Privacy Policy for Xemar
Last Updated: 25/05/2026
At Xemar, we value your privacy and are dedicated to protecting your information. This Privacy Policy outlines the types of data we collect, how we use and protect it, and your rights regarding your information.
By using Xemar, you consent to the processing of your information as set forth in this Privacy Policy. If you do not agree with these terms, please do not access the application.
1. Information We Collect
When you use Xemar, we collect the following types of information:
Profile Information
When you create an account, we collect:
A username (profile name) of your choice
An automatically generated 8-character manual code that serves as your unique identifier
An automatically generated 8-digit recovery PIN
An automatically generated 8-character admin code (for team features)
Feedback and Messages
Xemar enables users to send and receive anonymous feedback. All feedback includes:
Message content (text and/or dummy star ratings)
Photo Attachments** (User-provided images captured via camera or uploaded from device)
Timestamp of when feedback was sent
Read status (new/unread indicators)
Important Note:
Xemar is designed as an anonymous feedback platform. Feedback senders remain completely anonymous to recipients. We do not collect or store sender identities, email addresses, phone numbers, or any personally identifiable information about feedback senders.
Device Information
We may collect device-specific information such as operating system and app version to enhance app functionality and troubleshoot issues.
Web Dashboard Access
Xemar provides a browser-based dashboard accessible via personal computers. When you access the dashboard through a web browser, we may collect:
Browser type and version
IP address (anonymized where possible)
Session information to maintain your logged-in status
The web dashboard offers the same functionality as the mobile app, allowing you to manage feedback, view analytics, and export reports from your computer.
2. How We Use Your Information
We use the information collected to:
Facilitate Anonymous Feedback:
Enable users to send and receive feedback (including images) through QR codes, manual code entry, or the web dashboard
Account Management:** Store your profile information to maintain your account across devices using your recovery PIN
Team Features:** Enable team administration and subscription features for users who choose to use these optional features
Improve Services:** Analyze anonymous usage patterns to enhance user experience and fix technical issues
Multi-Platform Access:** Allow seamless access to your feedback data across both mobile devices and desktop browsers
3. How Xemar's Anonymous System Works
For Feedback Senders:
No account or registration is required to send feedback
Senders can use any QR code scanner (not just Xemar app) to scan a user's code, or use the web portal from any browser
Sender identity is never collected, stored, or transmitted
Feedback (including optional photo attachments) is sent directly to the recipient's database entry
Important Note for Senders:
While Xemar does not automatically collect your identity, please be aware that any information or images you voluntarily include in your feedback (such as photos of yourself, contacts, identifiable locations, or personal documents) will be visible to the recipient. Please exercise discretion when sharing sensitive visual content.
For Feedback Recipients:
You create an account with a username and receive unique codes
Your profile information (username and manual code) is publicly accessible for QR scanning
You can access your feedback on both the mobile app and the web dashboard (dashboard.html)
You receive feedback in your private notifications area
You can delete feedback (and associated photos) you've received at any time
Web Dashboard Access
Xemar includes a secure web dashboard accessible at `dashboard.html` that provides:
Full access to all received feedback, including photo attachments
Real-time feedback monitoring
Export capabilities (CSV reports)
Feedback moderation tools
Print functionality for reports
The dashboard uses the same secure session-based authentication as the mobile app, requiring approval from your linked mobile device.
