Trust
Security and privacy
XeroBot is built so a xerox shop or a company print room can accept phone uploads without turning the PC into a public file dump, and without XeroBot reading documents after print.
Files
- Uploads travel over HTTPS.
- Files exist only to complete the print job. After printing they are deleted in the configured retention workflow.
- Shop Admin and Hub see a receipt (pages, paper, amount, time, channel, employee name when corporate). They cannot open or re-download the original file from admin.
- Walk-in customers do not create an account and do not submit Aadhaar or PAN to print.
Who can send a job to the copier
- Xerox shops: the shop URL is public, but submitting typically needs the 4-digit access code shown on the agent (changes about every 5 minutes).
- Corporates: the employee QR identifies the person. A PIN is required. The PIN is not encoded in the QR. Repeated failures lock the employee for a period.
- Shop office print links are separate tokens; they can be paused or deleted.
- WhatsApp jobs come from the shop’s linked WhatsApp session on that PC (optional for corporates).
Payments
- Customer UPI uses the shop’s Razorpay keys or Razorpay Connect. XeroBot does not keep customer print settlements.
- Software recharge uses XeroBot’s Razorpay (platform keys). That is the subscription, not print money.
- Cash jobs never send card data through XeroBot.
Shop or print-room PC
- Printing happens locally via the Windows agent and the shop’s printer drivers / SumatraPDF.
- Agent updates are signed by version + SHA-256 on agent_update.json.
- The operator is responsible for locking Windows, antivirus, and who can sit at the counter PC.
Data XeroBot stores for the business
Shop name, slug, product mode, config (prices, papers, payment flags), employee names and PIN hashes/lockout state, job metadata for reports, recharge/invoices, distributor links. Not the customer’s document contents after delete.
Legal text: Privacy policy · Terms.