Privacy Policy for GXB apps and websites
Last updated October 9, 2026
This policy tells you what personal information GXB collects when you use the GXB services listed below, why we collect it, who receives it, and what you can ask us to do with it.
Which services this covers
This policy covers these GXB services:
- GXB website and GXB Sites: gxb.vc, gxbsites.com, and the website scanner at sites.gxb.vc.
- GXB Auth: auth.gxb.vc, the sign-in page for GXB apps.
- GXB Chat: chat.gxb.vc, and the chat window that appears inside other apps.
- GXB Mailer: mailer.gxb.vc, a tool that sends email for our customers.
- GXB Book: book.gxb.vc, a tool to book calls.
- GXB Scribe: scribe.gxb.vc, a tool that records and transcribes audio.
- GXB Mailboxes: mailboxes.gxb.vc, our shared inbox for email, text messages and voicemail.
- GXB Gov: gov.gxb.vc, a search tool for public records of government bodies.
- GXB News: news.gxb.vc, a search tool for news articles.
- GXB Pods: pods.gxb.vc, a search tool for podcasts.
This policy does not cover these services. They have their own policies:
- GXB Tickets has its own policy at tickets.gxb.vc/privacy.
- GXB Todo has its own policy at todo.gxb.vc/privacy.
- Fileinbox has its own policy on its own website.
- Apps and websites that GXB builds for a customer are covered by the policy of that customer.
Who we are
GXB, LLC ("GXB", "we", "us") is a Delaware limited liability company based in Dallas, Texas. We build and run the services above.
Email: christian@gxb.vc
What we collect in every service
When you sign in
- Most services use GXB Auth to sign you in. The service receives your email address, your name and an account ID. GXB Auth does not use passwords. It sends you a one-time code.
- Each service keeps a record of your sign-ins. The record has the time, your IP address and your browser type.
Technical data
- Our servers write ordinary logs. We use them to find and fix errors.
- GXB Auth, GXB Chat, GXB Mailer, GXB Scribe and GXB Mailboxes send a record of each page you open to analytics.gxb.vc. The record has your IP address, your browser type, the page you opened, the page you came from, campaign tags in the web address, the time, how long the page took, and your account ID if you are signed in.
- analytics.gxb.vc is our own system. It runs on our own servers. We keep these records for 35 days. We keep error records for 90 days. After that, we keep only totals and grouped error summaries.
- GXB Book, GXB Gov, GXB News, GXB Pods and the GXB Sites platform do not send these records. The GXB website and gxbsites.com use a different method. That method is explained in the section on GXB website and GXB Sites.
Cookies
- Each service that has a sign-in sets a cookie that keeps you signed in. It also sets a small session cookie that protects forms and remembers the page to return to. The cookies are sent only over secure connections.
- We do not use advertising cookies or tracking cookies.
- gxb.vc and gxbsites.com set no cookies of their own for visitors. The Calendly form on gxb.vc/book can set its own cookies.
- Some services save your light or dark display choice in your browser. This choice stays on your device.
Libraries and fonts
- Our pages load some code libraries and fonts from other hosts: jsDelivr (cdn.jsdelivr.net), JSPM (ga.jspm.io) and, on some pages, unpkg (unpkg.com) and Google Fonts. These hosts receive your IP address when they send the file. The service sections below name the extra hosts that each service uses.
Why we use it
- To sign you in and keep your account secure.
- To show you only the information you have access to.
- To run the features of each service, as the service sections below explain.
- To send you the emails and texts that a feature needs, such as sign-in codes and booking reminders.
- To find and fix errors, and to see which pages people use.
- To meet our legal duties.
Who we share it with
We do not sell your personal information. We do not share it for advertising. We do not use ad pixels or session replay. We do not use outside analytics companies.
GXB does not use your information to train AI models.
We use these service providers. They process data only to provide their service to us.
- DigitalOcean hosts most of our services. Hetzner hosts GXB Gov, GXB News and GXB Pods on servers in Finland. A copy of each service's database is sent to DigitalOcean storage all the time, as a backup.
