Privacy Policy
Last updated: 2026-08-27
Xirophi Pty Ltd, the operator of XIPHION (xiphion.app), is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what personal information we collect, how we use and disclose it, how it is stored, and what rights you have. By using XIPHION you consent to the practices described here.
Operator and Contact
The entity responsible for personal information collected through XIPHION is Xirophi Pty Ltd (Australia). For privacy enquiries, access requests, correction requests, or to make a complaint about how we handle your personal information, contact: privacy@xiphion.app. We will acknowledge complaints within 7 days and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Data We Collect
When you create an account, we collect authentication data through our identity provider, Supabase. This may include your email address, display name, and avatar image if you sign in via Google OAuth. Additionally, XIPHION stores user-generated content including personal frequency combinations, journal entries, field intelligence profiles, attractor configurations, and session preferences. Where you choose to use particular features, we also store the information you provide through them, including: birth details and soul-profile responses; life-audit answers; AI chat conversations; playback events such as frequency, label, source, and time for aggregate listening analytics; and, if you opt in to the Sphere social layer, your public profile, connection requests, and the messages you exchange with other members. Where you use the relevant features, we also collect: workshop registrations (name, email, and date of birth); Department of Frequency Studies enquiries (name, email, phone number, your enquiry, and technical request data); feedback you submit on frequency experiences; heart-sync check-ins you record (such as heart rate and blood pressure readings); zone-terminal journal threads; and, where you provide a birth place for chart accuracy, the geographic coordinates of that place derived through geocoding.
Sensitive Information and Health-Related Inputs
Some optional features let you provide information that may be sensitive under the Privacy Act 1988 (Cth), including the Tests feature (where you may upload health-test files for AI analysis), heart-sync check-ins (heart rate and blood pressure readings you choose to record), and questionnaires such as the Life Audit and Soul Profile. We collect this information only when you actively choose to provide it, and we use it solely to generate the output you have requested. By submitting such information you consent to us collecting and processing it for that purpose. You can decline to use these features, and you can request deletion of the information at any time via privacy@xiphion.app. We do not use this information for advertising and we do not sell it.
Local Storage
A significant portion of XIPHION data is stored locally in your browser via localStorage. This data remains on your device and is not transmitted to any server unless you are signed in with an account. Locally stored data includes:
- Theme preferences and display settings
- Frequency studio channel configurations
- Personal combinations and favourites
- Journal entries and session logs
- Revenue stream tracking data
- Application state and preferences
Cloud Synchronisation
When signed in via Supabase, certain data may be synchronised to enable cross-device access. This includes personal combinations, journal entries, field intelligence profiles, and user preferences. All synchronised data is stored securely within Supabase infrastructure using industry-standard encryption and access controls.
Data We Do NOT Collect
XIPHION is designed with privacy as a priority. We do not collect or store the following information:
- Audio recordings, microphone input, or biometric data
- Precise geographic location data (we do not track your device location; the coordinates of a birth place you choose to enter are stored for chart accuracy)
- Device identifiers or fingerprinting data
- Health or medical information, except where you actively choose to provide it through optional features such as Tests, Life Audit, or Soul Profile (see "Sensitive Information and Health-Related Inputs")
How We Share Information
We do not sell, rent, or trade your personal information, and we do not share it with advertising networks. We share personal information only with the service providers (sub-processors) needed to operate XIPHION, and only to the extent required to deliver the feature you are using. Where you opt in to the Sphere, the limited public-profile information you choose to publish (such as your handle, display name, avatar, and the public-safe profile fields you select) is visible to other members, and the messages you send are disclosed to the member you send them to. Free-text personal fields, health inputs, and private journal data are never published to other members.
Data Security
Authentication is handled through Supabase with industry-standard TLS encryption for data in transit. Passwords are never stored in plain text. OAuth tokens are managed securely by the authentication provider. We implement reasonable administrative, technical, and physical safeguards to protect the confidentiality and integrity of your personal data.
Your Rights
You have the following rights regarding your personal data:
- Access all data stored in association with your account
- Export your personal data in a portable format
- Request complete deletion of your account and all associated data
- Opt out of cloud synchronisation by using the application without signing in
- Withdraw consent for data processing at any time by deleting your account
Third-Party Services
XIPHION relies on the following third-party service providers (sub-processors), each used only to deliver the relevant feature and each subject to its own privacy policy:
- Supabase — authentication, database, and cloud storage for account data
- Google OAuth — optional social sign-in
- Anthropic (Claude) — processes AI chat messages, life-audit responses, and uploaded health-test content to generate AI analysis and responses
- OpenAI — processes content only where you supply your own API key to use that provider
- ElevenLabs — converts text to speech where you use voice features
- Resend — delivers transactional email such as feedback and enquiry messages
- Open-Meteo — geocodes the birth place you enter into geographic coordinates for chart accuracy (only the place name is sent)
- Stripe — processes subscription payments where you purchase a paid plan; we do not store your card details
Overseas Disclosure
Some of our service providers, including Supabase, Google, Anthropic, OpenAI, ElevenLabs, and Resend, may store or process personal information on servers located outside Australia, including in the United States and Europe. By using XIPHION you consent to your personal information being transferred to and stored in these jurisdictions. We take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with the Australian Privacy Principles.
Retention and Deletion
We retain personal information only for as long as required to provide the service or as required by law. You may request deletion of your account and associated personal information at any time via privacy@xiphion.app. Some information may be retained in backups or for legal compliance for a reasonable additional period after deletion.