NewsbinPostoutBlogAboutContact

    No results for .

    Search help articles, blog posts, FAQs, and release notes.

    Privacy

    Effective Date: September 7, 2026

    Xetabit does not run accounts, does not build profiles, and does not have a server that stores your content. This policy covers both the website at https://xetabit.com and the Xetabit apps, including Newsbin and Postout.

    The short version

    • Xetabit apps have no accounts and no sign-in.
    • Your content stays on your device and syncs through your own iCloud account.
    • No advertising, no tracking, no analytics SDKs inside the apps.
    • AI features are optional. They run on your device, or through an AI provider you choose and pay for directly with your own API key. Nothing routes through a Xetabit server.

    Xetabit apps

    What we collect

    Nothing. Xetabit apps contain no analytics framework, no advertising identifier, no crash reporting service, and no account system. We have no way to see what you read, what you write, or what you subscribe to.

    Where your data lives

    Your library, drafts, settings, and read state are stored on your device and synced between your own devices through your personal iCloud account using Apple's CloudKit. That data is governed by Apple's iCloud terms and privacy policy. It does not pass through any Xetabit server, and we cannot read it.

    Newsbin also offers a peer-to-peer sync option that transfers directly between your devices on a local network, with no cloud involved at all.

    AI features and third-party providers

    Newsbin and Postout include optional AI features. Xetabit does not operate an AI service, does not host a model, and does not proxy AI requests. You choose the engine, and requests go directly from your device to that engine.

    Apple Intelligence

    When you select Apple Intelligence, processing happens on your device using Apple's on-device foundation models. Where the system routes a request to Apple's Private Cloud Compute, that request is handled under Apple's privacy terms, and Xetabit receives nothing.

    Providers you configure with your own API key

    If you add your own API key, the app sends requests directly from your device to that provider's API, authenticated with your key and billed to your account with them. The providers the apps can be configured to use are:

    • Anthropic (Claude), at api.anthropic.com. SeeAnthropic's privacy policy.
    • OpenAI, at api.openai.com. SeeOpenAI's privacy policy.
    • Google (Gemini), at generativelanguage.googleapis.com. SeeGoogle's privacy policy.
    • A custom endpoint: any OpenAI-compatible API address you enter yourself, including a model running on your own hardware. Whatever privacy terms apply to that service are between you and its operator.

    What is sent

    Only the content the feature needs, and only while that feature is turned on:

    • Newsbin sends article titles, article text, and feed names for the features you have enabled, such as summaries, smart tags, list overviews, breaking news grouping, and feed suggestions.
    • Postout sends the idea you type, your personality profile answers, the writing instructions belonging to the templates you have turned on, and the readable contents of any link you paste into the compose bar.

    Your name, email address, device identifiers, and location are never included. Xetabit is not a party to the request and does not receive a copy of it.

    Your consent, and how to withdraw it

    No content is sent to a third-party AI provider unless you have added that provider and its API key yourself. There is no default cloud provider, and the apps never fall back to one. The provider being used is named on screen while a request is running.

    To stop it, remove the provider in the app's settings. This deletes the stored key and ends all requests to that provider immediately. You can also turn AI features off individually or all at once, and the app continues to work without them.

    Where your API keys are stored

    API keys are stored in the Apple Keychain on your device. If you enable iCloud Keychain syncing in the app's settings, they sync between your devices through Apple's encrypted Keychain service. Xetabit never receives, transmits, or stores your keys.

    Other network requests the apps make

    Beyond AI, Xetabit apps make ordinary network requests. Any server you contact can see your IP address, which is how the internet works, but none of these requests include an identifier we assign to you.

    • Feeds, articles, and images. Newsbin fetches directly from the publishers you subscribe to. Those publishers see the request in their own logs.
    • Site icons. Newsbin uses Google's public favicon service (google.com/s2/favicons) to display a site's icon, which sends that site's domain name to Google.
    • YouTube embeds. Newsbin loads embedded video through a static page hosted at xetabit.com/_api/yt.html. This exists so embeds run correctly and does not record anything beyond standard web server logs.
    • Links you open. Opening an article, or pasting a link into Postout, contacts that site directly.

    App Store data

    Apple provides developers with aggregate, anonymized statistics about downloads, crashes, and usage for apps distributed on the App Store and through TestFlight. This data comes from Apple, is not linked to individuals, and is subject to Apple's own privacy policy. If you email us or submit feedback from inside an app, we see what you send us and use it only to reply and to fix what you reported.

    The website

    We do not collect personally identifiable information on https://xetabit.com unless you volunteer it, for example by emailing us or using the contact form. We use Umami, a cookieless, privacy-friendly analytics service, to see which pages get visited. It sets no tracking cookies and does not collect personally identifiable information.

    We do not sell, rent, or trade any information, and there is nothing here to sell.

    Children

    Xetabit apps and this website are not directed at children under 13, and we do not knowingly collect information from them.

    Data security

    Your content stays on your devices and in your own iCloud account, protected by Apple's encryption. API keys are held in the Keychain. All network requests use HTTPS. No system is perfectly secure, but we have deliberately built the apps so that there is no Xetabit database to breach.

    Changes to this policy

    If this policy changes in a way that affects what leaves your device, we will update the effective date above and note it in the app's release notes.

    Contact

    Questions about this policy, or about what any feature sends where:contact@xetabit.com

    © 2026 Xetabit. All rights reserved.AboutBlogHelpChangelogFAQsPrivacyTerms