Template — have a lawyer review before launch. This text is a starting point, not legal advice.
Legal
Privacy Policy
Last updated October 1, 2026
This policy explains what personal data XCap ("we") collects when you use XCap, why, who we share it with, and the choices you have. We are based in the United States. For account data we are the controller; for content and contacts you put into your workspace (for example leads) we act as your processor.
1. What we collect
- Account data: name, email, a hashed password (we can't read it), workspace name, role and email-verification status.
- Content: brand kits, scripts, captions, uploads, saved reference videos, format templates, products, and generated audio, images and video.
- Voice samples and face images (sensitive): recordings you upload to clone a voice and photos you upload to create an AI twin presenter, each with a consent record (name, statement, time, IP). See "Voice clones and AI twins" below.
- Connected platforms: when you connect YouTube, TikTok, Pinterest or Meta (Facebook/Instagram/Ads) we store encrypted access tokens, the account id and name, granted scopes, and the statistics we sync for your own posts and ads.
- Billing: plan, credit balance and history. Card details are handled by Stripe, not stored by us.
- Results data: clicks on tracked links (with a daily-salted hash of IP and browser, not the raw IP), and leads you send us, where the lead's email is stored only as a hash.
- Technical data: session records, security logs, and rate-limit counters keyed by IP address.
- Support: messages you send us.
2. How we use it
- To provide the Service: generate content, run jobs, publish posts you schedule, and report results (contract).
- To secure accounts, prevent abuse and fraud, and enforce limits (legitimate interests).
- To bill you and keep required financial records (legal obligation).
- To send account emails such as verification, password reset and job notices, and, if you opt in, product updates you can unsubscribe from (contract / consent).
3. AI processing
Standard features run on models we host ourselves. Premium features send the prompt and the content needed for that task to the provider you choose (see below). We don't use your content to train AI models, and we choose providers whose API terms don't allow them to train on it by default. Check each provider's policy for details.
4. Voice clones and AI twins (sensitive data)
A voice sample or a face image can identify a person and, in some places, counts as biometric or special-category data (for example under the Illinois Biometric Information Privacy Act (BIPA), Texas and Washington biometric laws, and GDPR / UK GDPR Art. 9). We treat them as sensitive:
- Explicit consent. We only create a voice clone or AI twin after the person heard or shown gives explicit written consent in the app. We record who consented, the exact statement, the time and the IP address.
- Purpose limitation. Samples and images are used only to generate the voiceovers and presenter videos you ask for in your workspace. We don't use them to identify people, for surveillance or advertising profiles, or to train general AI models.
- No sale or sharing. We never sell, lease, trade or otherwise profit from voice samples, face images, or any voice or face model or template derived from them. They go only to the processors needed to generate your content (ElevenLabs for premium voices, Kling for premium video, otherwise our own hosted models).
- Retention. We keep them until you delete the voice or presenter, delete your account, or the person withdraws consent — and no longer than 3 years after your last use of the Service, or sooner where the law requires.
- Deletion. Deleting a voice or presenter (or your account) removes the sample or image from storage, unregisters the cloned voice at the voice engine, and deletes the consent record. The person whose voice or face it is can also ask us directly at legal@xcap.app.
5. Connected platforms and YouTube API Services
XCap uses the YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service, and Google's use of your data is covered by the Google Privacy Policy.
- With your permission (read-only scopes) we access your channel id and name and per-video statistics such as views, average percent watched, likes, comments and shares, to show results for videos you made with XCap. We don't post, edit or delete anything on YouTube.
- We refresh this data regularly and delete YouTube API data we haven't refreshed within 30 days.
- You can revoke our access at any time from Settings → Connections or at Google security settings. When access is revoked we delete the YouTube data we stored — immediately when you disconnect in the app, and within 7 days if you revoke at Google.
- TikTok, Pinterest and Meta work the same way: disconnecting revokes our token where the platform offers a revoke API (Pinterest doesn't, so we delete the token) and deletes the statistics we synced from that platform. Statistics you entered yourself are kept.
