Legal

Crosscheck (XC) Privacy Policy

Crosscheck is privacy-preserving by default: it runs on your machine or in your browser, and your keys and prompt/response content never reach us.

Version
v1.0
Effective
2026-07-16

This Privacy Policy explains what personal data Vardr Partners, LLC, a South Carolina limited liability company ("Vardr", "we", or "us"), collects in connection with Crosscheck (XC) (the "Service") and the website at crosscheckagent.com, how we use and share it, and the choices you have. It supplements the Terms of Service and the End User License Agreement (EULA). Crosscheck (XC) is designed to be privacy-preserving by default: it runs on your machine or in your browser, and the sensitive parts of your workflow never reach us.

1. What We Do Not Collect

We want to be explicit about this first, because it is central to how the Service works:

  • We do not collect your API keys. Under the bring-your-own-keys ("BYOK") model, your third-party provider keys are stored locally on your machine or in your browser (the Chrome extension encrypts them at rest using AES-GCM). Vardr never receives, transmits, stores, or logs your keys.
  • We do not collect the content of your prompts or model responses. Model calls go directly from your machine or browser to the third-party providers using your keys. We do not transmit, store, log, or process that content. Our server-side validation actively rejects any telemetry event that would contain prompt-shaped data.

2. What We Collect

We collect the following categories of data:

  • Account data. Your account email, obtained through our OAuth sign-in provider, and your organization details.
  • Billing data. Subscription status, number of seats, and payment records, handled by Stripe. Vardr does not store full payment card numbers.
  • Activation records. For each seat, an anonymized machine or browser fingerprint hash, last-seen timestamp, and the IP address and user agent captured at activation, used to enforce one active machine per seat.
  • Signed-EULA record. When you accept the EULA, we record your typed legal name, IP address, user agent, a signing identifier (JTI), and a SHA-256 hash of the EULA text you accepted.
  • Content-free usage telemetry. Usage metadata only: the tool or pattern invoked, the provider and model name, token counts, estimated cost, timestamps, coarse success/error status, and the anonymized fingerprint hash used for seat activation. This telemetry contains no prompt or response content.
  • Website and log data. Standard server logs and cookies/session data as described in Section 8.

3. How We Use It

We use the data we collect to: provide and operate the Service; authenticate you and activate your seat; process subscriptions, billing, and renewals through Stripe; enforce seat limits and the once-per-30-days re-activation rule; render usage dashboards; prevent abuse and fraud; plan capacity and improve the Service; comply with legal obligations; and communicate with you about your account, security, and changes to the Service.

4. Legal Bases

Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract (providing the Service, billing, and account management); legitimate interests (abuse prevention, security, seat enforcement, and product improvement, balanced against your rights); legal obligation (tax and record-keeping); and consent where required (which you may withdraw).

5. Sharing and Processors

We do not sell your personal data. We share limited data with service providers ("processors") who act on our behalf under contractual confidentiality and data-protection obligations:

  • Stripe — payment processing and billing.
  • Our OAuth sign-in provider — authentication.
  • Hosting and infrastructure providers — operating the Service and storing account, activation, and telemetry data.

Your chosen large language model providers (Anthropic, OpenAI, Google, xAI, and others) receive your prompts directly from your machine or browser under your own keys. Those are your own relationships, governed by those providers' terms and privacy policies; Vardr is not a party to them and does not act as their processor. We may also disclose data if required by law or to protect our rights, users, or the public.

6. Data Retention

We retain account, billing, activation, and signed-EULA records for as long as your account is active and as needed to comply with legal, tax, and audit obligations. Consistent with the EULA, we retain raw telemetry events for ninety (90) days and aggregated, anonymized rollups indefinitely. When data is no longer needed, we delete or anonymize it.

7. Security

We use reasonable administrative, technical, and organizational measures to protect the data we hold, including encryption in transit, signed telemetry events, encryption of locally stored keys at rest (AES-GCM in the extension), and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your API keys and prompt content stay on your device, you retain primary control over that most sensitive data.

8. Cookies and Sessions

The crosscheckagent.com website uses cookies and similar technologies that are strictly necessary to authenticate you, maintain your session, and operate the billing portal. We do not use the Service to build advertising profiles. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent sign-in.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can manage much of your data directly (for example, billing through the Stripe portal). To exercise other rights, contact us at privacy@crosscheckagent.com; we will respond as required by applicable law and may need to verify your identity. Note that we cannot provide prompt content or API keys because we never hold them.

10. International Users

Vardr is based in the United States, and we process and store data in the United States and with our processors' facilities. If you access the Service from outside the United States, you understand that your data will be transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction. Where required, we rely on appropriate safeguards for such transfers.

11. Children

The Service is intended for professional and commercial use and is not directed to children under 18 (or under 16 where that is the applicable threshold). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy at crosscheckagent.com and update the effective date above, and where appropriate we will notify you by email or in-product notice. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

13. Contact

Questions or requests regarding this Privacy Policy or your data may be sent to privacy@crosscheckagent.com.

This document is provided for transparency and is not legal advice.