops its Xerg-controlled tracking, reloads the page, and removes controllable first-party analytics, attribution, replay, and RB2B state. Xerg cannot directly delete cookies already set on a third party's own domain.
The footer status badge is served by Better Stack, Xerg's public documentation is hosted by Mintlify, and email sent to Xerg addresses is handled through Google Workspace. The hosted dashboard carries no browser analytics, advertising, or visitor-identification scripts; the hosted-product analytics described above is sent by Xerg's servers and sets no analytics cookie or browser storage. Details are on the cookies page.
You can opt out of RB2B or Retention.com identity matching through the database opt-out. Visitors covered by GDPR can also use the GDPR opt-out. These vendor choices are in addition to the controls in Xerg's consent banner.
If you allow marketing-site analytics, Xerg stores a first-touch record in your browser for
up to 30 days containing only a normalized channel, strict source/medium/campaign slugs,
and an external referrer hostname. Email-like, URL-like, overlong, or free-form values are
discarded, and Xerg never stores a full referring or landing-page URL. When you continue from
/signup, a server-signed one-time token can link PostHog's anonymous marketing
identifier to successful workspace creation, workspace pairing, and first audit push. The token expires after
24 hours, the anonymous identifier is cleared after both applicable milestones are accepted
or in all cases within 30 days, and neither value enters the product-analytics project. If consent
is absent or withdrawn, Xerg does not create this link and removes its first-touch browser
storage. Signup continues normally if tracking is unavailable.
If you request a free agent spend review, Xerg uses the name, work email, optional company, optional agent-stack description, and campaign attribution you submit only to respond to that request. The request is sent to Lightfield for sales follow-up and to Resend for an immediate notification to the founder. It is not added to a newsletter or marketing audience. After a successful request, Cal.com scheduling loads only if you choose to book a time; otherwise no information is sent to Cal.com from this page.
On the public demo page, Cal.com loads when the page opens whenever scheduling is available and may receive standard request metadata such as your IP address, browser information, and page URL. If you book, Cal.com also collects your name, work email, selected meeting time, invitation details, and any optional agent-stack or monthly-spend-range answer you provide inside the booking interface. Xerg does not put those answers in the booking URL.
Subprocessors
The full list of third-party providers that may process customer, account, or website-visitor data for hosted services is published at xerg.ai/subprocessors.
Contact
Privacy questions can be sent to hello@xerg.ai.