Xprompt Privacy Policy
1. Scope
This Policy explains how Xprompt handles personal information in accounts, Prompt management, model runs, debugging records, published API versions, public sharing, wallet balance, membership, support, security, and related services.
Third-party models, payment pages, email/SMS services, app stores, or other third-party websites may have their own privacy policies.
2. Information we process
We process information needed for the features you use:
| Category | Examples | Main purposes |
| Account information | Email, verification-code records, user ID, workspace ID, login session | Registration, login, account security, notices |
| Network and device information | IP, inferred country or region, browser/device data, cookies, request time, error logs | Security, fraud prevention, diagnostics, regional display, session keeping |
| User content | Prompts, system/user input, files, use cases, configuration, versions, notes | Saving, editing, running, publishing, collaboration |
| Model run information | Inputs, outputs, model parameters, usage/tokens, latency, status, call records | Returning results, debugging, cost tracking, billing, troubleshooting |
| Custom model credentials | API keys, endpoints, or related settings that you provide | Calling the model you instruct us to use |
| Sharing and publishing information | Share IDs, version snapshots, API tokens, access records, revocation status | Public sharing, published APIs, security auditing |
| Commercial and transaction information | Balance, top-up orders, ledger entries, currency, price, membership status, disputes | Payment, settlement, billing, anti-fraud, accounting |
| Payment callback information | Order number, transaction status, amount, currency returned by the visible payment channel | Payment confirmation, settlement, reconciliation, disputes |
| Support and feedback | Messages, attachments, contact details, tickets, appeal content | Support, troubleshooting, dispute handling |
| Compliance and safety records | Reports, reviews, restrictions, bans, consent records, lawful requests | Platform safety, rights evidence, legal compliance |
Please do not submit unnecessary identity documents, medical records, payment passwords, full card numbers, trade secrets, third-party keys, or other sensitive information in Prompts or support messages.
3. Purposes
We process personal information to:
- create and log in to accounts;
- save, edit, run, debug, and publish Prompts;
- send requests to the model provider you select or that is shown in the interface;
- generate results, keep run history, track model cost and call records;
- provide public sharing, Codex temporary access, or published API versions;
- handle top-ups, balance, Xprompt Plus, orders, receipts/invoices, disputes, and fraud prevention;
- provide support, notices, troubleshooting, security, and abuse prevention;
- comply with law, rights requests, infringement notices, and lawful requests;
- perform necessary product statistics and improvement without identifying you or with legally required consent.
4. Data is not used for training
Xprompt currently does not use your Prompts, inputs, outputs, run records, or API request content to train Xprompt’s own general models or third-party general models.
If we later want to use user content for training, human review, or product improvement unrelated to providing the service, we will update this Policy first and obtain separate consent or provide opt-out choices where required by law.
5. Third-party models and service providers
When you run a Prompt, we send the necessary inputs, parameters, and technical data to the model provider you select or that is shown in the interface. Different model providers may have different rules for retention, training, deletion, and regions. We will provide necessary information in the product interface, run notices, or later provider notes.
We may also use cloud infrastructure, email/SMS, payment, anti-fraud, security, analytics, support, and professional-adviser services. We require service providers to process data only as needed and to limit use through contracts, access controls, and security measures.
Payment providers are not listed one by one in this Policy. You can see the actual payment channel on the payment page. Xprompt generally does not receive full card numbers, payment passwords, or similar sensitive payment credentials.
6. Servers and cross-border processing
Xprompt’s servers and databases are primarily located in Hong Kong.
Because Xprompt serves users globally, and because model, payment, email, SMS, cloud, and support providers may be located in different countries or regions, necessary data may be processed or accessed in other countries or regions. We use contracts, access controls, minimization, and security measures where reasonably practical.
7. Public sharing, published APIs, and Codex temporary access
Content is shared or transmitted according to the interface only when you actively create a public share, publish an API version, or confirm Codex temporary access.
After a version API is published, requests to that API are routed through Xprompt servers. Public shares or temporary links may be accessed, copied, or saved by anyone who obtains the link. After revocation, we stop serving content through the official link, but we cannot delete copies already made by third parties.
8. Retention
We keep personal information only for as long as needed for the relevant purpose, considering account status, user choices, contract performance, security, disputes, tax/accounting, and legal periods.
Generally:
- account, Prompt, version, run history, and workspace content: retained until you delete it, close the account, or the service no longer needs it;
- API, sharing, and debugging records: retained until deletion, revocation, expiration, or reasonable cleanup after account closure;
- security, fraud-prevention, and error logs: usually kept no more than 180 days, unless a security incident, dispute, or legal requirement needs longer retention;
- top-up, balance, order, accounting, and transaction records: retained as required for tax, audit, payment disputes, and law;
- support, appeal, and infringement records: retained for a reasonable period after resolution, or longer if law or dispute needs it;
- backups: deleted or irreversibly anonymized over backup rotation cycles.
Deletion requests do not affect information we must keep for accounting, disputes, security, compliance, or legal obligations. That information will be restricted in use.
9. Security
We use security measures appropriate to the risk, including access controls, transport protection, storage protection, key management, logging, backups, vulnerability handling, and incident response. No system can be absolutely secure. If a notifiable security incident occurs, we will notify authorities and affected users as required by law.
10. Your rights
Depending on your location and the processing context, you may request access, copy, correction, deletion, restriction, objection, withdrawal of consent, portability, opt-out of certain sharing/marketing, limitation of sensitive information processing, or human review of automated decisions.
You can submit rights requests through the in-product support entry. We may need reasonable identity verification and will respond within legally required periods where applicable.
11. Cookies and analytics
We use necessary cookies or similar technologies for login, security, and core functions. If non-essential analytics, marketing, or cross-site tracking technologies are used, we will provide choices in regions that require consent and allow you to change those choices.
Xprompt currently does not sell personal information and does not share personal information for cross-context behavioral advertising. If this changes, we will update this Policy and provide legally required choices first.
12. Children
The minimum service age is 12. If your local law requires a higher age, guardian consent, or verifiable parental consent, that mandatory rule applies.
We do not knowingly collect information from children who do not meet the applicable age requirement. If we learn that an account does not meet the age requirement or lacks required guardian consent, we may restrict the account and delete or isolate related information as required by law.
13. Changes to this Policy
We keep historical versions. For changes that materially affect data use, training, sensitive information, major recipients, cross-border processing, or user rights, we will notify you before the effective date through the product, account, email, or equivalent method and obtain consent where required by law.
14. Contact and complaints
Privacy questions, rights requests, and complaints can be submitted through the in-product support entry.
You may also complain to the data protection, consumer protection, cyber, or other competent authority where you live.