- Mailgun sends and, for GXB Mailboxes, receives email for our services. GXB News and GXB Gov send no email.
- Other providers are named in the service sections below: Twilio, Cloudflare, Backblaze, Anthropic, OpenAI, Fireworks, TypeSafe, AssemblyAI, Microsoft, Google, Slack, Apple and a few more.
Other people in a service can see what you add to a shared space. The service sections below say who.
We can also share information when the law requires it, or to protect the rights and safety of GXB and the people who use our services. If GXB merges with or is sold to another company, the information can move to that company, and this policy continues to apply to it.
GXB website and GXB Sites
GXB Sites is the platform that publishes gxb.vc, gxbsites.com and websites for our customers. This section covers gxb.vc, gxbsites.com and the scanner at sites.gxb.vc. A customer website on GXB Sites is run by its owner. GXB hosts it for the owner. The owner decides what the site collects, and the owner's policy applies to it.
What we collect
- Page views. Each page on gxb.vc and gxbsites.com loads a small script from analytics.gxb.vc. The script sends the page path and title, the site you came from, your screen and window size, your language, your time zone, campaign tags in the web address, and a random visitor ID. The visitor ID and a session ID stay in your browser's local storage, not in a cookie. They let us see that a visit is a return visit. You can clear them in your browser. Our server also records your IP address and browser type. The system removes text that looks like an email address or a phone number from the page path and the site you came from. We keep these records for 35 days.
- The interest form on gxb.vc. It asks for your name, work email, company, an optional message, and whether you are a client or an investor. GXB Sites stores the form with your IP address and browser type. It sends the form by email to the owners of GXB. Please do not put confidential information in the form.
- The contact form on gxbsites.com. It asks for your name, email, website address and a message. GXB Sites stores it with your IP address and browser type, and sends it by email to a person at GXB.
- The website scanner at sites.gxb.vc. You type a website address. We fetch the public home page, the robots.txt file, the sitemap and the DNS records of that site. We send the page text and the check results to an AI service to write a short review, and we save the report. The report is public. Search engines can index it. If you ask us to rebuild a site, you type an email address, a phone number, or both. We store them and send them to a GXB owner by email.
Who else receives it
- Google receives your IP address when your browser loads fonts from Google Fonts on gxb.vc.
- jsDelivr receives your IP address when your browser loads code on gxb.vc.
- Pages on gxbsites.com load their files from our own address, cdn.gxbsites.com, which Cloudflare runs for us.
- Calendly shows the booking form on gxb.vc/book. Calendly receives what you type and your IP address. Calendly's own policy applies to that form.
- Cloudflare also checks form posts with its Turnstile tool on customer sites that turn it on.
- Mailgun sends the form emails.
- Fireworks is the AI provider for the scanner review. It receives the text of the home page that you scanned and the check results.
- The scanner also sends website addresses to Ahrefs, Serper, ip-api.com, RDAP servers and archive.org to collect public facts about a site.
- A customer can ask GXB Sites to send each form on its own site to a web address that the customer chooses. We do not use this for gxb.vc or gxbsites.com.
How long we keep it
- Page-view records: 35 days.
- Form entries and scanner contacts: until you ask us to delete them.
GXB Auth
GXB Auth is the sign-in page for GXB apps. Anyone can create an account. You enter your email address, and we send you a code.
What we collect
- Your email address and name.
- For each sign-in: the time, your IP address and your browser type.
- Sign-in codes. They expire quickly, and a job deletes old codes every hour.
- A session record while you stay signed in: your IP address, your browser type and an end date. A session lasts 30 days, and we delete the record when it ends.
- A security log of account events, such as sign-ins and changes to your phone, email or two-step methods. Each entry has the time, your IP address and your browser type. We do not delete these entries on a schedule.
- A list of the apps you signed in to, with the time, your IP address and your browser type.
