Legal · Xyra AB

Privacy Policy

Last updated: August 8, 2026

1. Data Controller

The data controller responsible for the processing of your personal data is Xyra AB (org. nr 559558-6701), Mälaregatan 12, 151 71 Södertälje, Sweden. For all data requests and privacy questions, contact support@getxyra.com.

2. 100% Local Vision Processing

Your privacy is protected by design. All screen analysis, OCR, and template matching run locally on your device. Screenshots are never uploaded to us and we never see your screen. The app contains no code that sends an image anywhere.

While a bot runs, screen frames are held in memory and then discarded. Two things you do yourself save pictures on the phone instead:

  • Cropping a region to build a bot. The crop is saved, because it is the picture the bot has to match against later.
  • Adding a Capture Data step to a bot. It saves frames so you can collect your own training set.

Both write only to Xyra's own storage on your device, under a size limit, and both stay there until you delete them, clear the app's data, or uninstall it. Neither is sent to us. Those files leave your phone only if you choose to export or share them yourself.

3. The Accessibility Service

Xyra uses Android's Accessibility API for one purpose: dispatching the taps and swipes you have configured. The service is declared with canRetrieveWindowContent set to false, so it cannot and does not read window content, text, or app state.

What Xyra sees comes from the Screen Capture permission, which Android grants through its own system dialog and which you approve each session. Those captures are processed on your device and are never sent to us. Section 2 covers the two cases where you can choose to save them on the phone. We collect nothing through the Accessibility service, store nothing from it, and share nothing from it with anyone.

4. Data Collection & Legal Basis

We process the following limited data. The legal basis (GDPR Art. 6) is stated per category:

  • Account data: Email address for login, account recovery, and support. Legal basis: performance of our contract with you (Art. 6(1)(b)).
  • Device identifier (Android ID): Used solely to enforce our single-device policy, so one account signs in on one phone at a time. Legal basis: our legitimate interest (Art. 6(1)(f)) in protecting accounts against shared or stolen credentials. It is not linked to your screen, what you automate, or your location.
  • Terms acceptance record: Which version of the Terms you accepted and when, kept as an append-only log so we can demonstrate your consent. Legal basis: our legal obligation and accountability (Art. 6(1)(c) and Art. 7(1)).

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

We never receive screenshots, gameplay data, or anything shown on your screen. Blueprints you create or customize inside the app, and any pictures they contain, are stored in your device's own storage; we do not upload them. Images saved on the phone by a Capture Data step, or by cropping a region, are covered in section 2 and are not sent to us either. There are no analytics, crash reporting, or tracking SDKs in the app.

5. Third-Party Processors

We use encrypted connections to talk to our trusted partners:

  • Google Firebase (Authentication, Firestore, and related Google services): Secure login plus the database that holds your account flags and the public blueprint catalog. The app also runs Google's Play Integrity check through Firebase App Check, which tells our servers the app is a genuine unmodified build and carries no personal data of yours. Data may be processed in the US under Standard Contractual Clauses (SCCs).
  • Stripe: Processing voluntary donations, where that link is shown. We never see your card data.
  • Cloudflare: Content delivery and DDoS/bot protection for getxyra.com. As it sits in front of the site, it processes your IP address and request metadata to route and protect traffic.

The public blueprint catalog (browsable inside the app) is a read-only resource. Browsing it or installing a blueprint does not log or share information about you beyond the standard authenticated session needed to read the catalog.

6. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, and secure authentication. However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and affected users without undue delay, as required by GDPR Articles 33 and 34.

7. Data Retention & Your Rights

We store data only as long as your account is active and the data is necessary for the purposes outlined in this policy. Tax records are kept for 7 years as required by Swedish law. Inactive accounts may be deleted after 3 years of inactivity.

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data ("right to be forgotten").
  • Right to Restrict Processing: Limit how we use your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time (where applicable).

To exercise these rights, contact us at support@getxyra.com. We will respond within 30 days. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

8. Children's Privacy

Xyra is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from a child without parental consent, we will delete such information promptly.

9. International Data Transfers

Your data may be processed and stored in servers located outside the European Economic Area (EEA), including the United States. When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions by the European Commission.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notification at least 30 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy. If you do not agree, you must stop using the Service and delete your account.

11. Contact

Xyra AB has not appointed a formal Data Protection Officer, as one is not required for our limited scale of processing (GDPR Article 37). The data controller handles all data protection matters directly. For privacy-related inquiries, data subject requests, or to report a security concern, contact us at:

Xyra AB

Email: support@getxyra.com

Address: Mälaregatan 12, 151 71 Södertälje, Sweden

Organization Number: 559558-6701