Privacy Policy
Last updated: August 8, 2026
This page explains what information Xylento collects, why, and how you can control it. If anything here is unclear, email team@xylento.com.
What we collect
When you submit an application, we collect the founder and startup information you enter in the form (name, email, country, LinkedIn/GitHub/website links if provided, and everything about your startup), along with any files you attach. If you create an account, we also store your password (hashed, never in plain text), and โ if you enable it โ a two-factor authentication secret (encrypted at rest).
We automatically log basic technical data needed to operate and secure the service: IP address and browser user-agent at submission and login time, and timestamps of account activity.
What we don't collect
We don't run third-party analytics on this site, and we don't sell or rent your data to anyone. We do run Google Ads campaigns, and use Google's advertising tag to measure whether ad clicks lead to applications โ but only if you accept the cookie banner; it's off by default. See "Cookies" below and our Cookie Policy for the full detail.
Payments
Payments are processed by Stripe. Your card number never reaches our servers โ it's entered directly into Stripe's embedded payment form and sent straight to Stripe. We only ever see a payment status and the last 4 digits, via Stripe's systems.
Transactional emails (application confirmations, status updates, notification pings) are sent through Resend. We don't send marketing email, and we don't add you to any mailing list. You can turn off notification emails at any time from your dashboard โ you'll still see updates there, just without the email ping.
Who can see your application
Your application is visible only to the Xylento review team. It is never used to train AI models, shared with other applicants, or shown publicly. It is always read and decided on by a real person โ never an algorithm.
Instant AI idea check
Before applying, the homepage optionally offers a quick, informal AI read on your idea โ five factors and a score, for fun and to help you gauge your pitch. It's a separate tool from the real application above: it's optional, it's never your official review, and it only asks for details about your idea (pitch, problem, solution, industry, stage) โ never your name, email, or any personal information.
The idea text you enter there is sent to OpenAI's API to generate the score and feedback. OpenAI does not use API data to train its models, and we don't store or reuse it for anything beyond showing you that result and (if you choose to continue) pre-filling the matching fields on the real application so you don't have to retype them.
Cookies
We always set two strictly necessary cookies โ a session cookie that keeps you logged in, and a short-lived cookie used during two-factor login. Both are HttpOnly and Secure, and are never used for tracking or advertising. If you accept the cookie banner, we additionally set Google's advertising-measurement cookie to track ad conversions; declining keeps that off. See our Cookie Policy for the full breakdown and how to change your choice.
How long we keep data
We keep application and account data for as long as your account is active, or as needed to comply with legal, tax, or fraud-prevention obligations. If you request deletion (below), we remove what we're not legally required to retain.
Your rights
You can request a copy of the data we hold about you, ask us to correct it, or request deletion of your account and associated data, by emailing team@xylento.com from the email address on your account. We'll respond within a reasonable time, and no later than 30 days.
Note: your original application data is locked once submitted and paid for, so we can maintain an honest record of what was reviewed โ but this doesn't affect your right to request its deletion.
Changes to this policy
If we make material changes to how we handle your data, we'll update the date at the top of this page and, where appropriate, notify account holders directly.