Privacy policy
Last updated 27 September 2026 · Draft
ဤစာမျက်နှာကို မြန်မာဘာသာဖြင့် မကြာမီ ဖတ်ရှုနိုင်ပါမည်။ ယခုအချိန်တွင် အင်္ဂလိပ်ဘာသာဖြင့်သာ ရှိပါသေးသည်။
The short version
- Your card is public. Anyone with its link or QR code can see what you put on it, and search engines can list it.
- We keep only what XID needs: your Telegram name and ID, your card and photos, and counts of views, taps and saves. We never get your phone number from Telegram.
- No ads and no trackers. We don't sell your data, and no XID page has advertising or analytics trackers.
- Your data is stored in Singapore by DigitalOcean, and your photos by Cloudflare.
- You can have your card and account deleted. Ask us, and it's done within 30 days. We keep only our decisions on reported cards (so a removed card can't quietly come back) and payment records for our accounts.
Dashed boxes are details still to be filled in.
This page explains what XID keeps about you, why we keep it, who else handles it, how long we keep it, and how to have it deleted. If anything here is unclear, email us at email address (not filled in yet).
01Who we are
XID (also called Xtra ID) is a digital contact card service at xid.sh. It's run by legal name of XID's operator (not filled in yet), postal address (not filled in yet). In this policy, "XID", "we" and "us" mean that operator.
For anything about your data, email email address (not filled in yet).
02Your card is public
Your card is a public web page at your own address, such as aung.xid.sh. Anyone who opens it can see everything you put on it: your name, photo, job title, company, phone numbers, emails, addresses, links, motto and bio.
Search engines such as Google can find and list your card. Apps such as Telegram, Viber and Facebook show a preview with your photo, name and job title when someone shares your link.
To keep your card out of search engines, turn on Hide from search engines in the editor.
When someone saves your contact, your details are copied into their phone. We can't delete them from there.
So only put on your card what you're happy for anyone to see.
03What we keep when you make a card
From Telegram. You log in with Telegram. We get your Telegram name and your Telegram ID (a number that stands for your account). We don't get your phone number, your contacts or your chats, and we don't keep messages you send to the XID bot.
Your Telegram photo. If bots can see your Telegram profile photo, we save a copy when you log in. If you publish your card without adding a photo, your card uses this one. You can change it at any time in the editor.
Your card. Everything you type into the editor, your web address and the design you choose. Until you tap Publish, your draft stays on your phone and we don't have it.
Your photos. We keep the original photo you upload in private storage. Only you can open it, through the editor, so you can reframe it later. From it we make the copies your card shows, and those are public. Photos you've replaced may be kept until you delete your card.
Counts. For each card and each day, we count views, scans of your QR code and taps on your NFC tag, and saves to contacts. On a Free card, we also count how often XID's invitation to make a card is shown and tapped; only XID sees those. They're only numbers: they don't say who viewed your card.
Your contact book. If you use it, it holds the people who shared their details with you and anyone you add yourself, with your private notes. Only you can see it.
Bot messages. The XID bot sends you messages about XID and your card, such as login checks, contacts people share with you, reminders before your Premium ends and, with Premium, your weekly numbers. It writes in the language you last used on XID (English or Burmese), which we keep with your account. It never sends other companies' ads.
04When you open someone's card
Opening a card adds one to its view count. Scanning its QR code or tapping its NFC tag adds a tap, and saving the contact adds a save. On a Free card, seeing XID's invitation to make your own card, and tapping it, are counted the same way. We don't store your IP address (the number your internet connection uses) or any other ID for you when this happens. The card's owner sees only the totals.
The first time you open a card, your browser remembers it, on your phone only, so the card's opening animation plays just once.
On about 1 in 10 visits, your phone also tells us how fast the card appeared and answered your taps: a few timings, which design the card uses, and the kind of connection (such as 4G). It carries nothing that identifies you, your phone or the card you opened, and we keep it for 90 days to make XID faster.
Our hosting companies, Cloudflare and DigitalOcean, see your IP address and browser details when your phone asks for a page. They use them to deliver the page and protect it from attacks, under their own privacy policies.
05When you share your details with a card's owner
If a card offers to share your details back with its owner, this happens only when you fill in the form and tap Share. Saving someone's contact never sends anything about you. After you share, your browser remembers it, on your phone only, so that card doesn't ask you again.
What you share (your name and phone number, and a short note if you add one) goes to that one owner. We send your name and number to them on Telegram, and keep them with your note in their XID contact book. We don't use them for anything else, we don't add you to any list, and we don't make an XID account for you.
The owner can delete your details from their contact book at any time, and they're deleted if the owner deletes their card. The Telegram message we sent the owner stays in their Telegram, and we can't delete it.
To stop spam, we keep a scrambled form of your IP address for 2 days.
To have your details removed, email email address (not filled in yet) with the card's web address and the phone number you shared.
06When you pay for Premium
Premium payments aren't open yet. When they are, this is how they work.
