Version 1.0.0Effective 2026-07-20Updated 2026-07-20

Xprompt Privacy Policy

1. Scope

This Policy explains how Xprompt handles personal information in accounts, Prompt management, model runs, debugging records, published API versions, public sharing, wallet balance, membership, support, security, and related services.

Third-party models, payment pages, email/SMS services, app stores, or other third-party websites may have their own privacy policies.

2. Information we process

We process information needed for the features you use:

CategoryExamplesMain purposes
Account informationEmail, verification-code records, user ID, workspace ID, login sessionRegistration, login, account security, notices
Network and device informationIP, inferred country or region, browser/device data, cookies, request time, error logsSecurity, fraud prevention, diagnostics, regional display, session keeping
User contentPrompts, system/user input, files, use cases, configuration, versions, notesSaving, editing, running, publishing, collaboration
Model run informationInputs, outputs, model parameters, usage/tokens, latency, status, call recordsReturning results, debugging, cost tracking, billing, troubleshooting
Custom model credentialsAPI keys, endpoints, or related settings that you provideCalling the model you instruct us to use
Sharing and publishing informationShare IDs, version snapshots, API tokens, access records, revocation statusPublic sharing, published APIs, security auditing
Commercial and transaction informationBalance, top-up orders, ledger entries, currency, price, membership status, disputesPayment, settlement, billing, anti-fraud, accounting
Payment callback informationOrder number, transaction status, amount, currency returned by the visible payment channelPayment confirmation, settlement, reconciliation, disputes
Support and feedbackMessages, attachments, contact details, tickets, appeal contentSupport, troubleshooting, dispute handling
Compliance and safety recordsReports, reviews, restrictions, bans, consent records, lawful requestsPlatform safety, rights evidence, legal compliance

Please do not submit unnecessary identity documents, medical records, payment passwords, full card numbers, trade secrets, third-party keys, or other sensitive information in Prompts or support messages.

3. Purposes

We process personal information to:

4. Data is not used for training

Xprompt currently does not use your Prompts, inputs, outputs, run records, or API request content to train Xprompt’s own general models or third-party general models.

If we later want to use user content for training, human review, or product improvement unrelated to providing the service, we will update this Policy first and obtain separate consent or provide opt-out choices where required by law.

5. Third-party models and service providers

When you run a Prompt, we send the necessary inputs, parameters, and technical data to the model provider you select or that is shown in the interface. Different model providers may have different rules for retention, training, deletion, and regions. We will provide necessary information in the product interface, run notices, or later provider notes.

We may also use cloud infrastructure, email/SMS, payment, anti-fraud, security, analytics, support, and professional-adviser services. We require service providers to process data only as needed and to limit use through contracts, access controls, and security measures.

Payment providers are not listed one by one in this Policy. You can see the actual payment channel on the payment page. Xprompt generally does not receive full card numbers, payment passwords, or similar sensitive payment credentials.

6. Servers and cross-border processing

Xprompt’s servers and databases are primarily located in Hong Kong.

Because Xprompt serves users globally, and because model, payment, email, SMS, cloud, and support providers may be located in different countries or regions, necessary data may be processed or accessed in other countries or regions. We use contracts, access controls, minimization, and security measures where reasonably practical.

7. Public sharing, published APIs, and Codex temporary access

Content is shared or transmitted according to the interface only when you actively create a public share, publish an API version, or confirm Codex temporary access.

After a version API is published, requests to that API are routed through Xprompt servers. Public shares or temporary links may be accessed, copied, or saved by anyone who obtains the link. After revocation, we stop serving content through the official link, but we cannot delete copies already made by third parties.

8. Retention

We keep personal information only for as long as needed for the relevant purpose, considering account status, user choices, contract performance, security, disputes, tax/accounting, and legal periods.

Generally:

Deletion requests do not affect information we must keep for accounting, disputes, security, compliance, or legal obligations. That information will be restricted in use.

9. Security

We use security measures appropriate to the risk, including access controls, transport protection, storage protection, key management, logging, backups, vulnerability handling, and incident response. No system can be absolutely secure. If a notifiable security incident occurs, we will notify authorities and affected users as required by law.

10. Your rights

Depending on your location and the processing context, you may request access, copy, correction, deletion, restriction, objection, withdrawal of consent, portability, opt-out of certain sharing/marketing, limitation of sensitive information processing, or human review of automated decisions.

You can submit rights requests through the in-product support entry. We may need reasonable identity verification and will respond within legally required periods where applicable.

11. Cookies and analytics

We use necessary cookies or similar technologies for login, security, and core functions. If non-essential analytics, marketing, or cross-site tracking technologies are used, we will provide choices in regions that require consent and allow you to change those choices.

Xprompt currently does not sell personal information and does not share personal information for cross-context behavioral advertising. If this changes, we will update this Policy and provide legally required choices first.

12. Children

The minimum service age is 12. If your local law requires a higher age, guardian consent, or verifiable parental consent, that mandatory rule applies.

We do not knowingly collect information from children who do not meet the applicable age requirement. If we learn that an account does not meet the age requirement or lacks required guardian consent, we may restrict the account and delete or isolate related information as required by law.

13. Changes to this Policy

We keep historical versions. For changes that materially affect data use, training, sensitive information, major recipients, cross-border processing, or user rights, we will notify you before the effective date through the product, account, email, or equivalent method and obtain consent where required by law.

14. Contact and complaints

Privacy questions, rights requests, and complaints can be submitted through the in-product support entry.

You may also complain to the data protection, consumer protection, cyber, or other competent authority where you live.