Ximos Legal
🛡️ Guardian Compliance & Data Security

Privacy Policy

Complete transparency regarding user consent, encrypted peer-to-peer WebRTC streams, live location relay with zero server-side retention, 30-day vault retention, and Android system permissions — including where the app can be hidden, and how that's disclosed to the device it's installed on.

Last Updated: September 28, 2026
Status: Reviewed for Parental Supervision Use
Architecture: Encrypted Peer-to-Peer (WebRTC) + Relayed Location

Parental Consent & Purpose Limitation Statement

Ximos (formerly and also known as XimDroid) is engineered strictly for parental supervision, minor child protection, and authorized family safety management. The application functions exclusively with the explicit, informed consent of the legal guardian and device owner. Unauthorized surreptitious surveillance is strictly forbidden and actively prevented by hardware indicator protocols.

Encrypted Peer-to-Peer Streaming

Live screen shares, dual-camera feeds, and Surrounding Audio streams use peer-to-peer WebRTC (DTLS-SRTP encrypted). The signaling server exchanges connection info only — it never receives or stores the stream itself.

Location — Zero Server Retention

Live location is triggered only when the parent taps refresh — no continuous background collection. Payloads are relayed in-flight through an encrypted Cloudflare WebSocket and are never written to disk on our servers. See the Location privacy details below.

30-Day Auto Purge

Cloud Media Vault snapshots, audio recordings, and video clips are stored in your personal database for a maximum of 30 days, plus a 7-day trash window, before irreversible automated deletion.

Notification Cannot Be Silenced

A continuous, non-dismissible status bar notification is always displayed while any monitoring service is active — even on builds where the parent has chosen to hide XimosKid's app icon. Full disclosure of that icon-hide option is in our Trust Center.

No Cookies or Trackers

We do not use browser cookies, tracking pixels, advertisement IDs, or behavioral analytics beacons to profile your children or monitor web activity.

Advisory, Not Restrictive

Ximos does not remotely block apps or filter web/video content — by design. We give parents visibility and a way to communicate directly with the child's device, not a remote lockdown switch. Optional app blocking and content filtering are being explored for a future update; see our public roadmap.

SEC 01

Information We Process & Collect

Ximos operates under a data minimization and zero-surveillance-profiling architecture. We only process data that you, as the authenticated parent or guardian, explicitly request or schedule through the parent dashboard:

  • Live Hardware Streams (Screen, Camera, Surrounding Audio): Real-time screen projection, front camera, rear camera, and one-way ambient audio streams are transmitted via encrypted WebRTC hardware channels. These streams are handled transiently in RAM and are never recorded or saved unless you explicitly tap "Record" or schedule an automated capture in your Cloud Vault.
  • Vault Media (Photos, Audios, Videos): Captured photos, ambient audio recordings, and video clips requested by the parent are encrypted and transmitted directly to your personal cloud storage database.
  • Location Data (Parent-Triggered, In-Flight Only): When you trigger a location fetch from the parent app or dashboard, the child device returns one payload containing latitude, longitude, accuracy, provider, and timestamp. This payload is relayed through an encrypted WebSocket directly to your connected parent session and is not retained on our servers beyond the in-flight broadcast. There is no background location collection, no location history table, and no location trail per device.
  • Device Telemetry & Hardware Metadata: To ensure accurate remote touch mapping, battery monitoring, and anti-fraud verification (preventing referral abuse), the app collects minimal non-identifying telemetry including: device manufacturer, model, screen resolution, operating system version, battery level, charging state, and network connectivity status.
SEC 02

Consent, Guardian Authority & Transparency

Ximos is designed exclusively for legal guardians monitoring minor children under their legal custody or for personal emergency protection on user-owned devices.

Persistent Notification: Ximos abides by Android platform security guidelines by maintaining a visible, non-dismissable notification in the Android notification drawer whenever the service is actively communicating with the parent portal.

Icon visibility, disclosed directly: XimosKid shows its own name and icon in the device's app list by default. A parent can optionally hide the launcher icon; when hidden, the persistent notification above remains in place regardless, and a hidden dial code can restore the icon from the child's device at any time. We document this trade-off in full, including what it does and does not guarantee, in our Trust Center — a notification is only a meaningful signal if it's read, and we'd rather say that plainly than oversell it here.