- Paid ads run in your own Meta ad account. If you delete your account, campaigns and ads stay in your ad account; we delete our copies and metrics.
- Platform data is never sold, never used for advertising, and only shared with the platform itself to do what you asked.
6. Sub-processors
We share data only with the service providers needed to run XCap:
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payments, invoices and subscription management | Billing contact, payment details (held by Stripe) |
| xAI | Premium AI text, image and voice generation | Prompts, scripts and content you send to premium features |
| Anthropic | AI text generation (scripts, captions, agents) | Prompts and content you send to those features |
| ElevenLabs | Premium voiceovers and voice cloning | Scripts; voice samples you choose to clone |
| Kling | Premium AI video generation | Prompts and reference images you provide (may include an AI twin's face image) |
| Pexels | Stock footage search | Search terms (no personal data) |
| Google — YouTube API Services | Trend research; your own channel's analytics when you connect YouTube | Channel id and name, per-video statistics, OAuth tokens |
| Google Trends | Trend research | Search terms (no personal data) |
| Reddit API | Trend research | Search terms (no personal data) |
| Meta (Facebook, Instagram, Marketing API, Ad Library) | Instagram insights and publishing, ads in your own ad account, ad research | Page/Instagram ids and names, post and ad metrics, OAuth tokens, ad creatives you launch |
| TikTok | Publishing and your own video statistics when you connect TikTok | Account id and name, video statistics, OAuth tokens |
| Publishing pins and pin statistics when you connect Pinterest | Account id and name, pin statistics, OAuth tokens | |
| Buffer | Scheduling and publishing posts when you connect it | Posts, media and captions you schedule |
| Email provider | Sending account and notification emails | Name, email address, message content |
| Cloudflare R2 | Storing media files | Uploaded and generated media, voice samples, presenter images |
| Hosting provider | Running the app, database and job workers | All Service data, encrypted in transit |
Premium providers only receive data when you (or an agent you enabled) use a feature that relies on them. We'll update this list before adding a new sub-processor.
8. How long we keep data
- Account and workspace data: while your account is active.
- When you delete your account, workspaces you own alone and their content — media files, voice samples, AI twin images, consent records, platform tokens (revoked at the platform where possible) and synced statistics — are deleted immediately; copies in backups are overwritten within [30] days. We keep a log entry with counts only (no personal data) as a record of the deletion.
- YouTube API data: refreshed or deleted within 30 days, and deleted when you revoke access.
- Voice samples and face images: see "Voice clones and AI twins" above.
- Billing records: as long as tax and accounting law requires (typically 7 years).
- Security logs and rate-limit counters: up to [90] days.
- Password-reset links expire after 1 hour; email-verification links after 48 hours.
9. Your rights (GDPR, UK GDPR, CCPA/CPRA)
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and to withdraw consent. California residents have the right to know, delete, correct, and opt out of sale or sharing (we don't sell or share), and not to be discriminated against for using these rights.
- Do it yourself: Settings → Account lets you export your data as JSON and delete your account.
- Or ask us: email legal@xcap.app. We'll verify your identity and respond within 30 days (45 for California requests).
- If you're in the EEA or UK, you can complain to your local data protection authority.
If you're a lead or contact of one of our customers, please contact that business first; we'll help them respond.
10. How to delete your data
- Delete your account: Settings → Account → Delete account.
- Disconnect one platform: Settings → Connections.
- Removed XCap from Facebook or Instagram? Meta sends us a deletion request and gives you a confirmation code you can check at /data-deletion, which also lists every option.
- Or email legal@xcap.app.
11. International transfers
We and our providers process data in the United States and other countries. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
12. Security
We hash passwords with scrypt, encrypt stored API secrets, use HTTPS, limit login attempts, and restrict staff access. No system is perfectly secure; we'll notify you of a breach affecting your data as the law requires.
14. Children
XCap isn't for anyone under 18, and we don't knowingly collect their data.
15. Changes and contact
We'll post changes here and email you about material ones. Questions: XCap, 6408 E Virgina Ave, Scottsdale, az 85257 — legal@xcap.app.