- Two-step sign-in, if you turn it on. People with a gxb.vc address must turn it on. You can use an authenticator app, a security key or a passkey as the second step. We store your authenticator secret in encrypted form. For a security key or passkey, we store its public key, a name you give it, the time you last used it and technical details. We do not store the private key. We never receive or store your fingerprint or face scan; your device checks that and tells us only that the check passed.
- A phone number, if you add one. We store the number, whether you agreed to texts, whether your carrier blocks the number, and a record that a text was sent. We use the number only for the sign-in and phone-setup texts that you ask for. See auth.gxb.vc/sms/privacy and auth.gxb.vc/sms/terms.
Who else receives it
- Mailgun sends the sign-in code and account emails.
- Twilio receives your phone number and the code, only if you add a phone number.
- The apps you sign in to receive your email address, your name and your account ID. When you sign out, they receive a sign-out message with your account ID and email address.
- An app that you connect to your account (for example an AI assistant such as Claude) keeps a refresh key. The app uses it to keep access without asking you to sign in again, until the key expires. Signing out of GXB Auth does not yet cancel these keys. If you want an app disconnected, email us and we will cancel its keys.
- GXB staff receive a push alert on a phone each time someone signs in to GXB Auth, and for two-step events. The alert has the email address of the person.
- avatars.gxb.vc, our own service, receives your email address in the web address to show your profile picture.
- DuckDuckGo receives your IP address when your dashboard loads small app icons from icons.duckduckgo.com.
How long we keep it
- Your account and security log: until you ask us to delete them. We may keep some security records after that for security reasons.
GXB Chat
GXB Chat is an AI assistant that works inside GXB and customer apps. Only people on a list that GXB keeps can sign in. The list has GXB staff and the staff of a few customer companies. A visitor to a site that shows the chat window must sign in before the visitor can chat.
What we collect
- Your messages, the assistant's replies, and the tools the assistant used.
- If you use the chat window inside another app, the window can send the page you are on with your message. This has the web address, the page title, text you selected, and up to about 15,000 characters of the page text.
- When the assistant runs a query on the data of an app you have access to, we save the result with your chat.
- Documents that the assistant writes for you. A document can be private, shared with the project, or public. A public document can be opened by anyone with its link. The assistant can change this setting.
- Tickets that you file or comment on in the chat window. See the GXB Tickets policy.
- Prompts that you schedule to run later, and their results.
- Voice. If you use the microphone, your browser sends the audio straight to OpenAI. We save only the text of what was said.
- Outlook. If you connect your Microsoft account, the assistant can read your mail, calendar and files in Microsoft 365 to answer you. We store your access keys in encrypted form. The assistant sends an email from your Outlook only after you approve it. The assistant can also send an email from chat@gxb.vc to an address that you give it.
- Slack. If a workspace installs GXBot, GXBot reads the messages and files in each Slack thread where someone mentions it. It follows that thread for 30 days. We store the workspace's access key in encrypted form.
- Phone. If you use the iPhone app, we store your device token for push messages.
AI providers
The assistant sends your messages, the chat history, the page text and the results of queries and tools to an AI provider. The provider writes the answer. We use Anthropic for most chats. For some projects, and when Anthropic is not available, we use Fireworks. Voice goes to OpenAI. OpenAI can keep voice content for up to 30 days to check for abuse. GXB does not train AI models on your chats.
Who else receives it
- Microsoft (if you connect Outlook), Slack (if a workspace uses GXBot), Apple (push messages) and Mailgun (email).
- The app that shows the chat window receives the queries and tool requests that the assistant runs in that app for you. They come with your email address and account ID.
- Our other tools (Todo, Mailer, News and Pods) receive your requests when you ask the assistant to use them. They act with your account.
- Code hosts. The chat window loads Chart.js from jsDelivr and map code from unpkg.
How long we keep it
- Tool task results: 1 hour. Slack event IDs: 14 days. A voice session key: 10 minutes.
- Chats, messages, tickets and files: until you ask us to delete them.
GXB Mailer
GXB Mailer sends email for our customers. A customer connects its own mailboxes, adds a list of people to write to, and writes the messages. Two groups of people are in Mailer: the customers who use it, and the people who receive email from a customer.
