Legal

Privacy Policy

๐Ÿ“… Effective: June 1, 2026 ๐Ÿ“ Last updated: June 1, 2026 ๐ŸŒ Applies to: xylomark.com

โœ… Plain English summary โ€” the short version

๐Ÿ‘คWe collect only what we need to run the platform. Nothing more.
๐ŸšซWe never sell your data. Not to advertisers, not to data brokers, not to anyone.
๐Ÿ”’Your artifacts belong to you. Always. Xylomark has no claim over your work.
๐Ÿ“คYou can export or delete your data at any time, for any reason.
๐ŸชWe use only essential cookies. No advertising trackers. No third-party ad networks.
โœ‰๏ธWe will email you only things you've opted into or that are essential to your account.

Xylomark Ltd. ("Xylomark", "we", "us", "our") operates the platform at xylomark.com. This Privacy Policy explains what data we collect, how we use it, and what rights you have over it. We've tried to write this in plain language. The legally-required text is still here โ€” but we've led with the human version.

01 โ€”

What we collect

Information you give us

  • Account data: Name, email address, username, and password (hashed โ€” we never store plaintext passwords).
  • Profile data: Professional headline, industry, location, education background, and any optional fields you fill in.
  • Artifact content: The files, text, images, links, and MER (Method, Evidence, Result) content you post to your Pipeline.
  • Messages: The content of conversations you have with other members and employers on the platform.
  • Challenge submissions: Work you submit to employer challenges, including all supporting files.

Information we collect automatically

  • Usage data: Which pages you visit, which artifacts you view, how long you spend on them (used to calculate qualified view counts โ€” 10+ seconds only).
  • Device data: Browser type, operating system, screen size, and IP address for security and fraud prevention.
  • Interaction data: Forks, saves, connections made, and challenges entered.

Information from third parties

  • If you sign in with Google, GitHub, or Apple, we receive your name and email from that provider. We do not receive or store your password from these services.

02 โ€”

How we use it

  • To operate the platform: Running your profile, your Pipeline, the discovery feed, the challenge engine, and the messaging system.
  • To calculate your Proof Score: Your score is derived from your own activity โ€” artifact quality, verifications received, fork rates, and qualified views. It is not sold or shared.
  • To personalise your feed: Showing you artifacts and challenges relevant to your industry and connections.
  • To send you notifications: Only about activity on your account, in the frequency you've set in Settings.
  • To enforce our policies: Investigating reports of abuse, ghosting, or policy violations.
  • To improve the platform: Anonymised, aggregated usage data only. We will never use your individual data for this without consent.
  • For legal compliance: Retaining data as required by applicable law.

03 โ€”

What we never do

These are unconditional commitments. They do not change based on jurisdiction, business model, or future company ownership decisions.

  • We never sell your data โ€” to advertisers, data brokers, recruitment firms, background check companies, or anyone else.
  • We never show you advertising โ€” Xylomark has no ad network. We do not take money from companies to promote them to you.
  • We never use your artifacts to train AI models โ€” Your work is your work. It is never used to train machine learning models without your explicit, opt-in consent.
  • We never share your messages with employers โ€” Conversations between you and employers are private. We do not provide transcripts to any third party.
  • We never share your unanonymised data with employers viewing your profile โ€” Employers see what you choose to make public. Nothing more.

04 โ€”

Who can see your work

Visibility of your profile and artifacts is entirely in your control via Settings โ†’ Privacy. The default for new accounts is Public.

  • Public artifacts: Visible to anyone, including non-members, search engines, and employers. Indexed by Xylomark's search.
  • Connections-only artifacts: Visible only to your confirmed connections on the platform.
  • Private artifacts: Visible only to you. Can still be shared via a direct link you control.
  • Challenge submissions: Visible to the employer who posted the challenge during the review period. Blind review means your name and profile are hidden until you consent to reveal them.
  • Messages: Visible only to the participants in the conversation and Xylomark's trust & safety team in the event of a policy violation report.

05 โ€”

Data storage & security

Your data is stored on servers in the European Union (primary) and the United States (backup). We use industry-standard encryption in transit (TLS 1.3) and at rest (AES-256). Passwords are hashed using bcrypt with a minimum cost factor of 12.

We conduct annual security audits and operate a responsible disclosure programme. To report a security vulnerability, email security@xylomark.com.

In the event of a data breach that materially affects your personal data, we will notify you within 72 hours of becoming aware of it, as required by GDPR Article 33.

06 โ€”

Your rights

Depending on your location, you may have some or all of the following rights. We honour all of them regardless of where you are.

  • Right to access: Request a copy of all data we hold about you. Use Settings โ†’ Plan & Billing โ†’ Request data export.
  • Right to correction: Update or correct any inaccurate information via your Settings page.
  • Right to deletion: Delete your account and all associated data via Settings โ†’ Danger Zone. We'll process this within 30 days.
  • Right to portability: Export your data in machine-readable format (JSON/CSV) at any time.
  • Right to restrict processing: Contact us to limit how we use your data while keeping your account active.
  • Right to object: Opt out of any non-essential data processing at any time via Settings.
  • Right to withdraw consent: Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email privacy@xylomark.com. We will respond within 30 days.

07 โ€”

Cookies

We use only the following cookies:

  • Session cookies: Required to keep you logged in. Expire when you close your browser unless you choose "Remember me".
  • CSRF protection: Required to prevent cross-site request forgery attacks. Essential for security.
  • Preference cookies: Storing your theme, feed layout, and notification preferences.

We do not use advertising cookies, tracking pixels, or any third-party analytics other than our own first-party analytics. We do not use Google Analytics, Meta Pixel, or similar tracking tools.

08 โ€”

Children

Xylomark is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If we become aware that we hold data about a child under 16, we will delete it promptly. If you believe we hold data about a child, please contact privacy@xylomark.com.

09 โ€”

Changes to this policy

If we make material changes to this policy โ€” particularly changes that reduce your privacy protections โ€” we will notify you by email at least 30 days before the changes take effect. You will have the option to delete your account during this period if you disagree with the changes.

Minor changes (fixing typos, adding clarity, updating contact information) will be noted with a new "last updated" date but will not trigger an email notification.

10 โ€”

Contact us

โœ‰๏ธ

Privacy questions: privacy@xylomark.com

Security issues: security@xylomark.com

Legal enquiries: legal@xylomark.com

Xylomark Ltd. ยท Registered in England & Wales ยท We aim to respond to all privacy requests within 30 days.