XHON logoXHON logo
HomeAboutNewsIntegrationsPricingContact
עבריתEnglish

Privacy Policy

The privacy policy of the XHON platform - transparency, accountability and compliance with Israeli law

Last updated: September 2, 2026

Contents

  1. 1. Database Controller and Contact Details
  2. 2. Scope of the Policy
  3. 3. Types of Information We Collect
  4. 4. Purposes of Processing and Legal Basis
  5. 5. Information Sharing and Sub-processors
  6. 6. Transfer of Information Abroad
  7. 7. Retention Periods
  8. 8. Information Security
  9. 9. Rights of Data Subjects
  10. 10. Minors
  11. 11. Automated Decision-Making and Profiling
  12. 12. Mailings, Marketing and Analytics
  13. 13. Links, Fonts and Third-Party Services
  14. 14. Changes to the Policy
  15. 15. Contact

Introduction

The operator of the XHON platform (the "Operator", "we" or "XHON") respects your privacy and is committed to protecting the personal information collected and processed through the platform, the services, the applications, the API and the OAuth/MCP protocols (the "Platform" or the "Service").

This Privacy Policy explains what information we collect, how we use it, with whom we share it, how long we keep it, how we secure it and what your rights are. This policy forms an integral part of our Terms of Use.

Please note: most of the information displayed on the Platform originates from public capital-market filings (the MAGNA system of the Israel Securities Authority) and is not "personal information" about you. However, in providing the Service we collect and process personal information about registered users - account details, settings, AI conversations, tracking and more.

We act in accordance with the Protection of Privacy Law, 5741-1981 (the "Law"), its amendments - including Amendment 13, which entered into force on August 14, 2025 - its regulations, the guidelines of the Privacy Protection Authority, the Data Security Regulations and the regulations on the transfer of data abroad.

This policy may be updated from time to time. We will publish the updated version on the Platform. Your continued use after an update constitutes acceptance of the updated policy. For privacy inquiries: info@xhon.io.

1. Database Controller and Contact Details

The controller of the databases of personal information collected through the Platform is the operator of the XHON platform.

As the database controller, the Operator determines the purposes of processing, the manner of collection, the scope of use, the retention periods and the sharing policy - subject to the law.

Database manager: the XHON team responsible for privacy, information security and regulatory compliance. It can be contacted on matters of database management, database registration (where required) and the exercise of rights.

Privacy Protection Officer (DPO): inquiries on privacy matters, requests to exercise rights, and questions about data processing and transfers abroad can be sent to info@xhon.io.

For general inquiries, complaints or legal requests: the "Contact" page on the website or info@xhon.io.

We undertake to respond to privacy inquiries within a reasonable time, and in any event subject to the applicable law.

2. Scope of the Policy

This policy applies to personal information collected, processed, stored or transferred through the Platform - including the website, applications, API, OAuth/MCP, WebSocket, technical support, account management, security, monitoring, logs, backups and background processes.

This policy applies to registered users, system administrators, API users, OAuth/MCP clients and any party that connects to or uses the Service.

This policy does not apply to:

Public MAGNA filings, official documents of reporting companies, open market data and other public sources - these are not personal information about you, unless you have linked them to your account (for example by adding a company to your tracking).

External websites, services, applications or tools linked from the Platform, approved by you through OAuth, or referred to by links - these are subject solely to the privacy policies and terms of use of those parties.

The privacy policies, terms of use and data processing policies of external AI and infrastructure providers (Google, Cloudflare and others) - available on their websites.

Information you enter about public entities (companies, funds) in your tracking - this is not personal information about you, but business/professional information about public entities.

3. Types of Information We Collect

We collect personal information only to the extent required to provide the Service, secure it, comply with the law, prevent fraud, provide technical support and improve the user experience - in accordance with the principles of data minimization, purpose limitation, fairness and transparency.

We do not knowingly collect sensitive information (such as medical, biometric, religious, sexual or political-opinion information) and we do not perform commercial profiling for credit, insurance or recruitment purposes.

3.1 Account and Identification Details

Email address (used for identification, sign-in and communication), full name or display name (if provided), system role (ADMIN / USER / API), account status (ACTIVE / BLOCKED / DELETED), a detailed list of permissions, account creation date, last update date and last sign-in date.

Passwords are stored as a one-way hash on the authentication (auth) server - we do not store passwords in plain text, do not return them in API responses and cannot recover them.