4. Data Storage and Security
Firebase Services
All data is stored securely using Google Firebase services:
Firestore Database:** Stores text-based feedback, profile data, and metadata
Cloud Storage:
Stores user-uploaded photo attachments securely with access controls
Protected by data encryption in transit and at rest
Secure access controls and Firebase Security Rules
Manual Code System
Instead of traditional email/password authentication, Xemar uses:
Unique 8-character codes as identifiers
Hashed recovery PINs for account security
No personally identifiable authentication systems
Web Dashboard Security
Session-based authentication using Firebase Realtime Database
Session tokens expire and require re-authentication
No persistent cookies store sensitive authentication data
Dashboard access requires explicit approval from your registered mobile device
Security Limitations
While we implement security measures, please be aware that:
Your manual code is publicly accessible (necessary for QR code functionality)
Anyone with your manual code can send you anonymous feedback
We cannot verify the authenticity of anonymous feedback or uploaded images
Exercise caution when sharing sensitive information through the platform
5. App Permissions
To provide its full features, Xemar requires the following permissions:
| Permission | Purpose |
| **Camera** | To scan QR codes for easy profile access and to capture photo attachments for feedback messages |
| **Internet** | To transmit feedback, upload/download photo attachments, and synchronize your profile across devices |
| **Storage** (Android) / **Photos** (iOS) | To upload images from your device gallery when providing feedback (optional) |
Note:
You can deny camera permission and still use Xemar's manual code entry method, but you will not be able to send photo attachments or scan QR codes.
6. Data Sharing and Third Parties
We Do Not:
Sell, trade, or transfer your information to third parties
Share your information with advertisers
Use your data for marketing purposes
Collect analytics that can identify individual users
Access or view your uploaded photo attachments except as necessary to provide the service
We May Share Information
If required by law or legal process
To protect the rights, property, or safety of Xemar, its users, or the public
7. Your Rights and Controls
You have full control over your data:
Access and Management
View all feedback and photo attachments you've received (on both mobile app and web dashboard)
Delete any feedback item at any time
When you delete a feedback entry, the associated photo attachment is also permanently removed from our Cloud Storage
Edit your username (limited changes available)
Delete your entire account and all associated data (including all stored images)
Account Recovery
Use your 8-digit recovery PIN to restore your account on new devices or access the web dashboard
The PIN is shown only once during account creation
Store your PIN securely as we cannot recover it for you
Data Retention
Feedback entries and associated photos are retained until you delete them
Deleted feedback is immediately removed from active databases and storage
Backups may retain data for up to 30 days for disaster recovery purposes, after which it is permanently erased
Account deletion removes all associated data within 7 days
Opt-Out Options
Uninstall the app at any time
Delete specific feedback items and their attached images
Disable team features if enabled
Revoke dashboard access by logging out or clearing your browser session
8. Children's Privacy
Xemar does not knowingly collect data from or market to children under 13 years of age. We do not solicit age information and rely on users to comply with age restrictions. If we learn that we have collected data from a user under 13, we will take steps to delete such information promptly, including any associated photo attachments.
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by Updating the "Last Updated" date at the top of this policy.
Your continued use of Xemar after any changes constitutes acceptance of the updated policy. You can access this Privacy Policy from within the app's menu or via the web dashboard.
10. Contact Us
If you have questions or concerns about this Privacy Policy or Xemar's privacy practices, please contact us at:
Email: xema.apps@gmail.com
Response Time:
We aim to respond to all privacy-related inquiries within 5-7 business days.
11. Important Disclaimers
Anonymous Nature
Xemar is designed for anonymous feedback exchange. We cannot:
Verify the identity of feedback senders
Guarantee the authenticity of feedback content or uploaded images
Prevent misuse of the anonymous system
Trace feedback back to specific senders
Remove images or content that senders voluntarily upload once delivered
User Responsibility
You are responsible for:
Keeping your recovery PIN secure
Using appropriate discretion in your username choice
Managing who has access to your QR code/manual code
The content of feedback you send to others, including any images you upload
Ensuring you have the right to share any images you upload as feedback attachments
Platform Limitations
The web dashboard requires an internet connection and a modern browser (Chrome, Firefox, Safari, or Edge)
Dashboard functionality mirrors the mobile app but does not support QR code scanning (requires manual code entry)
Session timeouts may occur for security purposes
No Liability
Xemar is not liable for:
Content of anonymous feedback sent or received (including images)
Misuse of the platform by users
Loss of data due to user error (e.g., losing recovery PIN)
Privacy breaches resulting from sharing your manual code publicly
The content, authenticity, or legality of images uploaded by feedback senders
This Privacy Policy reflects Xemar's commitment to anonymous communication while providing transparency about how our unique system works, including our new multi-platform access (mobile + web dashboard) and image attachment features.