Customers who use Mailer
- Anyone with a GXB account can create a workspace. We store your email address, your name, your IP address and your browser type at each sign-in, your API keys in hashed form, and the postal address you set for your emails.
- When you connect a mailbox, we store its address and display name. We store the access keys, and any SMTP or IMAP passwords you give us, in encrypted form. Mailer reads the inbox and the junk folder of the mailbox about every 5 minutes. It keeps a copy of each message it reads (sender, subject and text). It uses these copies to find replies, bounces and requests to stop.
- We send you emails about replies, sending problems and capacity. A reply email has an excerpt of the reply.
People who receive email from a customer
- For these people, we act for the customer. The customer decides who to write to and what to write. The customer adds your name, email address, company, job title, profile link and other notes to Mailer, or an app of the customer sends them in. Mailer stores them, with the messages sent to you, the replies you send, and a list of addresses that must not receive email.
- Each email we send has the postal address of the sender and a line that tells you to reply if you do not want more email. If you reply with words such as "unsubscribe" or "stop", Mailer adds your address to the list and stops all email to you from that customer. Mailer does not add open tracking or click tracking of its own. A customer can add its own tracking to its message text.
- MillionVerifier receives your email address to check that it works. We keep the answer for 30 days.
- If you want us to delete your information, or to stop emails, write to us at the email address below. We tell the customer and delete it, unless the law requires us to keep it.
Who else receives it
- Microsoft and Google act as the mailbox providers of the mailboxes that customers connect.
- Mailgun sends the emails to customers. Cold email goes out through the customer's own mailbox, not through Mailgun.
- InboxKit gives us warm-up statistics for mailboxes. They are about mailboxes, not about recipients.
How long we keep it
- Mailer does not delete accounts, contacts or messages on a schedule. The customer can delete them. We keep the list of addresses that must not receive email so that we do not write to them again.
GXB Book
GXB Book lets a host share a booking page. A guest picks a time and does not need an account. A host signs in with GXB Auth.
What we collect
- From a guest: your name, your email address, your time zone, notes, the meeting link, and the reason, if you cancel. The host can also put your name and email address in a link in advance. Co-host email addresses, if the host adds any.
- From a host: your email address, your name, your IP address and your browser type at each sign-in, and your calendar connection.
- Calendar. If you connect Google Calendar or Microsoft 365, we read your free and busy times and your calendar list. We also create, change and cancel the events for the calls that are booked with you. We invite the guest and co-hosts to the event. We store your access keys in encrypted form. We use calendar data only to show your free times and to manage your booked calls. We do not sell it and we do not use it for advertising.
- If the host uses Microsoft 365, Book can ask Microsoft for the free and busy times of a co-host, or of a guest who gave an email address.
Emails
- Book emails the guest a confirmation, a reminder 24 hours and 1 hour before the call, and any change or cancellation. Each email has a private link for the guest to change or cancel the booking. Anyone with that link can change or cancel the booking. Book emails the host when a call is booked, changed or cancelled.
- A host can send a calendar invite to any email address.
Who else receives it
- Google and Microsoft receive the event details, including the guest's name and email address, because the event is on the host's calendar. Google or Microsoft can also email the guest a calendar invitation.
- Mailgun sends the emails.
- avatars.gxb.vc, our own service, receives the host's email address in the web address to show the host's picture on the booking page.
- Google Fonts receives your IP address when the booking page loads fonts.
- GXB Chat can book calls for a host when the host asks it to.
How long we keep it
- Book does not delete bookings on a schedule. A host's link can have an end date. Ask us and we delete your information.
GXB Scribe
GXB Scribe records audio and turns it into text. Only people with a gxb.vc email address can sign in. If you are not GXB staff, Scribe holds information about you only when your voice is in a recording.
What we collect
- Staff accounts: email address, name, IP address and browser type at each sign-in, and an API key in encrypted form.