Accounts may be created through independent registration (email and password, or Google Sign-In), or by a system/organization administrator by invitation. A personal account is associated with the user; an organizational account is linked to the organization the user has joined.

When a password is changed, an audit event is recorded (audit log) without storing the new password.

3.1a Google Sign-In and Google User Data

When you use Sign in with Google / Google Sign-In to create or access an XHON account, we access Google user data that you authorize via Google OAuth / OpenID Connect. The Google user data we access is limited to: email address (email), name / display name (profile), and basic OpenID subject identifier (openid). We request only the non-sensitive scopes openid, email, and profile.

How we use Google user data: to create your XHON account, verify your identity, sign you back in, link your Google identity to your account, and display your name/email in your profile. We do not use Google user data for advertising, remarketing, credit decisions, lending, or to train generalized AI models that are not personalized.

How we store Google user data: the email address, name and provider identifier are stored in our database as part of your account details and your sign-in identity record (AuthIdentity / Google provider), secured as described in the Information Security section.

How we share, transfer, or disclose Google user data: we do not sell Google user data and do not transfer it to third parties for advertising or data-trading purposes. This data stays with us for the purpose of providing the Service; it may be transferred only to infrastructure processors required to operate the Platform, or where required by law - as described in the Information Sharing section. Google itself processes the sign-in flow in accordance with Google’s privacy policy.

Data retention and deletion: Google user data stored in your account is kept for as long as the account is active, subject to the retention periods in the Retention section. You can request deletion of your account or data at info@xhon.io. Unlinking Google on Google’s side does not automatically delete your XHON account unless you ask us to.

XHON limits use of Google user data to providing or improving user-facing account authentication features. We do not sell Google user data to data brokers, advertising platforms, or information resellers.

3.2 Usage, Security and Audit Data

IP address, User-Agent (browser type, version, operating system), request timestamps.

Successful sign-in and sign-out events, password changes, access token refreshes, permission revocations, permission changes (by an ADMIN), OAuth events (approval, denial, revocation, token renewal).

Failed sign-in attempts - which may include the email address attempted, the IP address and a timestamp - for detecting brute-force attacks and preventing intrusion.

Audit logs - administrative actions: creating/updating/blocking users, changing permissions, creating and revoking API keys, administrative OAuth actions.

Error and fault logs - technical metadata (without conversation content) for diagnosis, repair and improved stability.

Rate limiting - recording of anomalous requests for the prevention of misuse.

3.3 Content and Data Created by the User

Tracking (tracked entities): monitored entities (companies, funds), ownership percentages (if entered manually), creation and update dates.

Alert rules (alerts): rule name, linked entities, MAGNA form codes, keywords, alert channels, active/disabled status.

Filings: personal feed tabs (entities and filing categories), read status (read/unread), display preferences.

AI agent conversations (agent): conversation title, full message history (questions and answers), tool calls and their results, session metadata (identifier, dates). These conversations are sent to Google Gemini for processing.

Due-diligence packages: the entity reviewed, date range, parameters, lists of filings organized by chapter, generation date.

Interface preferences: the last entity selected in tracking, side menu state (open/closed), filings panel size ratio - stored in the browser’s localStorage.

This content is stored in the database (PostgreSQL) and linked to your account. It may be accessible to your system administrator (ADMIN) and to OAuth applications you have approved - in accordance with their scopes.

3.4 Cookies, Local Storage and Tokens

The refresh_token cookie - httpOnly (not accessible to JavaScript), SameSite=strict, path=/api/v1/auth, valid for about 7 days. Used to re-authenticate a session without signing in again. Sent only with authentication API requests.

sessionStorage (key hon-auth) - an access token (JWT, valid for about 15 minutes) and a user profile (name, email, role, permissions). Deleted automatically when the browser/tab is closed.

sessionStorage (OAuth) - temporary redirect state during the OAuth consent flow (state, redirect URI). Deleted once the flow is complete.

localStorage - interface preferences only (the entity selected in tracking, menu state, panel ratio). Contains no sensitive information, passwords or tokens.

Microsoft Clarity cookies - we use Microsoft Clarity, a behavioral analytics tool, to understand how the Platform is used and to improve the user experience. The tool sets cookies and collects data on clicks, scrolling, mouse movement, page paths (in normalized form - for example "/entities/:kind/:id" rather than the full address) and device/browser type, and produces session recordings and heatmaps. Sensitive content - including input fields, numbers, email addresses, AI agent conversation content, personal holdings and tracking data, and billing details - is masked and is not sent to Clarity. Registered users are identified to Clarity only by a hashed internal identifier - not by name or email address. The tool is active in the production environment only. Microsoft’s policy: privacy.microsoft.com

We do not use advertising cookies, remarketing, the Facebook Pixel, Google Analytics or tools for building advertising audiences - the only tool we use for analytics, as described above, is Microsoft Clarity, for product and user-experience improvement purposes only, and not for advertising, selling data or sharing with advertising networks.