Any attempt to deploy Ximos for unauthorized surveillance, stalking of spouses or adults, employee tracking without formal consent, or corporate espionage constitutes a direct violation of our Terms of Use and applicable state, federal, and international wiretap legislation.

SEC 03

Data Storage, Encryption & Retention

We implement stringent data lifecycle controls to safeguard your family's personal moments:

  • Transient Data Disposal: Real-time screen broadcasts, camera previews, audio bytes, and location payloads are streamed directly peer-to-peer or relayed in-flight, and are immediately discarded from memory once the active session or fetch terminates.
  • Cloud Vault 30 + 7 Policy: Photos, video clips, and audio files saved to your cloud vault are retained for a maximum period of 30 calendar days, then moved to a 7-day trash window, then permanently purged by server cron jobs. Users are responsible for exporting or downloading important evidence or memories prior to expiration.
  • End-to-End Encryption: Sensitive media, telemetry, and location payloads are encrypted in transit using TLS 1.3 cryptographic protocols and authenticated with unique pairing tokens.
  • Location — Zero Server Retention: Location payloads are never written to a database, never logged, and are not retrievable after the fetch completes.
Automated Lifecycle & Retention Matrix Cron Purge Active
Live Screen, Camera & Audio P2P Streams
0s (Transient RAM)
Live Location Payload (lat/lng/accuracy/provider)
0s (Relayed In-Flight Only)
Encrypted Vault Media (Photos & Video & Audio)
30 Days + 7-Day Trash
Account Fields (email, device ID, device brand)
Until Account Deletion
SEC 04

Location Privacy, in Plain Terms

Location is a sensitive data type, so it gets its own section rather than being folded into the general telemetry description.

  • Triggered, never continuous: the parent taps refresh in the Ximos app or dashboard. No polling, no scheduled background fetches, no location trail.
  • Two-stage fetch on the child device: the last-known cached location is uploaded immediately, and a fresh high-accuracy GPS fix is requested in parallel. Both are sent; the server uses the freshest timestamp.
  • Automatic fallback chain when GPS is unavailable: Fused GPS (3–20 m) → Network Provider via Wi-Fi BSSID + cell tower (20–100 m) → last-known from any enabled provider → IP-based geolocation (5–50 km, city-level only).
  • Honest tagging: each uploaded location is tagged with its provider and an isFallback boolean so the parent app can visually indicate how reliable the data is — accurate marker vs. approximate marker — rather than pretending every reading is equally precise.
  • Delivery path: relayed over the same encrypted Cloudflare Workers WebSocket used for stream signaling and usage data, in a per-user Durable Object room keyed to uid + deviceKey. The JWT is verified server-side against Google's public JWKS before any broadcast.
  • Map rendering: the parent app uses a free OpenStreetMap-based map (Esri World Street, Esri World Imagery satellite, or classic OSM) with a one-tap "Open in Google Maps" button. No Google Maps API key is required, and no location is sent to Google in order to render the map.
  • GPS auto-enable disclosure: when GPS is off on the kid device, XimosKid's Accessibility Service auto-clicks the system location-enable dialog's accept button in the user's language (English, Bengali, Hindi, and others). This only runs during a parent-triggered fetch — never in the background.
SEC 05

No Cookies, Web Beacons or Third-Party Sharing

Ximos is a privacy-first utility. We do not sell, rent, monetize, or trade your personal data, media streams, location payloads, or telemetry with any third-party marketing agencies, advertisers, or data brokers.

Our web applications and remote monitoring interfaces do not utilize tracking cookies, behavioral ad pixels, or session recording scripts. All communications are direct API calls between the authenticated parent dashboard and the child client service.

SEC 06

Android System Permissions Breakdown

To provide legitimate parental controls, device protection, and safety telemetry, Ximos requests specific Android permissions. Below is a full disclosure of each permission and its exact operational purpose:

android.permission.CAMERA Critical
Camera Access (Front / Rear)

Allows remote dual-camera streaming and photo snapshot captures, started only when a parent initiates a live session from the dashboard. During a live session, the parent can flip between front/rear camera, toggle the flashlight, and use Smart Zoom & Smart Focus.

Used in: Live Cam Stream, Camera Flip, Flashlight Toggle, Smart Zoom & Focus, Cloud Vault Snapshot
android.permission.RECORD_AUDIO Critical
Microphone & Audio Recording

Enables the standalone Surrounding Audio Listening feature — a one-way live ambient audio stream with 5-tier adaptive bitrate and its own dedicated UI — plus two-way audio inside a Camera Cast session. Draws from free bonus seconds or balance; sessions over 60 s receive a 10-second billing discount.

