Privacy policy

xou.ioIn effect 27 August 2026

What we collect, where it goes, and what we do not do with it. The clause that matters most is § 4 — it says exactly what happens to a contract when you press analyse.

Who we are

XOU operates xou.io. For your account and billing data we are the controller. For the contracts and standards you put into your workspace, you are the controller and we are your processor — we handle that content on your instructions and for no purpose of our own.

Contact us at privacy@xou.io.

What we collect

We hold four kinds of data:

Your account — name, email address, the workspace you belong to, your role and permission in it, and when you signed in.
Your content — the contracts you upload, the standards and positions you write, comments, and the decisions you take on findings.
Your usage — which operations ran, what they cost in credits, and the append-only record of acts described in § 8.
Your billing details — your plan, your credit ledger, and if you add a payment method, its type, brand, expiry and last four digits only. We never receive or store a full card number.

Why we hold it

We process your account and billing data to perform our contract with you, and your usage data on the basis of our legitimate interest in operating, securing and improving the service. Your content is processed solely on your instructions, to produce the analyses you run. We do not profile you, we do not advertise, and we do not sell data to anyone.

Your contracts and the AI providers

When you run an analysis, the text of that contract — and the relevant parts of the standard it is measured against — is transmitted over an encrypted connection to a third-party model provider, which returns the findings. This is what makes the analysis possible, and it is the one point at which your content leaves our infrastructure.

XOU supports OpenAI, Anthropic, Google and DeepSeek as providers. Each is engaged under terms that prohibit training on submitted content and require deletion after processing. We will name the provider or providers in use on request, and we will give notice before adding one.

Requests are made from our servers using our own credentials. Your identity is not sent with them: the provider receives contract text, not your name, your email or your workspace.

The private layer never leaves

A position in your standard can carry a private layer — the fallback you would accept and the line you would walk away at. That layer is excluded from every published version, every export, every redline sent to a counterparty, and every request to a model provider. The exclusion is enforced in the database itself, not by a setting that could be switched off by mistake.

Who else can see it

Subprocessors. Our database and authentication run on Supabase (PostgreSQL). Analyses are read by the model provider described in § 4. Both are bound by data processing terms.

Our staff. Support and operations staff can open a session into a workspace to investigate a problem. We are direct about this because it is true and because of how it is constrained: an audit entry naming the operator, the workspace and the reason is written before the data is read, not after, so a session that goes wrong is never a session with no record. Those entries are available to you.

We also disclose data where the law requires it. We will tell you first unless we are prohibited from doing so.

Where it lives, and for how long

Workspace data is stored in the European Union. Model providers may process contract text outside the EU, under the safeguards in their processing terms. We keep your content while your workspace is open and for 30 days after it closes, so an accidental closure can be undone; after that it is deleted, subject to § 8. Billing records are kept for as long as tax law requires.

The record we cannot delete

XOU keeps an append-only record of acts taken in a workspace — who decided what, on which clause, when. It cannot be edited or deleted by you, by us, or by the most privileged account in the system. It exists so that the history of a negotiation cannot be rewritten after the fact, which is a protection for you.

What this means for erasure: we can and will delete your contracts, your standards and your account details on request. The record entries describing that acts occurred — including the name of the member who took them — are retained, because their integrity is the point of them. If you need them removed, contact us and we will deal with the request individually and tell you what we can and cannot do.

Your rights

You can ask us for a copy of your data, for a correction, for deletion, for a portable export, or to object to or restrict processing. Write to privacy@xou.io and we will respond within one month.

Where your employer opened the workspace, they are the controller of its content, and we will pass your request to them. You may also complain to your local data protection authority.

Security

Data is encrypted in transit and at rest. Every table holding customer data carries a workspace identifier and is separated by row-level security enforced by the database, rather than by application code that could forget. Provider API keys are held in an encrypted vault, never in a column and never in a file. Access by our staff is audited as described in § 6.

Changes to this policy

We will give reasonable notice before a change that materially affects how we handle your data, including before adding a subprocessor. The date at the top of this page always states the version in force.

Questions, or a request about your data: privacy@xou.io.xou.io · in effect 27 August 2026