Privacy Policy

aLLfixx AI, a product brand of XCGS AI LLC

Last updated: 2026-09-17 · Version 2026-09-17.3

These pages describe current product behavior and pre-checkout limits. Effective: 2026-09-17.

1. Scope of this Privacy Policy

This Privacy Policy describes how aLLfixx AI, a product brand of XCGS AI LLC processes personal and usage information for currently implemented product behavior.

2. Account and profile information

Account authentication is implemented. When you sign up or sign in, account data such as name, email, role, provider identity and session timestamps are processed by the authentication service.

Profile and session views may show account metadata and provider-linked profile image URLs. Account data is processed to operate login, session validation and account security flows.

3. Chat messages and conversation history

Saved conversations and preferences are stored in browser local storage. Sending a message transmits message content, model selection, language preference, optional research mode and related metadata to server APIs for processing.

Model providers may process prompts and context to return responses. Do not treat local history as end-to-end encrypted or zero-knowledge storage.

Sharing a conversation creates a link containing a snapshot of its title and message text. Anyone with the link can read that snapshot. Deleting the original local chat does not withdraw links already shared.

4. Uploaded files, images, audio and attachments

Selected attachments are uploaded with ownership-bound identifiers. Temporary storage is used for active workflows, and message-linked attachments may be persisted in server storage for retrieval.

Attachment type/size rules and ownership checks are enforced before use. Voice capture is browser-dependent and may rely on browser vendor services.

5. Device, browser, IP and diagnostic data

Web requests necessarily expose network information such as an IP address and request headers to the serving infrastructure. This code does not establish a complete production analytics or logging policy. Actual hosting logs, diagnostic fields, recipients and retention must be inventoried before launch; do not assume requests leave no operational traces.

6. Cookies and local storage

Browser local storage holds chat history, preferences, workspace data and per-plan billing-duration selection state.

Server cookies include authentication session cookies and an HttpOnly attachment-owner cookie used for upload ownership checks. Clearing site data can remove local history and preferences.

7. How information is used

Current data is used to display conversations, remember choices, handle selected uploads and validate requests. Any new account, payment, fraud-prevention or analytics use requires policy updates before activation.

8. AI processing and service providers

The product can use configured third-party AI providers to process prompts, context and relevant attachments required to produce responses or media outputs.

Provider retention, training use and processing location depend on the active provider configuration and provider terms. This policy does not claim zero retention, no sharing or no training without verified provider controls.

9. Google Drive and other connector data

Google Drive is not connected and does not browse a real Google account in the current deployment. A future enabled flow requires authorization and scoped access.

Before launch, disclose requested permissions, content accessed, storage behavior and disconnect limits. Disconnect must not be described as deleting every prior copy.

10. Payment-provider information

Checkout is not active yet. The current Subscription UI does not process card payments.

Future payment activation must clearly disclose payment roles, recurring behavior, billing records received by the app, and refund/cancellation handling. Do not submit card numbers in chat, feedback or uploads.

11. Data sharing and subprocessors

The subprocessor register is BUSINESS INPUT REQUIRED. Service-provider disclosures and lawful-request handling must reflect actual arrangements.

This policy does not claim that data is never shared or sold.

12. Data retention

Local saved chats remain until removed from the app or browser storage. Current temporary attachment entries expire after one hour and are pruned on access or periodic cleanup; a server restart also loses that in-memory store. This is not a guarantee about hosting logs, backups or every copy. Data retention schedule: BUSINESS INPUT REQUIRED.

13. Chat export and deletion

Settings → Data Controls can export current history as JSON and clear saved/current chats after confirmation. Disabling history stops future local saving; it does not erase already-saved chats. Clearing chat history does not revoke previously shared snapshots or guarantee deletion of operational logs or separate uploads.

Data Controls also offers a separate confirmed action to remove temporary server uploads belonging to this browser and clear composer attachment thumbnails. That action preserves chat text and file-name metadata, local profile data and Library files.

14. Account deletion

Account deletion is available only to an authenticated user from account settings with explicit confirmation text and server-side authorization. A user can delete only their own account.

Account deletion ends active account access and revokes sessions through the authentication layer. Removing local browser data is separate from account deletion.

This flow does not claim immediate deletion from every backup or operational log; retention boundaries require BUSINESS INPUT REQUIRED.

15. Security safeguards

Current code checks selected request inputs, attachment ownership and permitted model access. These checks do not establish end-to-end encryption, certification or an independently audited security program.

16. International data processing

Processing locations: BUSINESS INPUT REQUIRED. Provider and hosting locations must be established before production. Any applicable transfer mechanism and safeguards require review based on actual countries and vendors; no particular region is promised.

17. Children’s privacy

Eligibility threshold and guardian process are BUSINESS INPUT REQUIRED. The product is not intended for collection of children’s personal information. Do not submit such information.

18. User privacy rights

Depending on jurisdiction and processing context, you may have rights such as access, correction, deletion, export and objection. Local chat export and local-history clearing are available in settings.

Verified identity-handling workflow, formal timelines and legal-exception handling for account-level requests require operational policy finalization.

19. Policy changes

The displayed version and date identify this policy text. Update this notice when data flows change and explain material changes before activating affected integrations.

20. Contact information

Privacy contact: [email protected]. Legal entity summary: XCGS AI LLC is a Limited Liability Company (LLC) in the Delaware, United States. Certificate of Formation filed May 11, 2026. A verified channel will be published before production. Do not send secrets or identity documents to unverified addresses.