DraftNot final yet. It may still change.

Privacy policy

Last updated 27 September 2026 · Draft

ဤစာမျက်နှာကို မြန်မာဘာသာဖြင့် မကြာမီ ဖတ်ရှုနိုင်ပါမည်။ ယခုအချိန်တွင် အင်္ဂလိပ်ဘာသာဖြင့်သာ ရှိပါသေးသည်။

The short version

Dashed boxes are details still to be filled in.

This page explains what XID keeps about you, why we keep it, who else handles it, how long we keep it, and how to have it deleted. If anything here is unclear, email us at email address (not filled in yet).

01Who we are

XID (also called Xtra ID) is a digital contact card service at xid.sh. It's run by legal name of XID's operator (not filled in yet), postal address (not filled in yet). In this policy, "XID", "we" and "us" mean that operator.

For anything about your data, email email address (not filled in yet).

02Your card is public

Your card is a public web page at your own address, such as aung.xid.sh. Anyone who opens it can see everything you put on it: your name, photo, job title, company, phone numbers, emails, addresses, links, motto and bio.

Search engines such as Google can find and list your card. Apps such as Telegram, Viber and Facebook show a preview with your photo, name and job title when someone shares your link.

To keep your card out of search engines, turn on Hide from search engines in the editor.

When someone saves your contact, your details are copied into their phone. We can't delete them from there.

So only put on your card what you're happy for anyone to see.

03What we keep when you make a card

From Telegram. You log in with Telegram. We get your Telegram name and your Telegram ID (a number that stands for your account). We don't get your phone number, your contacts or your chats, and we don't keep messages you send to the XID bot.

Your Telegram photo. If bots can see your Telegram profile photo, we save a copy when you log in. If you publish your card without adding a photo, your card uses this one. You can change it at any time in the editor.

Your card. Everything you type into the editor, your web address and the design you choose. Until you tap Publish, your draft stays on your phone and we don't have it.

Your photos. We keep the original photo you upload in private storage. Only you can open it, through the editor, so you can reframe it later. From it we make the copies your card shows, and those are public. Photos you've replaced may be kept until you delete your card.

Counts. For each card and each day, we count views, scans of your QR code and taps on your NFC tag, and saves to contacts. On a Free card, we also count how often XID's invitation to make a card is shown and tapped; only XID sees those. They're only numbers: they don't say who viewed your card.

Your contact book. If you use it, it holds the people who shared their details with you and anyone you add yourself, with your private notes. Only you can see it.

Bot messages. The XID bot sends you messages about XID and your card, such as login checks, contacts people share with you, reminders before your Premium ends and, with Premium, your weekly numbers. It writes in the language you last used on XID (English or Burmese), which we keep with your account. It never sends other companies' ads.

04When you open someone's card

Opening a card adds one to its view count. Scanning its QR code or tapping its NFC tag adds a tap, and saving the contact adds a save. On a Free card, seeing XID's invitation to make your own card, and tapping it, are counted the same way. We don't store your IP address (the number your internet connection uses) or any other ID for you when this happens. The card's owner sees only the totals.

The first time you open a card, your browser remembers it, on your phone only, so the card's opening animation plays just once.

On about 1 in 10 visits, your phone also tells us how fast the card appeared and answered your taps: a few timings, which design the card uses, and the kind of connection (such as 4G). It carries nothing that identifies you, your phone or the card you opened, and we keep it for 90 days to make XID faster.

Our hosting companies, Cloudflare and DigitalOcean, see your IP address and browser details when your phone asks for a page. They use them to deliver the page and protect it from attacks, under their own privacy policies.

05When you share your details with a card's owner

If a card offers to share your details back with its owner, this happens only when you fill in the form and tap Share. Saving someone's contact never sends anything about you. After you share, your browser remembers it, on your phone only, so that card doesn't ask you again.

What you share (your name and phone number, and a short note if you add one) goes to that one owner. We send your name and number to them on Telegram, and keep them with your note in their XID contact book. We don't use them for anything else, we don't add you to any list, and we don't make an XID account for you.

The owner can delete your details from their contact book at any time, and they're deleted if the owner deletes their card. The Telegram message we sent the owner stays in their Telegram, and we can't delete it.

To stop spam, we keep a scrambled form of your IP address for 2 days.

To have your details removed, email email address (not filled in yet) with the card's web address and the phone number you shared.

06When you pay for Premium

Premium payments aren't open yet. When they are, this is how they work.

07Features that use AI

If you use a feature that runs on Google's Gemini AI, such as filling in the editor from a photo of your paper business card, checking a payment slip, polishing your photo or making a moving portrait, we send that photo to Google.

