Back to Xpanion
Trust

Trust & security

Xpanion is built so that the question "where does my data go?" has a short answer: nowhere. This page states what the app does on the network, what we hold on our side, and how you can check both for yourself.

Last updated 2026-09-16 · Applies to Xpanion for macOS and to xpanion.com


What leaves your Mac

By design, Xpanion uses the network for three things, and none of them carries meeting content — no audio, no transcript, no minutes, no board, no ledger.

  1. License validation. Xpanion checks your license over the internet when you activate it, re-check it or change your plan, when you return to Xpanion shortly after opening the payment page, and periodically after that. The license check sends your license key, an identifier derived from your machine, and the version of Xpanion you are running; our license service also sees your IP address. It carries nothing about your meetings, your recordings or your project data. Details: Privacy Policy, section 4.1.
  2. Updates. Xpanion checks for a newer version shortly after it starts and every six hours while it runs, with or without an active license. The update check and the update download go to our update storage at Vercel and carry no license key, no machine identifier and no account data; Vercel sees your IP address. A newer version is downloaded from the same storage, and its signature is verified before it is installed.
  3. Models. After you activate a license, Xpanion downloads the speech and language models it runs from Hugging Face, with our own mirror as a fallback, and keeps them on your Mac. If a model is missing later, Xpanion downloads it again the same way. The model download carries no license key, no machine identifier and no account data; Hugging Face, or our mirror when it is used, sees your IP address. On macOS 26 or later, the same step asks macOS to download Apple's speech-recognition assets for English and German, which macOS fetches from Apple. Details: Privacy Policy, section 4.4.

A Corporate seat can use the network for one more thing. On a Corporate seat connected to your organization's own hub, Xpanion signs in to that hub with the enrollment token your organization gave you and exchanges with it the projects and cards you share with your team — with their comments and activity — your team's member list, and the output-folder settings of your team and your organization; private cards are never sent, and the hub is run by your organization, not by us. Whether that connection is encrypted depends on the hub address your organization sets: an https address is, an http address is not.

There is no analytics, no telemetry, no crash reporting and no session recording inside the application.

Verify it yourself

You do not have to take our word for it. Put an outbound firewall on the app — Little Snitch or LuLu — or watch it with nettop in Terminal, and record a meeting. You may see the license check, the update check and, after you activate a license, the model download, each at the moments described above — and on a Corporate seat connected to your organization's own hub, that hub. If you see anything else, write to hello@xpanion.com with the subject "Network" and tell us what you saw. We will answer, and we will publish what we find on this page.

What we hold on our side

Account, subscription and license records — who bought which plan, which machine it is bound to, and whether the license is active. The database runs on Supabase in the United States. No meeting content ever reaches it, because the application has no code path that sends any.

The service providers involved, what each one receives, and where each one processes it are listed on the Sub-processors page.

The app you download

Xpanion is signed with Valinorsk's Apple Developer ID and notarized by Apple. The only system entitlement the app carries is the microphone. Third-party components and their licenses are listed in LICENSE-3RD-PARTY.txt inside the application bundle.

This website

xpanion.com sets no cookies, runs no analytics and no tracking, and loads nothing from a third party — no fonts, no scripts, no images. Every page is served with a Content Security Policy that forbids outside origins, and with the usual hardening headers. You can inspect them in your browser's developer tools, or with curl -I https://xpanion.com/.

Reporting a vulnerability

If you believe you have found a security issue in Xpanion or on this site, write to hello@xpanion.com with the subject "Security". We read every report ourselves, we will acknowledge it, and we will not take action against anyone who reports in good faith.


Back to Xpanion