Privacy

Your day is yours.

Xallar holds your money, your notes, your journal, your passwords and your mornings. This page names every single thing that leaves your phone, where it goes, and who else can see it. No summaries, no “including but not limited to”.

Last updated 9 September 2026

The rule underneath all of it

Your phone is the real Xallar. The cloud is a copy, kept so that a lost phone is not a lost life.

The short version

Every alarm, task, note, journal entry, ledger line and routine is written to your phone first, and the app works with the signal off. When you are signed in, a copy of that same data is kept in your account so you can get it back on a new phone.

We do not sell or rent your data. We do not advertise to you. There is no third-party tracker, ad network or analytics company anywhere in the app. Nothing you write in Xallar is read by us or used to train any AI model.

Xallar is made by Xallar Inc. An account is required to use the app, so everything below assumes you have one.

What is kept on your phone

All of it, and it stays readable with no connection:

Deleting something in the app deletes it on the phone. Some lists can be set to delete a ticked item automatically a day later; that is a setting you control per list.

What leaves your phone

Ten things, and this is the complete list.

1. Your account

Your email address and password, so you can sign in. Passwords are handled by our authentication provider and stored hashed — we never see or hold the password itself. We send you a confirmation email when you sign up, and a reset link if you ask for one.

If you choose a username and display name, those are visible to other Xallar users, because a username is how someone adds you as a friend. Nothing else about your account is discoverable.

2. Your backup

This is the big one, so it is worth being exact. When Xallar goes to the background, it copies everything in the list above into a single record in your account, replacing the previous copy. That includes your notes, your journal, your money, your transcripts and your encrypted Vault. It excludes the keys that identify your sign-in session, which stay on the device.

Only your account can read that record. It is enforced in the database itself, on every table, not in the app — so a bug in the app cannot hand your rows to anyone else.

3. Your files

Pandora’s Box is the element that holds files — photos you pick from your library, documents you pick from the file picker. Every file you put in it is copied to Cloudflare, a file storage provider, under your account, so that it follows you to a new phone or a reinstall instead of dying with the old one. Nothing is read from your photo library or your files except the ones you pick, one by one, and the picture you choose as an alarm background is not among them — that one stays on the phone.

The phone never holds a key to that storage. It asks our own server for a link good for one file, one direction, fifteen minutes, and moves the bytes itself. Only your account can be handed a link to your files. Each account gets 2 GB of room. Deleting a file in the app deletes the cloud copy too, once the bin lets it go.

4. Your mornings

When you settle an alarm, two numbers are recorded: when it rang and how many times you snoozed it. That is what your Snooze Grade and the heat map on your profile are made of. The alarm’s name, its label and its mission are not included.

5. Friends and sharing

If you use Connections, we store who is friends with whom, which requests are pending, and who you have blocked. If you report someone, we store your account, their account and the reason you typed.

When you deliberately send a friend a copy of something — a bookmark, a checklist, a routine, a to-do — that item is stored until they accept or dismiss it. A friend never sees your alarms, tasks, notes, journal or money. Only the thing you chose to send.

6. Meredith, and Telegram

Meredith watches your money and speaks up in Telegram. She is off unless you link a Telegram account, and this is the one flow where a third party sees the substance of your data, so read it properly.

When you link, we store your Telegram chat ID and Telegram username, plus a one-time linking code that expires. Each alert is written into a queue on our server and our server hands it to Telegram to deliver — that is what lets her reach you with the app shut.

The alert text contains the money fact it is about. A budget warning names the budget and the amounts. A large-transaction alert names the amount and where you spent it. An unsettled-splits alert names the split and the total owed. A task reminder contains the text of the task. All of that passes through Telegram, and Telegram’s own privacy policy governs what they do with a message once it is in your chat.

So here is the honest line, and we will not write you a softer one: we never send your financial records, only the message you are meant to read. Your transactions, budgets, categories and balances stay on your phone. The server holds no copy of them and could not add them up if it wanted to. But the sentence it does hold was written for a human, so it can carry a figure or a category name inside it, and anyone who can read your Telegram can read that.

You can pause Meredith or unlink Telegram at any time, from inside the app. Unlinking removes the connection between your account and that chat.

7. Talking instead of typing

When you record on the Transcribe page, or tap the microphone in a text field, the recording is uploaded to our own server, which passes it to Groq — the company running the Whisper speech model — and hands the text back to your phone.

The microphone is only live while you are recording, and only after you tap. Xallar’s server does not keep the audio — it holds the file just long enough to pass it on, and keeps no copy. Groq’s terms state that they do not train models on what is sent through their interface and do not retain it by default. The text that comes back is stored on your phone and rides your backup like anything else you typed.

On top of that, Xallar’s account with Groq has Zero Data Retention switched on. That means your recording is not written down at Groq’s end at all — not kept for a retention window, not held for abuse review, not stored to improve anything. It is processed and gone. So all three things are true of a recording you make: it is not stored, it is not trained on, and it is not retained.

Each account gets fifteen minutes of transcription a day, so we count how many seconds of audio you sent, per day. That tally is the only record kept of the fact that you transcribed something. The transcript itself is not stored on our server.

