PRIVACY BASELINE

Collect less.
Share deliberately.

This is the current plain-language privacy baseline for the website and private-development products. A formal release policy will be reviewed before public distribution.

01 / WEBSITE

Limited analytics and defensive security logs

XenoSentinel measures page visits, navigation, coarse device and browser groups, performance, downloads, and errors to improve the site. It does not use advertising trackers, third-party analytics, cross-site profiles, precise location, or persistent visitor cookies. Session identifiers expire with the browser tab, daily visitor estimates rotate every day, analytics events are removed after 90 days, and Global Privacy Control or Do Not Track disables analytics collection.

Separately, the site records IP address, time, requested route, response status, and browser user-agent details in a private security log used to investigate abuse, automated probing, and attacks. These security events are removed after 30 days. Security logging is necessary to protect the service and is not disabled by the analytics opt-out. An address placed on the owner-managed denylist remains there until the owner removes it. Hosting infrastructure may also maintain standard access logs under the hosting provider's policies.

Analytics on this browser: CHECKING

You can change this choice at any time on this device.

02 / DESKTOP PRODUCTS

Local-first private beta

Engagements, scopes, findings, settings, and reports are stored on the operator’s computer. Current beta builds do not automatically upload analytics, telemetry, crashes, or feedback. The operator chooses the assessment target and separately reviews any feedback export before sharing it.

03 / SENIOR SHIELD

Proposed consent-centered design

Senior Shield is not released. Its proposed pilot would minimize collection, favor on-device preprocessing and redaction, use short retention periods, provide deletion and withdrawal paths, and require clear resident consent before involving family or staff. No medical-record integration is proposed.

04 / CONTACT

Email is not a secure evidence vault

Do not email passwords, private keys, medical information, financial records, customer evidence, regulated data, or unredacted screenshots. Begin with the minimum description needed to understand the request.