You can delete cookies and local storage through your browser settings - but this may require you to sign in again and reset your preferences.

3.5 Automatic Technical Information

When the Platform is accessed, the following is collected automatically: IP address, browser type and version, operating system, browser language, timestamp, request paths (URL paths) and HTTP response codes - for purposes of security, operations, fault monitoring, prevention of misuse and documentation.

This information may be kept in server logs (nginx, application logs) for a limited period - as detailed in the Retention section.

3.6 OAuth, API and Integrations

With your OAuth consent: OAuth client registration (client ID, redirect URIs), approved scopes, authorization codes, access tokens, refresh tokens, consent and revocation dates, and MCP (Model Context Protocol) connection metadata.

API keys (managed by an ADMIN): prefix (first characters, for identification), hash (one-way), creation date, revocation date and linked permissions - the full key is not stored after creation.

API requests: call metadata (endpoint, timestamp, IP, response code) - for security, rate limiting and audit.

3.7 Information That Is Not Personal Information

MAGNA filings, public documents, company and fund data, structured financial extractions, AI news items, news images and exchange-rate data originate from public filings or open sources.

This information is not personal information about you. However, linking public information to your account (for example adding a company to your tracking, or saving a conversation about a specific report) creates a record linked to your identity - and the metadata of that link (not the content of the report itself) may be considered personal information.

4. Purposes of Processing and Legal Basis

We process personal information only for the purposes set out below, and on an appropriate legal basis under the Law and Amendment 13:

4.1 Providing the Service and Managing Accounts

Creating an account, verifying identity, signing in (including Google Sign-In), managing permissions and roles, and providing access to modules (filings, search, tracking, alerts, research, news, AI agent).

Google user data (email, name/profile, OpenID identifier) is used solely to create and authenticate your XHON account and to keep your session secure - not for advertising or unrelated profiling.

Storing settings, tracking, alert rules, filings feed tabs, agent conversations, research and interface preferences.

Providing technical support, responding to inquiries and handling faults.

Legal basis: performance of a contract (Terms of Use, organizational agreement), consent (when choosing Sign in with Google), and the legitimate interest of providing the service you requested.

4.2 Information Security and Fraud Prevention

Detecting intrusion attempts, brute-force attacks, unauthorized access and misuse.

Managing tokens, refreshing sessions, revoking permissions and blocking suspicious accounts.

Rate limiting of requests, anomaly monitoring and documentation of security events for investigation and compliance.

Legal basis: legal obligation (the Data Security Regulations, Amendment 13) and the legitimate interest of protecting the system, the users and the Operator.

4.3 Artificial Intelligence Processing

Sending reports, texts, questions and conversations to Google Gemini: extracting structured financial data, summarizing reports, generating news items, responding through the AI agent and analyzing texts. (The current due-diligence packages do not include Gemini processing.)

Sending text prompts to Cloudflare Workers AI: generating images for news items (by default, the Flux model).

Information sent to AI providers may include: the text of MAGNA reports, metadata (company name, form code, date), user questions and answers, agent conversation content and image prompts.

Legal basis: performance of a contract, legitimate interest, and graduated consent - by using the AI modules (news, AI agent, extraction) you are aware of and agree to this processing.

4.4 OAuth and Third-Party Integrations

Managing external MCP/AI connections, OAuth client registration, scopes, tokens, user consents and permission revocations.

Providing controlled access to third-party applications you have approved - in accordance with their scopes.

Legal basis: express consent (in the consent interface) and performance of a contract.

4.5 Improving the Service

Aggregate and anonymous (not personally identifiable) usage analysis - to improve performance, fix faults, develop features and carry out quality checks.

We do not use personal information for targeted advertising or for selling data.

Legal basis: legitimate interest, while minimizing identifying information and anonymizing it as far as possible.

4.6 Legal Compliance

Responding to regulatory, governmental, judicial or enforcement requirements - including from the Privacy Protection Authority, the Israel Securities Authority, the police and the courts.

Keeping records for audit, reporting (where required under Amendment 13) and the resolution of disputes.