8. Polish, and chatting with Meredith

Two features send text to Anthropic, the company that runs the Claude model, and only at your press.

When you tap Polish on a note or a transcript, that text goes to Anthropic, comes back tidied, and that is the whole trip. When you chat with Meredith, the message you typed and the recent turns of that conversation go to Anthropic so she can answer.

Anthropic does not use what Xallar sends to train any model — its commercial terms exclude API traffic from training. It may hold traffic briefly for abuse monitoring under those terms, then deletes it. Neither feature ever runs on its own: nothing is sent until you press the button that sends it.

9. Crash reports

When the app crashes, a report goes to Sentry saying what broke and where. It is deliberately configured to carry as little of you as possible:

10. App updates

Xallar improves by fetching updates when you close and reopen it. That request goes to Expo, who host the updates, and like any web request it tells them your IP address, your platform and which version you are on. It carries nothing about your account and nothing from inside the app.

11. Writing to us

Contacting support opens your own mail app with a message ready to send from your own account. Nothing is sent by Xallar. The message arrives with your app version, build number and the date of the last update you received, so nobody has to ask. We read what you send us and nothing else.

If you vote on which element gets built next, we store your account and which element you picked.

The Vault

The Vault holds door codes, wifi passwords and locker combinations, and it is built so that we cannot read it even if we wanted to.

The box travels; the key does not. The Vault is encrypted on your phone with a key derived from your master password. The encrypted box is allowed into your backup — that is what gets your codes back on a new phone — and it is meaningless to anyone without the key. The key itself lives in your phone’s Keychain (iPhone) or Keystore (Android), which the backup never touches. Your master password is stored nowhere at all: not saved, not hashed, not hinted.

Which means: if you forget your master password and lose the phone, the Vault is gone. Not gone until support restores it — gone. That is the price of it being genuinely private, and the app says so before you set one up.

On Android, Vault screens are flagged so the operating system blocks screenshots and blanks the app-switcher preview. iPhone gives an ordinary app no equivalent, so the Vault closes itself the moment Xallar stops being the app in front of you — having nothing on screen to capture is the protection there.

Everyone who touches your data

The complete list. Each one is here to do a job the app cannot do alone.

Supabase
Your account, your backup, your friends and Meredith’s queue. Held in the United States.
Groq
Speech to text. Receives a recording only when you record one, and receives nothing else. Zero Data Retention is on, so it is not kept.
Anthropic
Runs the model behind Polish and Meredith’s chat. Receives the text you send those two features and nothing else, and does not use it to train models.
Cloudflare
Holds the files you put in Pandora’s Box, under your account. Receives a file only when you bring one in, and can hand one out only to a link our server issued for your account.
Telegram
Delivers Meredith’s messages, and only if you have linked it. Receives the alert text described above.
Sentry
Crash reports. Receives nothing unless the app crashes.
Expo
Hosts app updates and builds the app. Sees the update request, not the contents of the app.
Apple and Google
Distribute the app and handle notifications and system alarms on their own platforms, under their own policies.

Nobody else. There is no advertising network, no attribution SDK, no analytics service and no data broker in Xallar, and there never has been.

What Xallar never does

What your phone asks permission for

Every one of these is optional, refusable, and revocable in your phone’s own settings. Refusing one costs you that feature and nothing else.

How long things are kept

What you can do about any of it

Your rights, wherever you live

Depending on where you live, you may have a legal right to see what we hold, correct it, delete it, take it elsewhere, object to how it is handled, and complain to your data protection authority.

We give all of it to everyone, wherever you are. Keeping two standards would mean building a worse product for most people, so we do not. We do not charge for a request and we do not need a reason.

Deleting your account

There is a Delete Account page inside the app, and you can also ask us at support@xallar.com. It wipes your account, your backup, your username, your friends, anything shared with you, your Telegram link and Meredith’s queue.

It cannot be undone and there is no copy to restore from. Data on the phone in your hand is separate: uninstalling the app removes it, and the app can also wipe it for you.

Children

Xallar is not built for children and is not directed at them. We do not knowingly collect anything from a child under 13. If you believe a child has an account, write to support@xallar.com and we will delete it.

Where your data is held

Your account and your backup are held on servers in the United States. Our other providers — Cloudflare, Groq, Sentry, Expo, Telegram — operate internationally. If you use Xallar from outside the United States, your data is transferred there and handled under this policy wherever it sits.

How it is protected

No system is perfect, and we will not pretend otherwise. If something is ever exposed, we will say so plainly, here and in What’s New, and tell you what to do about it.

Changes to this page

When a data flow changes, this page changes with it and the date at the top moves. Anything material also gets written up in plain English on What’s New, so a change is something you can read rather than something you have to notice.

Who to write to

Xallar is made by Xallar Inc. For anything on this page — a question, a request, or a correction — write to support@xallar.com. It is read by a person.

The rules for using Xallar — what we owe you, what you agree to, and the honest warning about relying on an alarm — are in the Terms of Service.