Privacy Policy
How xillix handles your data and protects your privacy.
Last updated: January 12, 2026
Your privacy matters. This policy explains what data LuxonLink collects, what we don't collect, and how your information is used and protected.
What Data LuxonLink Collects
π Your Documents
What: The documents you upload or sync to LuxonLink (PDFs, DOCX, XLSX, PPTX, TXT, MD files), stored encrypted to power search and citations.
Why: To index and process them so LuxonLink can answer questions.
How long: For the duration of your subscription. Deleted within 30 days of cancellation (Enterprise can request immediate deletion).
π¬ Usage Data
What: Questions asked, answers generated, documents retrieved, timestamps, and user identities (for internal deployments with authentication).
Why: For audit logs, compliance, and improving answer accuracy.
How long: 90 days (LuxonLink), 1 year (Enterprise, configurable up to 7 years for compliance).
π€ Account Information
What: Account admin name, email, company name, billing information.
Why: To manage your account, billing, and provide support.
How long: For the duration of your subscription plus 7 years for tax/legal requirements.
π Technical Data
What: IP addresses, browser type, device type, access times.
Why: For security monitoring, troubleshooting, and abuse prevention.
How long: 90 days in access logs.
What Data We Do NOT Collect
π« No Behavioral Tracking
We do not use third-party analytics, tracking pixels, or advertising cookies on the LuxonLink application. No Google Analytics, no Facebook Pixel, no tracking scripts.
π« No Personal Content Analysis
We do not read, analyze, or mine the content of your documents for any purpose other than answering your queries. Automated processing only.
π« No Selling or Sharing of Data
We never sell, rent, or share your data with third parties for marketing purposes. Your documents and usage data are yours alone.
How We Use Your Data
β Providing the Service
- Indexing and processing your documents
- Answering questions with citations
- Maintaining search functionality and access controls
β Security & Compliance
- Monitoring for unauthorized access or abuse
- Generating audit logs for compliance requirements
- Detecting and preventing security threats
β Account Management
- Billing and invoicing
- Customer support and troubleshooting
- Service updates and notifications
AI Models & Third-Party Processing
π€ OpenAI API
xillix uses OpenAI's API for natural language processing. Two options:
1. BYOK (Bring Your Own Key):
- You provide your own OpenAI API key
- Your queries go directly to OpenAI using your key
- OpenAI does not train on API data per their terms
- You control your OpenAI account and data retention settings
2. xillix-Managed Keys (Enterprise):
- xillix provides and manages the OpenAI API key
- Zero data retention (ZDR) enforced with OpenAI
- Query data is not used for training
- Processed data is not stored by OpenAI beyond the API request
π« We Never Train Models on Your Data
Guaranteed: Your documents, queries, and answers are never used to train LuxonLink's models or any third-party AI models. This is enforced by contract and system architecture.
Data Sharing & Subprocessors
Third-Party Services We Use
xillix uses the following subprocessors to deliver the service. Each has a Data Processing Agreement (DPA) in place.
| Service | Purpose | Data Shared |
|---|---|---|
| Cloud Hosting Provider | Infrastructure hosting | Documents, user data (encrypted) |
| OpenAI | Natural language processing | Query text, document excerpts (ZDR enforced) |
| Cloudflare | Zero Trust access control | Authentication requests, IP addresses |
| Payment Processor | Billing and payments | Billing info, payment data (PCI compliant) |
Note: We update this list if subprocessors change. Enterprise customers are notified 30 days before new subprocessors are added.
Your Rights & Controls
β Data Access
You can export your documents and data at any time in standard formats (PDF, DOCX, JSON). Enterprise customers have admin dashboards for self-service export.
β Data Correction
Update or correct your account information at any time via your admin dashboard or by contacting support.
β Data Deletion
Delete specific documents or your entire account. Upon account deletion, all data is removed within 30 days (Enterprise can request immediate deletion).
β Data Portability
Export your data in machine-readable formats. No vendor lock-inβtake your documents and go.
β Right to Object
Object to data processing for specific purposes (e.g., request that certain documents not be indexed). Contact support to exercise this right.
Data Retention
| Data Type | Retention Period |
|---|---|
| Documents | Duration of subscription + 30 days after cancellation |
| Usage Logs | 90 days (LuxonLink), 1 year (Enterprise, configurable) |
| Account Info | 7 years after cancellation (tax/legal requirements) |
| Technical Logs | 90 days |
International Data Transfers
xillix infrastructure is hosted in the United States. If you are located outside the US, your data will be transferred to and processed in the US.
EU/UK Customers: We provide Standard Contractual Clauses (SCCs) for GDPR compliance. Enterprise customers can request data residency in EU regions.
Data Sovereignty: Enterprise customers in regulated industries can request dedicated instances in specific geographic regions.
Children's Privacy
xillix is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
Material Changes: If we make material changes that affect how your data is used, we will notify you by email (for account admins) at least 30 days before the change takes effect.
Contact Us
Questions about privacy, data handling, or your rights? We're here to help.
Email: privacy@xillix.io
General Inquiries: info@xillix.io
Contact Us