Legal basis: legal obligation.

5. Information Sharing and Sub-processors

We do not sell, rent, trade or transfer personal information to third parties for marketing or commercial purposes.

We may share information with the following parties, solely for the purposes set out in this policy and to the extent required:

5.1 Sub-processors

Google Sign-In / Google Identity - sign-in authentication: when you Sign in with Google, Google transfers to us the Google user data you have approved (email, name/profile, openid). We do not pass Google Sign-In data on to third parties for advertising purposes. Google’s policy: policies.google.com/privacy

Google (Gemini API) - AI processing: financial extraction from reports, news generation, AI agent responses, summarization, text analysis and image generation (optional). Information sent: report text, metadata, user questions and conversations, prompts. Processing location: generally outside Israel (United States, European Union). Policy: policies.google.com/privacy

Cloudflare (Workers AI / Flux) - generating images for news items. Information sent: text prompts derived from the news item’s content (headline, summary). No user details are sent. Location: Cloudflare’s global infrastructure. Policy: cloudflare.com/privacypolicy

Infrastructure provider (storage/database) - PostgreSQL for persistent data (accounts, tracking, conversations, extractions), Redis for queues, pub/sub and real-time alerts, and file storage (news images) - according to the deployment configuration (cloud or dedicated server).

Google Fonts - loading fonts (DM Sans, JetBrains Mono) from Google’s CDN (fonts.googleapis.com) when you visit the website. Google may receive your IP address and User-Agent. You can prevent this through your browser settings or content blockers.

Microsoft Clarity - behavioral analytics: session recordings, heatmaps, click and scroll data, for improving the user experience and product design. Information sent: on-page interactions (clicks, scrolling, mouse movement), normalized URL paths, device/browser type, and a hashed internal user identifier (hashed on the client side) - not your name or email address. Sensitive content (input fields, numbers, AI agent conversations, holdings and tracking data, billing details) is masked and not sent. Active in the production environment only. Processing location: Microsoft’s global infrastructure (outside Israel). Policy: privacy.microsoft.com

Bank of Israel - the official USD/ILS exchange rate displayed on the news page. Automated requests to the Bank of Israel public API, without any personal user information.

5.2 OAuth/MCP Applications You Have Approved

With your express approval in the consent interface, a third-party application (including AI tools, agents and automations) may access the data and actions defined in the scope you approved - for example: reading reports, retrieving tracking, updating tracking, reading filings and performing searches.

It is your responsibility to review the privacy policy, security and behavior of that application before approving it. Permissions can be revoked through the consent interface or by contacting info@xhon.io.

We are not responsible for processing of information carried out by third-party applications after they have been granted access through OAuth.

5.3 Legal Requirements and Enforcement

If required by law, a court order or the demand of a competent authority (including the Privacy Protection Authority, the Israel Securities Authority, the police or the Tax Authority), or to protect our legal rights, the safety of users or the integrity of the system - we will disclose information as required, to the minimum extent necessary.

5.4 Merger, Acquisition or Transfer of Business

In the event of a merger, acquisition, sale, transfer of assets or structural change, personal information may be transferred to a successor, acquirer or related entity - subject to continued appropriate protection, an undertaking to honor this policy and prior notice to data subjects, where required by law.

5.5 Within Your Organization

System administrators (ADMIN) in your organization may access user management, permissions, API keys and audit logs - within the scope of their role and for the operation of the organization.

The organization is responsible for managing internal access, granting minimal permissions and revoking the access of employees who have left.

6. Transfer of Information Abroad

AI processing through Google Gemini and Cloudflare, as well as behavioral analytics through Microsoft Clarity, involve the transfer of information outside the State of Israel - including to the United States, the European Union and other countries - according to the provider’s configuration and server locations.

We carry out transfers in accordance with the regulations on the transfer of data abroad, Amendment 13 to the Protection of Privacy Law, and the guidelines of the Privacy Protection Authority - including:

Agreements with sub-processors that include data protection undertakings.

Standard Contractual Clauses or equivalent mechanisms.

Risk assessments for transfers to countries not recognized as providing an adequate level of protection.

By using the AI modules (news, AI agent, financial extraction), you are aware of and agree to this transfer - subject to this policy and the Terms of Use.

If you do not agree to transfers abroad, you must refrain from using the AI modules. The other modules (filings, search, tracking, alerts without AI) may be available without transfer to AI providers - subject to the deployment configuration.