Used in: Surrounding Audio Listening, Camera Cast two-way audio, Video Record audio
BIND_ACCESSIBILITY_SERVICE Special
Accessibility Automation & Touch Control

Enables remote screen touch emulation (click, swipe, gesture) during an active screen-mirroring session, and auto-accept of the Android system GPS-enable dialog during a parent-triggered location fetch. Not used to read content from unrelated apps in the background.

Used in: Remote Touch Injection (during active session), GPS Dialog Auto-Accept (during location fetch)
android.permission.MEDIA_PROJECTION Critical
Real-Time Screen Cast & Capture

Utilizes the Android MediaProjection API to broadcast live smartphone display activity securely to the parent console with full remote touch control.

Used in: Live Screen Stream + Full Remote Control, In-App Safety Alert Overlay
ACCESS_FINE_LOCATION Active
High-Precision GPS Location

Used only when the parent explicitly triggers a location fetch from the Ximos app or dashboard. No continuous background collection. See Location Privacy, in Plain Terms above for the full fetch flow, fallback chain, and zero-retention guarantee.

Used in: Parent-Triggered Location Fetch (Fused GPS fresh fix)
ACCESS_COARSE_LOCATION Active
Network-Based Approximate Location

Enables the Network Provider fallback path (Wi-Fi BSSID + cell tower via Google's database) when a high-accuracy GPS fix is unavailable — typically 20–100 m accuracy in urban areas. Also used as the last-known fallback source.

Used in: Network Provider Fallback, Last-Known Fallback
FOREGROUND_SERVICE Standard
Persistent Foreground Operation

Keeps communication channels alive in the background while displaying the mandatory persistent notification to the child. Declares the correct service type (camera / microphone / mediaProjection / location) per Android 14+ requirements.

Used in: Background Sync, Push Listener, Notification Banner
READ_EXTERNAL_STORAGE Standard
Storage & Media Gallery Sync

Allows parent-directed media vault backup and file management for saved parental recordings. Not used to bulk-scan the existing photo library.

Used in: Vault Backup, Media File Management, Local Export
SYSTEM_ALERT_WINDOW Special
System-Level Alert & Overlay Window

Allows parents to display critical priority warning modals, OnScreen Notify messages, or emergency takeover screens over other apps.

Used in: Priority Window Alerts, OnScreen Notify, Screen Takeover
RECEIVE_BOOT_COMPLETED Standard
Automatic Startup On Device Reboot

Ensures safety services automatically resume protection immediately following a device reboot or power cycle.

Used in: Auto Boot Service, Continuity Guardian Watchdog
android.permission.WAKE_LOCK Standard
CPU Wake Lock

Prevents the operating system from abruptly terminating active live WebRTC audio/video streams or a parent-triggered location fetch during sleep mode.

Used in: Live Stream Stability, Location Fetch Completion
POST_NOTIFICATIONS Standard
Push & Priority Notifications

Delivers instant parental text alerts, reminder messages, and the persistent monitoring notification itself to the child's notification shade.

Used in: Parent Push Messages, Notification Send, Persistent Monitoring Banner
Device Admin (Uninstall Protection) Special
Accidental-Removal Protection

Requires a parent PIN before XimosKid can be uninstalled through normal Android settings, preventing impulsive removal. Does not lock the device, wipe data, or block uninstallation permanently — see full scope in the Trust Center.

Used in: PIN-Gated Uninstall Only
SEC 07

Children's Privacy (COPPA & GDPR Article 8)

Ximos is designed with the principles of the Children's Online Privacy Protection Act (COPPA) and General Data Protection Regulation (GDPR Article 8) in mind. We have not sought a third-party certification of formal compliance, and we'd rather say that directly than claim a status we can't point to an auditor for.

  • Parental Authorization: Data processing is initiated solely under the direct affirmative consent and configuration of the child's legal parent or court-appointed guardian.
  • No Commercial Profiling: Under no circumstances is child telemetry, activity logs, location data, or media utilized for behavioral advertising, credit profiling, or demographic sales.
  • Right to Erasure: Parents can review, export, or permanently delete stored vault media and their account's data at any time via account deletion or the vault's delete controls in the parent dashboard. Account deletion is permanent — see Retention & Deletion for the exact flow.