We use Google's paid service. Under its terms, Google doesn't use what we send to improve its products, and keeps it only for a limited time to check for misuse.

We don't keep the photo of your paper card once its details are read. A polished photo or moving portrait goes on your card, so it's public like your photo.

AI never runs when someone opens your card.

08Companies that handle data for us

We use a few companies to run XID. They handle your data only to provide their service to us.

DigitalOcean
Runs our app and database, in Singapore.
Cloudflare
Runs our domain and the network in front of our app, and stores photos (Cloudflare R2). We ask Cloudflare to store files in the Asia-Pacific region, and it keeps copies of public photos on its servers around the world so they load fast.
Telegram
Carries your login and our bot's messages. Your Telegram account is also covered by Telegram's privacy policy.
Google
Runs the AI features above, when you use them.
Your wallet company
Handles your payment under its own terms, once payments open.

So your data is stored outside Myanmar: in Singapore, elsewhere in Asia-Pacific and, for public photos, on Cloudflare's servers around the world.

We don't sell your data, share it with advertisers, or use it to train AI.

09Cookies and storage on your phone

XID uses only the cookies it needs to work. There are no advertising or analytics cookies, so there's no cookie banner.

Login cookie (lc_session)
Keeps you logged in on this browser for 90 days. Scripts on the page can't read it.
Owner cookie (lc_slug)
Tells your own card to show your owner buttons, such as Show my QR and Share. It lasts a year and gives no access to anything.
Language cookie (lc_lang)
Remembers whether you chose Burmese or English, if you pick one. It lasts a year.
Editor draft
Your card before you publish it, saved in your browser on your phone.
"Seen" marks
Remember which cards you've opened, so their opening animation plays once. Saved in your browser on your phone.
Show my QR offline copy
If you add Show my QR to your home screen, your phone keeps a copy of your QR code and contact details so it works without a signal.

10How long we keep things

Your account and card
Until you delete them. We never delete a card because you stopped paying: it becomes a Free card.
Your Telegram photo copy, and photos you've replaced
Until you delete your card.
View, tap and save counts, and counts of XID's invitation
As long as your card exists.
Speed measurements from visits (timings, the card's design, the connection type)
90 days.
Login codes
They expire after 5 minutes and are deleted within a day.
Scrambled IP addresses, kept to stop abuse
2 days.
Your contact book: people who share their details with you, and people you add
Until you delete them, they ask us to, or you delete your card.
Payment slip images
12 months after the payment, or until you delete your card if that's sooner.
Payment records (amount, date, transaction number)
7 years, for our accounts, also after you delete your card.
Photos of paper business cards
Not kept. Deleted as soon as the details are read.
Emails you send us
1 year after we've dealt with them.
What you write in a report on a card, and how to reach you
90 days after we've dealt with the report.
The reason picked in a report
As long as the card exists. It doesn't say who sent it.
Our decisions on reported cards (the card's web address, the rule it broke, the date, our note)
Kept, also after the card is deleted, so a removed card can't quietly come back.
Backups of our database
Up to 8 weeks.
Server logs
A short time, kept by DigitalOcean. We keep personal details out of them.

11Your choices

Deleting your card can't remove your details from phones where people saved your contact, from Telegram chats, or from link previews apps have already made.

12Keeping your data safe

Every XID page uses a secure connection (HTTPS). Original photos are kept in private storage with no public address. Logging in needs a Confirm tap in your own Telegram, so there are no passwords to steal. Card pages run only XID's own code, never scripts from other sites.

No system is perfectly safe. If something goes wrong that puts your data at risk, we'll tell you through the XID bot as soon as we can.

Whoever controls your Telegram account can change your card, so keep your Telegram safe.

13Children

XID is for people aged 18 and over. If we learn that a card belongs to someone younger, we'll delete it.

14When the law asks for data

We give data to the police, courts or government only when a law that applies to us requires it. We check every request and give only what it requires. Where the law allows, we'll tell you first.

15Changes to this policy

If we change this policy in a way that matters, we'll tell you through the XID bot at least 14 days before the change applies. Small fixes, such as typos, we just make. The date at the top shows when this page last changed.

16Contact us

Email email address (not filled in yet), or write to legal name of XID's operator (not filled in yet), postal address (not filled in yet).

If you email us, we use what you send only to deal with it, and we delete it 1 year after it's dealt with.

If you report a card, only XID sees the report; the card's owner never learns who sent it. What you wrote and how to reach you are deleted 90 days after we've dealt with it.

Read the Terms of use