- You pay in your own wallet app, such as KBZPay or WavePay, by scanning XID's payment QR code. We never see your wallet login or PIN.
- You upload a screenshot or photo of your payment slip. We keep the slip and the payment details on it (the amount, date, wallet, transaction number and whether it paid XID) to check your payment and keep our accounts.
- A computer reads the slip first, using Google's Gemini (see the next section). If anything doesn't match, a person at XID checks it, and we may check any payment by hand.
07Features that use AI
If you use a feature that runs on Google's Gemini AI, such as filling in the editor from a photo of your paper business card, checking a payment slip, polishing your photo or making a moving portrait, we send that photo to Google.
We use Google's paid service. Under its terms, Google doesn't use what we send to improve its products, and keeps it only for a limited time to check for misuse.
We don't keep the photo of your paper card once its details are read. A polished photo or moving portrait goes on your card, so it's public like your photo.
AI never runs when someone opens your card.
08Companies that handle data for us
We use a few companies to run XID. They handle your data only to provide their service to us.
- DigitalOcean
- Runs our app and database, in Singapore.
- Cloudflare
- Runs our domain and the network in front of our app, and stores photos (Cloudflare R2). We ask Cloudflare to store files in the Asia-Pacific region, and it keeps copies of public photos on its servers around the world so they load fast.
- Telegram
- Carries your login and our bot's messages. Your Telegram account is also covered by Telegram's privacy policy.
- Runs the AI features above, when you use them.
- Your wallet company
- Handles your payment under its own terms, once payments open.
So your data is stored outside Myanmar: in Singapore, elsewhere in Asia-Pacific and, for public photos, on Cloudflare's servers around the world.
We don't sell your data, share it with advertisers, or use it to train AI.
10How long we keep things
- Your account and card
- Until you delete them. We never delete a card because you stopped paying: it becomes a Free card.
- Your Telegram photo copy, and photos you've replaced
- Until you delete your card.
- View, tap and save counts, and counts of XID's invitation
- As long as your card exists.
- Speed measurements from visits (timings, the card's design, the connection type)
- 90 days.
- Login codes
- They expire after 5 minutes and are deleted within a day.
- Scrambled IP addresses, kept to stop abuse
- 2 days.
- Your contact book: people who share their details with you, and people you add
- Until you delete them, they ask us to, or you delete your card.
- Payment slip images
- 12 months after the payment, or until you delete your card if that's sooner.
- Payment records (amount, date, transaction number)
- 7 years, for our accounts, also after you delete your card.
- Photos of paper business cards
- Not kept. Deleted as soon as the details are read.
- Emails you send us
- 1 year after we've dealt with them.
- What you write in a report on a card, and how to reach you
- 90 days after we've dealt with the report.
- The reason picked in a report
- As long as the card exists. It doesn't say who sent it.
- Our decisions on reported cards (the card's web address, the rule it broke, the date, our note)
- Kept, also after the card is deleted, so a removed card can't quietly come back.
- Backups of our database
- Up to 8 weeks.
- Server logs
- A short time, kept by DigitalOcean. We keep personal details out of them.
11Your choices
- See and change your card at any time in the editor at xid.sh/edit.
- Delete your card and account. Email email address (not filled in yet) with your card's web address. To check it's really you, we'll send a code to your Telegram through the XID bot for you to send back. We then delete your card, account, photos, counts and contact book within 30 days. We keep our decisions on reported cards and the records of your payments (see How long we keep things). Copies in our backups are gone within 8 weeks.
- Get a copy of what we keep about you. Email email address (not filled in yet). After the same check, we'll send it within 30 days.
- Stop bot messages by blocking @XtraID_bot in Telegram. You'll need to unblock it to log in again.
- Remove details you shared with a card's owner: email email address (not filled in yet) with the card's web address and the phone number you shared.
Deleting your card can't remove your details from phones where people saved your contact, from Telegram chats, or from link previews apps have already made.
12Keeping your data safe
Every XID page uses a secure connection (HTTPS). Original photos are kept in private storage with no public address. Logging in needs a Confirm tap in your own Telegram, so there are no passwords to steal. Card pages run only XID's own code, never scripts from other sites.
No system is perfectly safe. If something goes wrong that puts your data at risk, we'll tell you through the XID bot as soon as we can.
Whoever controls your Telegram account can change your card, so keep your Telegram safe.
13Children
XID is for people aged 18 and over. If we learn that a card belongs to someone younger, we'll delete it.
15Changes to this policy
If we change this policy in a way that matters, we'll tell you through the XID bot at least 14 days before the change applies. Small fixes, such as typos, we just make. The date at the top shows when this page last changed.
16Contact us
Email email address (not filled in yet), or write to legal name of XID's operator (not filled in yet), postal address (not filled in yet).
If you email us, we use what you send only to deal with it, and we delete it 1 year after it's dealt with.
If you report a card, only XID sees the report; the card's owner never learns who sent it. What you wrote and how to reach you are deleted 90 days after we've dealt with it.