7. Retention Periods

We keep personal information only for as long as required for the purposes for which it was collected, for legal compliance, for the resolution of disputes, for the enforcement of agreements and for the protection of our rights - and no longer than necessary:

Account details - for as long as the account is active (ACTIVE). After closure, blocking or deletion (DELETED) - a grace period of up to 90 days for backup, restoration, audit and compliance, followed by deletion or anonymization.

Audit and security logs - 12 to 36 months, according to internal policy, the severity of the event and regulatory requirements.

Server and fault logs - 30 to 90 days, unless longer retention is required to investigate a security event.

AI agent conversations - for as long as the account is active. You can request deletion of specific conversations or all of them at info@xhon.io.

Tracking, alert rules, filings feed tabs and read status - for as long as the account is active, or until you delete them manually.

Due-diligence packages - for as long as the account is active, or until deleted manually.

Tokens, authorization codes and OAuth - until expiry, revocation of the permission or deletion of the account, whichever is earliest.

API keys - the hash and metadata are kept until the key is revoked. The full key is never stored.

Refresh cookie - valid for ~7 days; deleted on sign-out or session revocation.

sessionStorage - deleted automatically when the browser is closed.

localStorage - until deleted manually, the browser is cleared or preferences are reset.

Backups - may contain information deleted from the active system for an additional grace period, according to the backup policy.

8. Information Security

We implement administrative, organizational and technical security measures - in accordance with the Data Security Regulations, Amendment 13 and the Authority’s guidelines - including:

Password hashing (bcrypt/hash), hashed refresh tokens, and httpOnly cookies with SameSite=strict.

HTTPS in production, short-lived JWT access (~15 minutes) and automatic session refresh.

RBAC - role-based permissions (ADMIN/USER/API) with detailed permissions for each action.

Rate limiting on API requests - to prevent misuse and attacks.

Audit logs for sensitive actions - creating users, changing permissions, API keys, OAuth.

Separation of services (microservices): auth, backend, agent - with separate databases and isolated permissions.

Periodic backups, fault monitoring, and security updates to infrastructure and dependencies.

Access to servers and databases restricted to authorized staff only.

No system is completely immune to breaches, faults or cyber threats.

8.1 Security Incidents and Reporting

In the event of a serious security incident (including a leak of personal information), we will act according to an internal procedure for investigation, containment, documentation and remediation.

Where required under Amendment 13, we will report to the Privacy Protection Authority and to the affected data subjects, within the time and in the manner prescribed by law.

If you suspect a security incident related to your account, contact info@xhon.io and your system administrator immediately.

9. Rights of Data Subjects

Under the Protection of Privacy Law, Amendment 13 and the guidelines of the Privacy Protection Authority, you have the following rights with respect to personal information about you:

To exercise your rights, contact info@xhon.io or your organization’s system administrator (ADMIN). We will ask to verify your identity before disclosing information or taking action - to protect your privacy and the privacy of other users.

9.1 Right of Access

To ask whether personal information about you is held in our database, what the nature of the information is, the purposes of processing, the sources of collection and the identity of its recipients - and to receive a copy in a readable format.

Free access to your account details (name, email, permissions) is available through your system administrator. Access to agent conversations, tracking and other data - by contacting info@xhon.io.

We may refuse access to information whose disclosure would harm the privacy of others, trade secrets or the security of the system, or would be contrary to law.

9.2 Right to Rectification

To request the correction of information that is incorrect, incomplete, outdated or misleading.

Basic account details (name, email) - through your system administrator (ADMIN).

Correction of other data (conversations, tracking) - by contacting info@xhon.io, or directly in the interface (where the feature is available).

9.3 Right to Erasure

To request the deletion of personal information - subject to legal retention obligations, the Operator’s legitimate interests, audit logs, backups and the need to enforce agreements.

Full account deletion is performed by an ADMIN (status DELETED). After deletion, access to the Platform is blocked.

Deletion of agent conversations, tracking and research - by contacting info@xhon.io or in the interface (where available).

Information that must be kept by law (audit logs, payment records) may be retained even after an account is deleted, for the period permitted by law.

9.4 Right to Object and to Restrict Processing

To object to certain processing based on legitimate interest - in the cases prescribed by law.

To request restriction of processing - when you dispute the accuracy of the information, when the processing is unlawful but you do not request deletion, or when we no longer need the information but you need it for legal proceedings.

9.5 Withdrawal of Consent

Withdrawal of OAuth consent - through the consent management interface or by contacting info@xhon.io. Withdrawal may limit capabilities (for example MCP connections and automations).

