This policy explains what data Xavior collects, how we use it, and what we do not do with it. Xavior is operated by XAVIOR Inc.
Short version: Your data is yours. We store it in per-user isolated databases, encrypt it in transit and at rest, and never sell it or use it for advertising.
1. Information We Collect
Account Information
- Email address (used for authentication and service notifications)
- Name (optional, used to personalize your experience)
- Plan and billing information
Content You Create
- Notes, documents, and files you upload
- Contacts, tasks, events, places, assets, and stats you create
- Conversation history with Xavior's AI assistant
- Workspace configurations and module settings
Data from Connected Integrations
When you connect third-party services, we collect data from those services with your explicit authorization:
- Google (Gmail, Calendar, Drive, Contacts, People API): Email messages, calendar events, documents, and contact information
- Whoop: Heart rate, strain, recovery, and sleep data
- Strava: Workouts, routes, and performance metrics
- Fitbit: Activity, sleep, and heart rate data
Automatically Collected Information
- Login timestamps and session information
- IP address (for security and abuse prevention)
- Browser type and device information
- Error logs and performance metrics
2. How We Use Your Information
We use your information only to:
- Provide and operate the Xavior service
- Authenticate your account and maintain security
- Process your conversations through AI providers to deliver intelligent assistance
- Sync and display data from connected third-party services in your workspace
- Provide AI-powered insights and assistance based on your connected data
- Send critical service notifications (login codes, security alerts)
- Respond to support requests
- Improve reliability and performance of the service
- Comply with legal obligations
We do not use your data for advertising. We do not sell your data.
3. Data Storage and Security
We implement the following security measures to protect your data:
- Per-user isolated databases: Each user's data is stored in a dedicated, isolated PostgreSQL database schema, kept separate from every other user's
- Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest
- Isolated containerized environments: Each user runs in their own secure container
- OAuth 2.0: Secure authentication for all third-party integrations
- Regular security audits: Ongoing review of security practices
No system is perfectly secure. Breaches, bugs, or failures can happen. We cannot guarantee absolute security, but we take reasonable measures to protect your data.
4. Google User Data
This section specifically addresses how Xavior handles data received from Google APIs, in compliance with Google's requirements.
What Google Data We Access
When you connect your Google account, Xavior may access the following data based on the permissions you grant:
- Gmail: Email messages, labels, and metadata — used for email management, triage, and AI-assisted responses
- Google Calendar: Calendar events, event details, attendees, and schedules — used for scheduling, event management, and AI-powered planning
- Google Drive: Files and folders you choose to connect — used for document access and reference within your workspace
- Google Contacts / People API: Contact names, email addresses, phone numbers, and organizations — used for contact enrichment and CRM features
How Google Data Is Used
- Gmail data is used for email management, triage, and AI-assisted drafting within Xavior
- Calendar data is used for scheduling, event display, and AI-powered planning assistance
- Drive data is used for document sync and reference within your workspace
- Contacts data is used for contact enrichment, CRM auto-population, and relationship tracking
How Google Data Is Stored
All Google user data is stored in your per-user isolated PostgreSQL database schema. Each user's data is kept completely separate from other users' data. Google data is encrypted at rest and in transit.
Google Data Restrictions
- Google user data is NOT shared with third parties (except as needed to process it through our AI providers to deliver features you request)
- Google user data is NOT used for advertising
- Google user data is NOT sold to anyone
- We only access the minimum data necessary to provide the features you request
Revoking Google Access
You can revoke Xavior's access to your Google data at any time by:
When you disconnect, we delete all stored OAuth tokens and stop syncing Google data. Previously synced data remains in your workspace until you delete it or delete your account.
Google API Services User Data Policy Compliance
Xavior's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Third-Party Services
Xavior integrates with the following third-party services. Below is what data each service receives and how it is handled.
AI Providers
- Anthropic (Claude API): Conversation content and relevant context from your workspace is sent to Anthropic's Claude API to power Xavior's AI capabilities. Anthropic does not use data sent to its API to train its models. Subject to Anthropic's Privacy Policy.
- OpenAI (API): As an alternative AI provider, conversation content and context may be sent to OpenAI's API under the same data handling principles. OpenAI does not use API data for model training. Subject to OpenAI's Privacy Policy.
