XenoTrack Privacy Policy
Version: xenotrack-privacy-v1-early-access · Effective July 2026
1. Information We Collect
We collect information you provide directly when you use XenoTrack. This includes:
- Account information (name, email address, encrypted password)
- Organization/lab workspace details you configure
- Colony management data entered by you and your authorized team members
2. Account Information
When you create an account, we collect your name, email address, and an encrypted password. Account credentials are managed through Supabase Auth with industry-standard encryption. We do not store passwords in plain text.
3. Lab/Workspace Data
When you create a lab workspace, we store your organization name, lab mode configuration, and team member roles. This data is used solely to provide workspace functionality and access control.
4. Colony/Bin/Frog/Use/Rest Data
Colony data you enter — including bin configurations, frog records, use/rest events, transfer logs, performance notes, rest timers, environmental observations, and any other colony management records — is stored securely and is private to your organization by default. We do not analyze, mine, share, or use your colony records for purposes other than providing the Service to you and your workspace members.
5. Frog Photos and Uploaded Files
Photos and videos you upload are stored in private cloud storage buckets with access restricted to your organization's authenticated members. Uploaded media is not publicly accessible, not used for training purposes, not used for marketing, and not shared with any third party. Files are associated with your organization via row-level security policies.
6. How We Use Information
We use your information solely to:
- Provide, maintain, and improve the XenoTrack service
- Authenticate your identity and manage access to your workspace
- Send notifications you have configured (e.g., rest-complete alerts)
- Respond to support requests
- Ensure security and prevent abuse
We do not sell your data. We do not use your colony data for advertising. We do not build user profiles for marketing purposes. We do not use your data to train machine learning models.
7. How We Store Information
Data is stored in the XenoTrack database hosted on Supabase (PostgreSQL) with row-level security (RLS) policies that enforce organization-level isolation. All data is encrypted in transit (TLS) and at rest. Database backups are maintained by our infrastructure provider. Photos and files are stored in private cloud storage with access control.
8. Who Can Access Information
Your colony data is accessible only to authenticated members of your organization/workspace, according to the role-based permissions you configure (owner, admin, manager, technician, viewer). The XenoTrack administrator may access infrastructure for security, debugging, or support purposes but will not browse your colony data without your explicit request or a legal obligation.
9. Organization/Workspace Privacy
Each lab workspace is isolated. Users in one organization cannot see, query, or export data from another organization. Row-level security policies enforce this isolation at the database level.
10. No Automatic Sharing with Frog Social or External Case Systems
Colony data is private to the user's organization/workspace by default. XenoTrack does not automatically share colony records, frog photos, husbandry notes, or performance data with Frog Social or any external case system. If optional integrations are offered in the future, they will require explicit user action and you will see a clear preview of any data before it leaves your workspace.
11. Service Providers
We use the following third-party service providers to operate XenoTrack:
- Supabase — database hosting, authentication, and file storage
- Vercel — application hosting and deployment
- Email/SMS providers — for delivering notifications you configure (if enabled)
These providers process data only as necessary to provide their services and are bound by their own privacy and security obligations. We do not share your colony data with these providers for their own use.
12. Data Export
You may export your colony data at any time using the CSV export functionality available within the Service. Exported data is generated in your browser and downloaded directly — it does not pass through any third-party analytics or tracking service. You are responsible for the security of exported files once downloaded. XenoTrack is not intended to lock users into the system.
13. Data Deletion / Account Closure
You may request deletion of your account and all associated data at any time by contacting us at rob@xenopus1.com. Upon receiving a deletion request, we will permanently remove your account, colony data, uploaded files, and all associated records within 30 days. Some data may be retained in encrypted backups for a limited period as required by our infrastructure provider's retention policies.
14. Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for stored data
- Row-level security policies for database isolation
- Role-based access controls within each workspace
- Secure password hashing (bcrypt via Supabase Auth)
- Regular security updates
No system is perfectly secure. If you discover a security vulnerability, please report it immediately to rob@xenopus1.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the Service after notification constitutes acceptance of the updated policy. If you do not agree to the new policy, you may export your data and close your account.
16. Contact
For privacy-related questions, data access requests, or deletion requests, contact us at: rob@xenopus1.com
© 2026 XenoTrack · Terms of Service · rob@xenopus1.com