Security and privacy
XeroBot is built so a xerox shop can accept phone uploads without turning the shop PC into a public file dump, and without XeroBot reading customer documents after print.
Files
- Uploads travel over HTTPS.
- Files exist only to complete the print job. After printing they are deleted in the configured retention workflow.
- Shop Admin and Hub see a receipt (pages, paper, amount, time, channel). They cannot open or re-download the original file from admin.
- Walk-in customers do not create an account and do not submit Aadhaar or PAN to print.
Who can send a job to the copier
- The shop URL is public, but submitting a print typically needs the 4-digit access code shown on the agent (changes about every 5 minutes).
- Office print links are separate tokens; they can be paused or deleted.
- WhatsApp jobs come from the shop’s linked WhatsApp session on that PC.
Payments
- Customer UPI uses the shop’s Razorpay keys or Razorpay Connect. XeroBot does not keep customer print settlements.
- Software recharge uses XeroBot’s Razorpay (platform keys). That is the subscription, not print money.
- Cash jobs never send card data through XeroBot.
Shop PC
- Printing happens locally via the Windows agent and the shop’s printer drivers / SumatraPDF.
- Agent updates are signed by version + SHA-256 on agent_update.json.
- The shop is responsible for locking Windows, antivirus, and who can sit at the counter PC.
Data XeroBot stores for the business
Shop name, slug, config (prices, papers, payment flags), job metadata for reports, recharge/invoices, distributor links. Not the customer’s document contents after delete.
Legal text: Privacy policy · Terms.