xf.app Platform Privacy Policy
Last Updated: May 15, 2026
This Privacy Policy describes how Experience Futures Holdings LLC (“we,” “us,” or “our”) collects, uses, and shares information in connection with the xf.app platform and related managed services (the “Platform”), and in connection with the public xf.app marketing website (informational pages, contact and demo request flows, and password-gated marketing demo pages served from the same domain, such as paths under /demo/). For the Platform, this Policy applies to Client administrators, authorized users, and end-users who interact with applications hosted on the Platform. For the public website, it applies to visitors who browse those pages or submit forms there.
This Privacy Policy should be read alongside our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Our Role
The Platform is an orchestration layer that connects Client-provided APIs, data sources, and third-party services into front-end experiences for end-users. We operate the Platform infrastructure. We are not a “data controller” or “data processor” as defined under applicable privacy laws with respect to Client Data or end-user content that flows through the Platform via Client-provided APIs and services.
Each Client is responsible for its own privacy policy governing the data it collects from its end-users through the Platform. If you are an end-user of an application built on the Platform, please refer to the privacy policy of the organization that operates that application.
2. Public marketing website (xf.app)
This section applies to visitors of the public marketing website at xf.app only (including password-gated marketing demo pages served from paths such as /demo/). It does not change how the Platform processes Client Data or end-user content in Client-hosted applications, which is described in Section 1 and in Sections 3 through 13 below.
Web analytics. We use Google Analytics 4 to understand traffic, page views, and how the public site is used. This may involve cookies or similar technologies placed by Google. For how Google handles this data, see Google’s Privacy Policy. We use these analytics to operate and improve the marketing website. We do not sell personal information for cross-context behavioral advertising through these tools.
Mailing list. If you use our contact or demo request forms and opt in via the mailing list checkbox, we may use your email address to send product updates and related news. That checkbox is optional and off by default. You may unsubscribe at any time using the link in those emails or by contacting us at info@xfutures.org.
Client applications built for their own end-users may implement their own analytics and notices; those remain the Client’s responsibility as described in Section 1.
3. Information We Collect
3.1. Client Account Information
When a Client engages us, we collect:
- Contact information (name, email address, phone number) of authorized Client representatives.
- Billing and payment information.
- API keys and credentials provided by the Client for use on the Platform. These are stored encrypted and used solely to operate the Platform on the Client’s behalf.
3.2. Operational Data
To operate, maintain, and improve the Platform, we collect:
- Server and application logs, including error logs, access logs, and performance metrics.
- Usage analytics, including feature usage, session duration, and interaction patterns.
- Security event logs, including authentication events and access attempts.
3.3. End-User Interaction Data
When end-users interact with applications hosted on the Platform, the Platform processes and logs:
- Conversation and interaction data (e.g., chat messages, form submissions, responses generated by AI inference services).
- Device and browser information (IP address, browser type, operating system).
- Session identifiers.
This data is logged by the Platform to provide the service, enable debugging, ensure platform stability, and make interaction data available to the Client as part of the managed service. Clients may access this data through the Platform or request exports at any time. Clients may also request deletion of this data at any time.
3.4. Cookies and Similar Technologies
On the Platform, we use essential cookies and session identifiers necessary for the application to function. We do not use tracking cookies or advertising cookies on the Platform. Client applications hosted on the Platform may implement their own analytics or tracking; such implementations are the Client’s responsibility and are governed by the Client’s own privacy policy.
The public xf.app website (including password-gated marketing demo pages under paths such as /demo/) may use cookies and similar technologies for web analytics as described in Section 2 above.
4. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Platform.
- Process payments and manage Client accounts.
- Monitor platform performance, security, and stability.
- Debug issues and provide technical support.
- Generate aggregated, anonymized usage analytics to improve the Platform.
- Comply with legal obligations.
- Communicate with Clients about their account, service updates, and changes to these Terms.
We do not use Client Data or end-user interaction data for advertising, marketing to third parties, or training AI models.
5. How We Share Information
We may share information with:
5.1. Service Providers
Trusted infrastructure and service providers who assist in operating the Platform (e.g., cloud hosting, monitoring, email delivery), subject to confidentiality obligations.
5.2. Client-Designated Third Parties
When a Client configures the Platform to integrate with third-party services using Client-provided API keys, data flows to those third parties as directed by the Client. We are not responsible for the privacy practices of those third-party services. Clients are responsible for their own data processing agreements with their API providers.
5.3. Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request.
5.4. Business Transfers
In the event of a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will notify affected Clients of any such transfer.
We do not sell personal information to third parties.
6. Data Retention
- Client Account Information: Retained for the duration of the Client relationship and for a reasonable period thereafter for legal, tax, and audit purposes.
- Operational Data and Logs: Retained for up to twelve (12) months, unless a longer period is required for security investigations or legal compliance.
- End-User Interaction Data: Retained for the duration of the applicable SOW. Upon termination, Client Data (including logged interaction data) is exported to the Client and deleted from the Platform within thirty (30) days, unless otherwise agreed.
- API Keys and Credentials: Deleted or rotated upon termination of the applicable SOW.
Clients may request deletion of their data at any time by contacting us at the address below.
7. Security
We implement security controls aligned with SOC 2 standards, including:
- Encryption of data in transit (TLS) and at rest.
- Multi-factor authentication for platform administration.
- Access controls and least-privilege principles.
- Regular security monitoring and logging.
- Incident response procedures.
No method of transmission over the internet is completely secure. We cannot guarantee absolute security, but we use commercially reasonable efforts to protect information processed through the Platform.
8. Data Breach Notification
In the event of a security incident that results in unauthorized access to Client Data, we will notify affected Clients promptly and without undue delay. The notification will include the nature of the incident, the types of data affected, the steps we are taking to address it, and recommended steps for the Client. We will also notify relevant authorities as required by applicable law.
9. International Data Transfers
Information may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers as required by applicable law.
10. Your Rights
Depending on your location and applicable law, you may have rights regarding your personal information, including the right to access, correct, delete, or port your data. Clients may exercise these rights by contacting us at the address below. End-users should direct requests to the Client organization that operates the application they used.
10.1. California Residents (CCPA)
If you are a California resident, you have additional rights under the CCPA, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information.
10.2. European Union Residents (GDPR)
If you are located in the EU/EEA, you may have additional rights under the GDPR, including the right to lodge a complaint with your local data protection authority. Our legal basis for processing is legitimate interest (operating the Platform) and contractual necessity (performing services under the SOW).
11. Children’s Privacy
The Platform is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active Clients in writing. The “Last Updated” date at the top of this policy indicates when it was last revised. Continued use of the Platform after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Experience Futures Holdings LLC
Email: info@xfutures.org
Website: https://xf.app