Xavior holds your email, calendar, files, and notes — so we built it around one rule: your data is yours. Isolated, encrypted, and never used to train AI models.
Every account runs in its own container with its own isolated database. Your workspace is a physical boundary — not a row filter on a shared table.
Data is encrypted in transit (HTTPS/TLS) and at rest. That covers your conversations, your files, and everything synced from connected services.
Your conversations and workspace content are processed by AI providers only to answer your requests — not stored beyond the request, and not used to train models.
We never see or store your provider passwords. Gmail, Calendar, Drive, and every other integration connects through scoped OAuth grants you can revoke at any time.
Xavior is a subscription. We don't use your data for advertising and we don't sell it to anyone — your data is not the product.
Security practices are under ongoing review, with regular audits of how data is stored, moved, and accessed across the service.
When you chat with Xavior, your conversation and the relevant context from your workspace are sent to our AI providers — Anthropic (Claude API), OpenAI (API) — or to our own fine-tuned models to generate the response. Neither external provider stores your data beyond the duration of the API request or uses API data to train their models, and our own models are never trained on your conversations or workspace content.
No system is perfectly secure. Breaches, bugs, or failures can happen anywhere, and anyone who tells you otherwise is selling something. We cannot guarantee absolute security — but isolation, encryption, and minimal access are designed in, not bolted on.
Full details on what we collect and how it's handled are in our Privacy Policy.
If you believe you've found a security issue in Xavior, please email support@xavior.ai with the details. We read every report.
Questions about data handling? privacy@xavior.ai