Legally Binding User Agreement

By accessing, installing, downloading, or using the Ximos application, software packages, or parent dashboard, you explicitly agree to be bound by these Terms of Use. If you do not agree to every provision herein, you must immediately uninstall and discontinue all use of the software.

ART 01

Eligibility & Guardian Attestation

You represent and warrant that:

  1. You are at least 18 years of age (or the legal age of majority in your jurisdiction).
  2. You are the biological parent, legal adoptive parent, or court-appointed legal guardian of the minor child whose device you configure with Ximos.
  3. You own the hardware device or possess full legal authority from the owner to install administrative device management software.
  4. You will not install this software on any device operated by an adult without their express, written, legally verifiable consent.
ART 02

Permitted vs. Prohibited Uses

Strictly Permitted Uses:

  • Supervising screen time, location, and application usage of your minor children.
  • Protecting children against online harassment, cyberbullying, or predatory interactions.
  • Locating lost or stolen family devices and executing remote emergency alarms.

Expressly Prohibited & Illegal Abuses:

  • Installing Ximos on a spouse's, partner's, roommate's, or acquaintance's device without their continuous knowledge.
  • Conducting corporate espionage, employee eavesdropping, or illicit trade secret theft.
  • Reverse engineering, decompiling, circumventing license protections, or redistributing modified proprietary binaries without authorization.
ART 03

Account Security & Pairing Credentials

You are entirely responsible for maintaining the confidentiality of your parent account credentials, device pairing tokens, and private encryption keys. Any actions executed through your paired parent dashboard are deemed to have been authorized by you.

If you suspect unauthorized access to your account or paired devices, you must immediately unpair the affected device from your dashboard and change your account password. Ximos does not currently offer a remote device-wipe capability; unpairing stops the monitoring session and access to that device.

ART 04

Service Availability & Telemetry Accuracy

Ximos relies on third-party hardware, cellular data networks, Wi-Fi connectivity, and Android operating system power management systems. Consequently:

  • We do not guarantee 100% uninterrupted uptime or immediate WebRTC stream connection in areas with poor network coverage.
  • Certain aggressive Android battery management optimizations (e.g., Doze Mode, OEM memory killers) may delay push notifications or background sensor reads.
  • Location accuracy is subject to GPS satellite line-of-sight and cellular triangulation limitations. Fallback sources (Network Provider, IP-based) return progressively less precise coordinates and are tagged with an isFallback flag so the parent knows how reliable each reading is.
ART 05

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, IN NO EVENT SHALL Ximos, ITS DEVELOPERS, AFFILIATES, OR CONTRIBUTORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, DEVICE MALFUNCTION, LEGAL DISPUTES ARISING FROM MISUSE, OR EMOTIONAL DISTRESS, ARISING OUT OF OR IN CONNECTION WITH THE USE OR INABILITY TO USE THE APPLICATION.

Critical Legal Warning on Wiretap & Surveillance Laws

Surreptitious monitoring of an individual without their consent is a serious criminal offense in most jurisdictions worldwide. The user assumes 100% legal responsibility for ensuring that their use of Ximos conforms strictly with all applicable local, state, federal, and international wiretap and privacy laws.

WARN 01

Strict Parental Supervision Scope Only

The Ximos suite is developed and distributed solely as a child safety and parental management tool. It is not licensed, marketed, or intended to be used as hidden spyware, covert trojans, or illicit surveillance equipment.

The developers and distributors of Ximos have zero tolerance for illegal spying. If law enforcement agencies present valid judicial subpoenas regarding illegal non-consensual surveillance, we will comply in full accordance with the law.

WARN 02

Not an Emergency Dispatch Replacement (911 / 112)

Ximos is NOT a certified emergency dispatch system or 911/112/999 service replacement. In the event of immediate danger, medical crises, fire emergencies, or life-threatening criminal situations involving your child, you MUST directly dial official public emergency authorities.

Location tracking, alerts, and remote notifications within Ximos are software-assisted features that require active cellular or Wi-Fi data to function and should never be solely relied upon in life-critical events.

WARN 03

"As-Is" & "As-Available" Software Disclaimer

Ximos IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.

We do not warrant that the application will meet your specific operational requirements, that operation will be error-free or uninterrupted, or that all defects can or will be corrected.