Search
- Brave Search API: When you use the web search feature, search queries are sent to Brave Search. No personal user data, account information, or workspace content is sent — only the search query itself. Subject to Brave's Privacy Policy.
Google Services
- Gmail: Email messages, labels, and metadata
- Google Calendar: Events, schedules, and attendees
- Google Drive: Files and documents you choose to connect
- Google Contacts / People API: Contact names, emails, phone numbers, and organizations
See Section 4 above for complete details on Google data handling.
Health and Fitness Services
- Whoop: Heart rate, strain, recovery, and sleep data are synced to display your performance and recovery metrics. Subject to WHOOP's Privacy Policy.
- Strava: Workouts, routes, distance, pace, and performance metrics are synced to track and display your athletic activities. Subject to Strava's Privacy Policy.
- Fitbit: Activity, sleep, heart rate, and fitness metrics are synced to display your health data. Subject to Fitbit's Privacy Policy.
Infrastructure Services
You control which integrations are enabled. Disconnecting an integration stops data flow and deletes stored OAuth tokens.
6. Data Sharing
We do not sell your data.
We share data only in these limited circumstances:
- With AI providers (Anthropic, OpenAI) to process your requests and deliver AI features
- With Brave Search to fulfill web search queries
- With third-party services you explicitly connect (Google, Whoop, Strava, Fitbit)
- With infrastructure providers (hosting, payment processing, email delivery) strictly to operate the service
- When required by law or valid legal process
- To protect Xavior, our users, or the public from harm
Data is shared only as needed to provide the features you use. We do not share data for advertising or marketing purposes.
7. Data Retention
- Active Accounts: Your data is retained while your account is active
- Connected Service Data: Synced data is retained until you disconnect the service or delete your account
- OAuth Tokens: Deleted immediately when you disconnect a service
- After Account Cancellation: Data is retained for 30 days, then permanently deleted
- Account Deletion: You can request deletion of your account and all associated data at any time by emailing privacy@xavior.ai; we action verified requests promptly
- Google Data on Disconnect: When you disconnect your Google account, OAuth tokens are deleted immediately. Previously synced data remains until you explicitly delete it or delete your account
- Legal Requirements: Some data may be retained longer if required by law
8. User Rights
You have the right to:
- Access: Request a copy of your personal data
- Delete: Request deletion of your account and all associated data by contacting privacy@xavior.ai
- Export: Download your data in a portable format
- Correct: Update or correct your information
- Revoke Integrations: Disconnect any third-party service at any time
- Revoke Google Access: Remove Xavior's access to your Google account through your Google Account settings or through Xavior's settings
To exercise any of these rights, contact privacy@xavior.ai.
9. AI and Your Data
Xavior uses AI to help process your data and provide intelligent assistance.
- Your conversation content and relevant workspace context is sent to AI providers (Anthropic Claude, OpenAI) to generate responses
- AI providers process data only for the duration of the API request and do not retain it
- AI outputs are generated in response to your requests and may summarize, transform, or reinterpret your data
- AI can make mistakes — always verify important information
We do not train foundation models on your private data without explicit opt-in.
10. Cookies and Analytics
Xavior uses minimal first-party cookies and local storage only for essentials:
- Essential login and session management
- Remembering your preferences
- Storing OAuth tokens for connected services
To understand aggregate usage and improve the service, we use privacy-friendly, cookieless analytics: Google Analytics 4 and PostHog. Both are configured to set no tracking cookies and no persistent cross-site identifiers (Google Consent Mode with storage denied; PostHog in-memory persistence), so no cookie-consent banner is required. Inside the signed-in app, session recording is disabled — we never record the contents of your inbox, calendar, or contacts.
We do not use third-party advertising cookies or ad trackers.
11. Children's Privacy
Xavior is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it immediately.
12. California Privacy Rights (CCPA)
California residents have additional rights:
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access your personal information
- Right to equal service and price
We do not sell personal information.
13. GDPR Rights (European Users)
If you are in the European Economic Area (EEA), you have rights under the GDPR:
- Right to access, rectify, or erase your data
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
14. International Data Transfers
Your data may be transferred to and processed in the United States. By using Xavior, you consent to this transfer. We ensure appropriate safeguards are in place.
15. Changes to This Policy
We may update this policy from time to time. If changes are significant, we will notify you via email or through the service. Continued use of Xavior after changes constitutes acceptance of the updated policy.