Privacy Policy
Last updated: 2026-07-17
This policy is effective from January 1, 2026.
This page explains what data XPT collects, how we use it, and the choices you have. We aim to collect the minimum needed to run the service, never use your conversations to train third-party models, and give you real control over your own data.
1. What we collect
• Account data: email address, hashed password (or Google account ID if you sign in with Google), and preferences (language, theme). • Conversation data: messages you send to XPT and the responses returned, including any files, images, or URLs you attach. Only stored in Personal mode — see below. • Usage data: request timestamps, model used, token counts, error events, IP address, and basic device fingerprint (browser, OS). Used for rate limiting, billing, and debugging. • Payment data: handled entirely by our payment processor (Airwallex). We store only your subscription status and the last 4 digits of your payment method for reference. We never see or store your full card number.
2. Incognito mode
This is XPT's core privacy promise. When you use Incognito mode: • The conversation is not stored anywhere. Not in our database, not on disk, not in backups. • Nothing is logged beyond aggregate usage counters ("1 request happened", not what was said). • When you close the tab or start a new chat, the entire conversation is gone. We cannot recover it. Neither can anyone else. Incognito is the default for people who want zero footprint. If you're not sure, use Incognito.
3. Personal mode
Personal mode saves your conversation history so you can come back to it later. In this mode: • Conversations are stored in our PostgreSQL database, encrypted at rest. • Attached files go into encrypted object storage. • You can delete any conversation, or all conversations, at any time from the sidebar. • Deletion is real: within 30 days it is purged from backups too. • We do not read your conversations. Access is restricted to a small operations team and only touched during specific incident response, all logged.
4. What we don't do
• We do not sell your data. Not to anyone, not for anything. • We do not use your conversations to train models — not ours, not third parties'. • We do not share personally identifiable information with advertisers, analytics companies, or data brokers. • We do not run ad networks, cross-site trackers, or fingerprinting scripts. • The only time we hand over data is when a valid legal process compels us. In those cases we publish a transparency note and, where legally allowed, notify the affected user.
5. Data security
• In transit: all traffic uses TLS 1.3. • At rest: databases and object storage are encrypted with AES-256. • Access control: least privilege by default. Only a small ops team can reach production, all access is audit-logged. • Incident response: if a breach exposes your data, we will notify you within 72 hours as required by applicable law.
6. Cookies
We use only strictly necessary first-party cookies: • Session token — keeps you signed in. • Language / theme — remembers your interface preferences. We do not use advertising cookies, cross-site trackers, or third-party analytics. There is no cookie banner because there is nothing to consent to beyond what makes the site work.
7. Third-party services
The following third parties process limited data on our behalf: • Airwallex — payment processing. Sees your name, email, card details (they store, we don't), and subscription events. • Cloud infrastructure providers — host our servers and storage. Data is encrypted before it reaches them; they cannot read it in plaintext. • Third-party AI APIs (OpenAI, Google, Anthropic, xAI) — when you pick one of their models. Your prompt is forwarded to them under their zero-retention terms where available. We do not send your account identity. • Self-hosted models (XPT 1.0, XPT Img 1.0) — run entirely on our own infrastructure. Nothing leaves.
8. Your rights
You have the right to: • Access your data — email us and we'll send a JSON archive of everything we have on you. • Correct data — update your email, nickname, and preferences from account settings. • Delete conversations — one by one, or all at once, from the chat sidebar. • Delete your account — permanently removes your account and all associated data within 30 days including backups. Contact iweaver@iweaver.ai to start the process. • Portability — export your history as JSON, take it anywhere. • Object to processing — opt out of any non-essential processing. We process every request within 30 days.
9. Data retention
• Incognito conversations: not retained. Ever. • Personal conversations: retained until you delete them or delete your account. • Usage logs (IP, timestamps): retained 90 days for security and abuse detection, then aggregated and purged. • Payment records: retained 7 years as required by financial regulations. • Deleted account: purged from live systems immediately; purged from backups within 30 days.
10. Children's privacy
XPT is not directed at anyone under 13 and we do not knowingly collect data from anyone under 13. If we learn that we have collected data from a child under 13, we delete it immediately. If you believe your child has created an account, contact iweaver@iweaver.ai.
11. Changes to this policy
If we make material changes, we notify subscribers by email at least 30 days before the change takes effect, and post a diff on this page. The "Last updated" date above always reflects the current version. Continuing to use XPT after the effective date means you accept the changes; if you don't, you can delete your account.
12. Contact
Privacy questions, data requests, or complaints: iweaver@iweaver.ai We read every message. Expect a reply within 3 business days.