- Recordings. Staff record meetings, calls and voice notes with the Mac app, the iPhone app, a command-line tool and a voice device. A recording can include the voices of other people. The Mac app can record the audio of the computer as well as the microphone. On a Mac, Scribe also saves the names of the windows and the web addresses (without the part after the "?") that were on the screen. The iPhone app can save the place where the recording was made.
- For each recording, Scribe stores the audio file, the text of what was said, the title, the date, the length, and any summary that an AI service wrote.
- Who can hear a recording: the staff member who made it, and GXB administrators. A staff member can set Scribe to send a transcript to a web address that the staff member chooses.
Who else receives it
- AssemblyAI receives the audio and returns the text.
- Anthropic receives the text of a recording. It receives the first part to write a title. It receives all of it to write a summary or another AI output that staff ask for.
- avatars.gxb.vc, our own service, receives the staff member's email address in the web address to show a profile picture.
- DigitalOcean stores the audio files.
- Mailgun sends the account emails.
- OpenStreetMap receives your IP address and the map position when staff open a recording that has a place.
How long we keep it
- Scribe does not delete recordings or text on a schedule. Ask us and we delete a recording of you.
GXB Mailboxes
GXB Mailboxes is the shared inbox that GXB staff use for email, text messages (SMS and MMS), iMessage and voicemail. If you write to, text or call a GXB address or number that Mailboxes handles, Mailboxes stores what you send.
What we collect
- Staff accounts: email address, name, IP address and browser type at each sign-in. New accounts are not open to the public. A staff member can share a mailbox with another person. That person gets an account.
- Email: sender and recipient addresses, the subject, the text and the attachments.
- Text messages and voicemail: the phone number, the text and pictures, the voicemail recording, and the city, state, country and ZIP code of the caller that Twilio provides.
- iMessage: the other person's handle and the messages.
- Calendar invites that arrive in a mailbox: the organizer, the attendees, the place and the description. By default, Mailboxes accepts an invite and sends a reply to the organizer.
- Contacts: names, handles and notes that staff type.
Who else receives it
- Mailgun receives and sends email. Twilio receives and sends text messages and calls. A voice call can be forwarded to a phone number that staff choose.
- A mailbox owner can turn on a Slack notice. The notice has the sender and the first part of the message.
- DigitalOcean stores a backup of the database. The attachments stay on our server.
How long we keep it
- Mailboxes does not delete messages on a schedule. Ask us and we delete messages about you.
GXB Gov
GXB Gov is a search tool for public records of government bodies in the United States. Only people whom GXB approves can sign in. GXB Gov does not send email or text messages.
What we collect about people in public records
- Public meeting agendas, minutes, documents, captions and transcripts, and sometimes the audio or video of a meeting. These can contain the names of officials, staff and members of the public who spoke or were named, and what they said. We do not have a table of contacts, donors or officials.
- Facts about vendors and contractors of a government body.
- We get this from the websites of government bodies, from video captions and from meeting files that others give us. Our web crawler usually identifies itself as GovCivicBot, with our contact email address.
What we collect about users
- Email address, name, IP address and browser type at each sign-in.
- The Toboggan sales assistant, if a person has access to it: the company name, website and description that the person types, the customers the person names, and accounts the person follows, reminders and notes.
Who else receives it
- Fireworks receives text of public documents to find signals in them, and the text a Toboggan user types to write a score, a brief or a draft message.
- Firecrawl helps us find the web pages of government bodies. It receives website addresses, not personal information about users.
- Backblaze stores the files.
- Customers can ask to receive new signals at a web address. A signal has a title, a short summary or quote, the government body and a link to the source.
- When a person gets access to Toboggan, GXB Chat receives the person's email address and account ID.
- Map code and tiles. Pages with a map load code from unpkg and map tiles from OpenStreetMap. They receive your IP address.
How long we keep it
- Gov does not delete records on a schedule. If you appear in a public record that we hold and you want it corrected or removed from our copy, email us.
GXB News
GXB News finds news articles that match a topic, and gives our customers short summaries with links. Anyone can open the page that explains our crawler (news.gxb.vc/bot). Only people whom GXB approves can use the search.
