Your library is yours. Here is the mechanism, not the slogan.
A knowledge library is a decades-long bet, and you should never have to trust a vendor's goodwill to get your own thinking back. These six promises are each backed by something you can point at in the product today — not a roadmap item.
Everything exports, in formats you can read without us.
One click in Settings downloads your whole library as a ZIP: every note as plain Markdown with its metadata in frontmatter, attachments and AI cards included, plus a manifest.json and a README that documents the layout. Single notes export as Markdown from the note itself.
Export is free on every plan. Forever.
There is no export fee, no plan gate, and no rate trick on the way out. The free tier exports exactly like the paid tiers. We will never charge you to leave.
The format round-trips — and CI proves it on every merge.
The same bundle the exporter writes, the importer reads back. A leavability check runs in our merge pipeline on every change: if a release would break the export contract, it does not ship. Leaving XESO and coming back loses nothing we promised to keep.
Exports can carry a signature anyone can check.
Verified exports sign their manifest, and each cited source's content is hash-verified at export time. A recipient with no XESO account can paste the manifest at /verify to check the signature against our published key.
Deletion means deletion, on a written clock.
Account deletion is self-serve from Settings with a 72-hour grace window to change your mind. After that, your personal information and content are deleted within 30 days, and encrypted backups age out within 90 — the same terms our privacy policy commits to.
No hostage patterns.
No feature exists to make leaving harder: no export throttles, no proprietary-only formats, no 'contact sales to get your data'. If we ever sunset a capability your data depends on, the export path outlives it.
Check us, don't trust us
Verify a signed export at /verify. Read the security and compliance posture at /trust. See the grounding numbers, with run dates, at /benchmarks. The deletion terms above are the same ones written into the privacy policy.
