Data and Privacy
XiaDown is centered on local data. Downloaded files, the Library database, settings, App Sessions, and sniffing browser data are stored on the current computer. Online features such as YouTube, YouTube Music, and RSS still connect to their corresponding services.
Local data
Section titled “Local data”| Data | Description |
|---|---|
| Downloaded and transcoded files | Stored in your selected download directory or a Library-managed location. |
| Library metadata | Records tasks, files, categories, states, relationships, and activity. |
| Settings and logs | Stored in the XiaDown app-data directory. Logs may contain error context and local paths. |
| App Sessions | Stored in Keychain on macOS and with current-user system encryption on Windows. XiaDown reads sign-in data required by supported apps from a selected source only after you explicitly choose Sync from Browser. |
| Sniffing browser data | Stored in a separate browser directory that you can manage from Settings when using XiaDown Managed. Browser Default connects to the current Chrome session instead. |
Metadata backups
Section titled “Metadata backups”Library Data Management can create local metadata snapshots. They do not contain media files, but may include metadata such as accounts, settings, device authorizations, and credential hashes. Treat them as sensitive files and do not upload them publicly.
Library Access
Section titled “Library Access”If you explicitly enable private-network access to the Library, pair only devices you trust. Pairing codes and links are short-lived private credentials; do not include them in public screenshots. Revoke access promptly when a device is no longer in use.
See Library Access for connection methods, pairing steps, and device permissions.
The mobile clients have not been released. Do not provide pairing information to a third party claiming to offer XiaDown Mobile.
Usage statistics
Section titled “Usage statistics”Release builds send limited product usage statistics to TelemetryDeck, including app launches, feature areas used, app version, system platform and architecture, time zone, interface language, and cumulative usage count. Identification uses a hash of the installation identifier.
An in-app allowlist restricts the permitted events and fields. They do not include download links, file names, local paths, search terms, subscription addresses, media titles, account names, or App Session content.
Sharing logs and screenshots
Section titled “Sharing logs and screenshots”Before submitting an issue, hide or remove:
- User names and avatars.
- Website accounts and App Session state.
- Download links, subscription addresses, and private media titles.
- Local file paths and device names.
- Library pairing codes, links, tokens, and certificate information.