What we collect about people in the news
- Article text from Common Crawl, GDELT and news websites. Our crawler is named GXBNewsBot. It follows robots.txt and visits a site at most once every five seconds.
- The names of people, companies and places that appear in the articles, and short quotes (up to 25 words) that we show to customers.
What we collect about users
- Email address, name, IP address and browser type at each sign-in, the queries that a person runs, and the topic descriptions that a person saves.
Who else receives it
- Fireworks receives an article's title and the first part of its text, and the topic description, to write a summary and to judge if the article fits.
- TypeSafe receives an article's title, source, date and a short excerpt, to judge if it fits.
- Customers can ask to receive new signals at a web address. A signal has a title, a summary, a short quote, and the names of the people, companies and places that appear.
- DigitalOcean stores a backup of the database. Articles older than two years move to DigitalOcean storage.
- jsDelivr receives your IP address when a page loads.
How long we keep it
- News does not delete articles or accounts on a schedule. If you want your name removed from our copy of the news, email us.
GXB Pods
GXB Pods finds podcast episodes that match a topic, and gives our customers short summaries with links and quotes. Only people whom GXB approves can sign in.
What we collect about people in podcasts
- Show and episode details from public podcast lists and feeds, including the names of the owners, hosts and guests.
- The text of episodes. We take it from the publisher or we make it ourselves. We download the public audio to a GXB computer, turn it into text, and do not keep the audio.
- Names and short biographies of people, and quotes of what people said. Customers see summaries and quotes of up to 25 words.
What we collect about users
- Email address, name, IP address and browser type at each sign-in, the queries that a person runs, the topic descriptions that a person saves, and the list of email addresses for a scheduled digest.
- A digest email goes to up to 20 addresses that a GXB administrator enters. These people do not need an account. The email has the signals, episode titles and quotes. It has no unsubscribe link yet. To stop it, email us.
Who else receives it
- Fireworks receives the topic description, the opening text of episodes, and passages that mention a company.
- TypeSafe receives the topic description (in some cases), and show, episode, person and passage text, to judge fit.
- Customers can ask to receive new signals at a web address. A signal has people's names, a summary and a quote.
- Mailgun sends the digest emails.
- jsDelivr receives your IP address when a page loads. Google Fonts receives it on the newer pages.
How long we keep it
- Pods does not delete episode text or accounts on a schedule. If you want your name or words removed from our copy, email us.
How long we keep it in general
- We keep your account and what you create while you use the service. Each service section above lists exceptions. Ask us and we delete your information, unless the law requires us to keep it.
- Analytics page-view records: 35 days. Error records: 90 days.
- Backups: copies of deleted data can stay in backups for a short time before the backups are replaced.
Security
We use encrypted connections (HTTPS), sign-in through one central account system, access rules that limit each person to their own information, encrypted storage of mailbox, calendar and Slack access keys, and continuous database backups. No system is fully secure. If you find a security problem, email christian@gxb.vc.
Your choices and rights
You can ask us to:
- tell you what personal information we have about you, and send you a copy;
- correct information that is wrong;
- delete your information.
Send your request to christian@gxb.vc. If you have an account, send it from the email address you use in the service. If you are not a user, for example you received an email through GXB Mailer, you are in a recording, or you appear in a public record, tell us your name and where we may have your information, so that we can find it. We reply within 45 days. We may need to confirm who you are before we act. We do not treat you differently because you made a request.
California and Texas residents have these rights under state law. You can also name an agent to make a request for you. If we refuse a request, you can appeal by replying to our answer. We will reply to the appeal within 60 days.
Children
Our services are not for children. We do not knowingly collect information from anyone under 13. If you think a child gave us information, email christian@gxb.vc and we will delete it.
Changes to this policy
If we change this policy, we will change the "Last updated" date at the top. If the change is large, we will also tell signed-in users in the service or by email.
Contact
GXB, LLC
Dallas, TX
christian@gxb.vc