WARN 04

Indemnification Agreement

You agree to defend, indemnify, and hold harmless Ximos, its project maintainers, developers, and hosting infrastructure providers from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable attorneys' fees) arising out of your violation of these terms or your unlawful deployment of the software on unconsenting parties.

Open-Source Software & Third-Party Library Acknowledgments

Ximos is built with gratitude upon the open-source software ecosystem. In compliance with the licensing obligations of our dependencies, this page provides a comprehensive inventory of all third-party libraries, framework components, and their respective license terms.

AndroidX & Android Jetpack
Google LLC / Android Open Source Project
Apache 2.0

Core architecture components, Lifecycle, ViewModels, and modern Android runtime support libraries powering the client engine.

Google WebRTC Native Stack
The WebRTC Project Authors
BSD 3-Clause

Real-time peer-to-peer audio and video streaming engine enabling ultra-low latency screen broadcasts, dual-camera viewing, Surrounding Audio, and the WebRTC Data Channel used for camera zoom/focus commands.

Firebase Android SDK & FCM
Google LLC
Google / Apache 2.0

Cloud Messaging (FCM) push notification delivery, Firebase Authentication, and user-owned Realtime Database synchronizers used for command signaling.

Google Play Services — Fused Location & Auth
Google LLC
Google Open Source

FusedLocationProviderClient for high-accuracy GPS fixes during parent-triggered location fetches, and Google Sign-In SDK for secure parent identity federation.

osmdroid
osmdroid Contributors
Apache 2.0

OpenStreetMap-based MapView used in the parent app location view with switchable Street / Satellite / OSM styles — no Google Maps API key required.

Esri ArcGIS Online & OpenStreetMap Tile Services
Esri / OSM Foundation
Tile Service Terms

Free map tile sources — Esri World Street Map, Esri World Imagery satellite, and classic OpenStreetMap tiles — used to render location views without requiring a Google Maps API key.

Cloudflare Workers & Durable Objects
Cloudflare, Inc.
Service Terms

Edge WebSocket relay carrying stream signaling, usage data, and in-flight location payloads — isolated per user-device room via Durable Objects, JWT-verified server-side against Google JWKS.

OkHttp & Okio
Square, Inc.
Apache 2.0

High-performance HTTP/2 and WebSocket client used for secure parent-child signaling, encrypted vault uploads, and the location relay WebSocket client.

Google Gson
Google LLC
Apache 2.0

Java serialization/deserialization library to convert Java Objects into JSON representation and vice versa for telemetry and location payloads.

Material Components for Android
Google LLC
Apache 2.0

Modular and customizable Material Design UI components for responsive child device setup screens and the parent dashboard.

Glide Image Loading Engine
Bumptech / Google
BSD / Apache 2.0

Fast and efficient image loading and caching framework for Android and smooth thumbnail generation in the Cloud Vault.

PhotoView
Chris Banes
Apache 2.0

Implementation of ImageView supporting pinch-to-zoom, multi-touch gestures, and smooth viewport panning for photo inspections.

CircleImageView
Henning Dodenhof
Apache 2.0

Circular ImageView component for Android providing rounded child avatar and disguise icon badge rendering.

ZXing Android Embedded
JourneyApps / ZXing Authors
Apache 2.0

Barcode and QR code scanning library used for instant, single-scan pairing between child devices and the parent portal.

Android Camera2, MediaProjection & LocationManager
Android Open Source Project
Apache 2.0

Low-level camera control pipelines (Smart Zoom & Focus via CONTROL_ZOOM_RATIO / SCALER_CROP_REGION), hardware video encoding, virtual display projection interfaces, and the platform LocationManager used for Network Provider fallback.

Chart.js
Chart.js Contributors
MIT License

Simple yet flexible JavaScript charting engine used in the parent dashboard for screen time and battery usage analytics.

Lucide Icons
Lucide Project Contributors
ISC / MIT

Community-crafted vector icon library providing clean visual indicators across the parent web interface.

NOTE

Transitive Dependencies & Disclaimer of Affiliation

Any secondary libraries or transitive sub-dependencies included as part of the above packages are distributed under their respective open-source licenses (such as MIT, Apache 2.0, BSD 2-Clause, BSD 3-Clause, or ISC).

Disclaimer of Affiliation: Ximos and its maintainers are independent entities. The use of third-party open-source libraries does not imply any official endorsement, sponsorship, or affiliation with the authors, Google LLC, Square, Inc., Cloudflare, Esri, or the Apache Software Foundation.