Opting out of the AI modules - by ceasing to use the relevant modules (AI agent, news, research). Previous conversations may be kept until you request their deletion.

Withdrawal of consent does not retroactively affect processing lawfully carried out before the withdrawal.

9.6 Complaint to the Authority

You have the right to file a complaint with the Privacy Protection Authority if you believe that the processing of your information violates the law:

Privacy Protection Authority: www.gov.il/en/departments/the_privacy_protection_authority

We recommend contacting us first - and we will make every effort to handle your inquiry before you turn to the Authority.

9.7 Response Time

We will endeavor to respond to requests to exercise rights within 30 days of receiving the verified request.

In complex cases or subject to workload, the period may be extended in accordance with the law, with a reasoned notice.

If we refuse a request, we will provide written reasons, where required by law.

10. Minors

The Platform is not intended for minors under the age of eighteen (18). We do not knowingly collect personal information from minors and do not direct the Service at them.

If you are a parent or guardian and believe that personal information has been collected from a minor, contact info@xhon.io and we will act to delete it as soon as possible.

Organizations that grant access to young employees (for example interns) are responsible for ensuring compliance with the law and for granting minimal access.

11. Automated Decision-Making and Profiling

The Platform does not make decisions with legal, financial or significant effect on you solely by automated means - such as credit, insurance, recruitment, personalized pricing or trustworthiness scoring.

AI systems provide summaries, extractions, news items, informational answers and insights - but do not replace human judgment. You are responsible for verification, interpretation and decision-making.

Alerts are based on rules you have defined (form, company, keywords, tracking) - and are not commercial profiling, credit assessment, behavioral analysis for marketing purposes or automated decision-making about you.

Structured financial extractions (AI) may affect how data is displayed on the dashboard - but do not constitute an automated decision about you; they are based on public reports and may be incorrect.

12. Mailings, Marketing and Analytics

We do not send marketing mailings, promotional newsletters or commercial messages - unless you have expressly agreed to this (opt-in) and it is presented separately.

Operational messages (changes to terms, security alerts, system updates, password resets) may be sent to the email address registered in your account, as part of providing the Service.

We use a behavioral analytics tool (Microsoft Clarity) as described in section 3.4 - for purposes of improving the user experience and product design only. We do not use this data, or any other analytics tool (such as Google Analytics or Mixpanel), for targeted marketing, remarketing, building advertising audiences or selling information to third parties.

13. Links, Fonts and Third-Party Services

The website loads fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Google may receive your IP address, User-Agent and technical metadata when the fonts are loaded.

The Platform loads a Microsoft Clarity analytics script (clarity.ms) for behavioral analytics - see the full details in sections 3.4 and 5.1.

Links to external websites (MAGNA, the Israel Securities Authority, the Tel Aviv Stock Exchange, company websites) are subject to the privacy policies of those websites. We are not responsible for their practices.

The use of OAuth/MCP applications is subject to the privacy policies of those applications. We recommend reading the privacy policy of each application before approving access.

We are not responsible for the privacy, security or content practices of third parties - including Google, Microsoft, Cloudflare, Apify and OAuth applications.

14. Changes to the Policy

We will update this policy in line with changes in the law (including amendments to legislation, regulations and Authority guidelines), in technology, in the services, in sub-processors or in processing practices.

Material changes will be published on the Platform with an updated revision date. In certain cases, we will send a notice to the email address registered in your account.

Continued use after an update constitutes acceptance of the updated policy - unless additional express consent is required by law (for example, a material change in the purposes of processing).

Previous versions of the policy are available on request at info@xhon.io.

This policy was originally drafted in Hebrew. This English version is provided for convenience; in the event of any conflict or inconsistency between the versions, the Hebrew version shall prevail.

15. Contact

To exercise rights, and for questions, complaints, deletion requests, access requests or any other privacy inquiry:

Email: info@xhon.io

Contact page: /en/contact

In your inquiry, please include: your full name, the email address registered in your account, a description of the request and any relevant details. We will respond within a reasonable time.

XHON logoXHON logo

Smart intelligence on Israel Securities Authority filings - built on capital-market disclosures.

info@xhon.io

Product

  • Information layers
  • Research & reports
  • Financial statement analysis
  • Issuance wall

Resources

  • How it works
  • FAQ
  • Integrations

Company

  • About
  • Pricing
  • Contact

Legal

  • Terms of use
  • Privacy policy

© 2026 XHON. All rights reserved.

light_mode