Privacy Policy

Last updated: January 2025

1. Introduction

aX2In Panel ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our server monitoring and mail management platform.

2. Information We Collect

2.1 Account Information

  • Email address
  • Name (optional)
  • Authentication credentials (via Firebase Auth)

2.2 Server Data

  • Server hostnames and IP addresses
  • System metrics (CPU, RAM, disk usage)
  • Mail server statistics (queues, delivery status)
  • Firewall rules and fail2ban data
  • CVE vulnerability scan results
  • System logs (if enabled by user)

2.3 Usage Data

  • Login timestamps and IP addresses
  • Feature usage patterns
  • Error logs for debugging

3. How We Use Your Information

  • To provide and maintain our service
  • To monitor your servers and send alerts
  • To analyze server performance and security
  • To improve our platform and user experience
  • To communicate important updates and security notices
  • To detect and prevent fraud or abuse

4. Data Security

We implement industry-standard security measures:

  • mTLS (Mutual TLS) - All agent-to-server communication is encrypted and mutually authenticated
  • Row-Level Security (RLS) - Database-level tenant isolation
  • HashiCorp Vault - Secure storage for sensitive credentials
  • Encrypted passwords - All mail passwords are encrypted at rest
  • Rate limiting - Protection against brute force attacks

5. Data Retention

We retain your data for as long as your account is active. Historical metrics are retained for:

  • Real-time metrics: 24 hours
  • Hourly aggregates: 30 days
  • Daily aggregates: 1 year

Upon account deletion, all your data is permanently removed within 30 days.

6. Third-Party Services

We use the following third-party services:

  • Firebase Authentication - For secure user authentication
  • Stripe - For payment processing (if applicable)
  • Anthropic Claude API - For AI-powered log analysis (Insight Engine module, if enabled)

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Withdraw consent at any time

8. Contact

For privacy-related inquiries, please contact:

Sebastian Obara
Email: [email protected]

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.