We know, we know: few of you are excited to dive into a sea of legal jargon. But it’s important to know your rights and what we are doing. So we encourage you to read through this document. At Xperius, we collect the data we need to make our platform work brilliantly for you—things like how you use our tools, what integrations you connect, and the content you create. We're not in the business of selling your information or cluttering your inbox with irrelevant pitches. When we do use your data, it's to improve your experience, keep our services secure, and occasionally let you know about features that will matter to your work.
The bottom line: You control your data, we protect it fiercely, and we'll always be straight with you about what we're doing and why. We use industry-standard encryption, host everything securely in the US, and make it simple for you to access, correct, or delete your information whenever you want. No hidden agendas, no data mining schemes—just the transparency and control you'd expect from a tool built by people who understand that trust isn't just earned through new capabilities, but through how we handle the responsibility that comes with your data.
This Privacy Policy describes the collection, processing, use, and disclosure practices of Xperius, LLC ("Xperius," "we," "us," or "our") regarding personal data from users ("Client," "Customer," “User,” "you," or "your"). This policy applies to any information we obtain from any source or method, including but not limited to http://xperius.io (the "Website"), our web and mobile platforms, and any browser-based tools and widgets embedded in web applications (collectively, the "Services").
When you provide personal data to us, you consent to the collection, processing, use, and disclosure of your information as outlined in this Privacy Policy. Access to and full utilization of the Services requires certain personal data from you. This policy does not apply to third-party websites, applications, products, or services not owned or controlled by us.
In cases where our Services are made available through an organization (for instance, when your employer is our Customer and has made you an authorized user under their contract with us), that organization acts as the controller of information processed via the Services, including customer data. This Privacy Policy does not apply to such information, and we bear no responsibility for that organization's information and privacy practices. Your information will instead be governed by that organization's policies and procedures.
Our comprehensive privacy framework enables you to maintain control over your data (subject to the terms of our policies) while benefiting from advanced research capabilities. We provide an explanation of how we collect, process, use, govern, disclose, and share your personal data as well as notify you of your data privacy rights. We provide secure data storage, ensure regulatory compliance, and offer data ownership structures that protect both Xperius, LLC and our Users.
Browser and System Information: Your browser provides information including operating system type and version, device specifications, browser type and version, IP addresses, and connection details when accessing our Services to improve service functionality, prevent spam, and monitor server performance.
Usage Analytics: We automatically collect and analyze information during your use of our Services. This encompasses usage information, metadata, and technical logs of visited pages and utilized features.
Tracking Technologies: We use cookies—small text files with anonymous unique identifiers—to track this information. These cookies are sent from our servers to your browser and stored on your device. This allows us to gather non-personal user information and record service usage preferences, both individually and collectively. We employ persistent cookies (remaining until manually deleted) and session cookies (expiring upon closing your browser).
Targeted Advertising: We use non-personal data collected through cookies to access advertising features on various platforms (for example, Google, Reddit, Instagram, LinkedIn). We gather data about visitor behavior and track conversions, such as account creation or subscription purchases. This information allows us to analyze and optimize advertising campaigns. All data is anonymous and does not reveal personal or financial information.
Account Details: During account creation, we gather personal details including your name, email address, phone number, profile photo, and billing address. Profile photos are optional and can be substituted with initials.
Integration Credentials: Product integrations require authentication credentials like user IDs and passwords. We do not store these credentials on our systems but maintain authentication tokens that may need periodic renewal.
Communication Data: We collect personal data including email addresses, phone numbers, mailing addresses, and marketing preferences when you request Service information, subscribe to our newsletter, or contact us.
Customer Content: We gather information and materials you create or upload to the Services, such as notes, documents, images, and videos. User Content may include personal data like names, email addresses, and IP addresses of you, your customers, or clients.
Feedback and Support: You may voluntarily provide personal data about technical problems you experience or suggestions for Service enhancements. The information you share is completely discretionary. In providing Feedback and Support, we will never ask for any additional personal data other than what has already been gathered (although other portions of the Services may ask for this information).
Request for Information: When you submit forms on our website seeking information about our Enterprise solution, we may collect information including name, organization, email, address, country, and currency preference.
Employment Applications: We may gather information related to employment applications, including your name, contact details, occupation, educational background, and work experience as well as information required to verify your identity, work eligibility, or professional work reference’s contact information.
Please note: When our Services are used to conduct research studies, the rights and management of study participant data remain the responsibility of the Customer and/or User (that is, the organization or researcher conducting the study). Users must ensure appropriate consent mechanisms, data subject rights procedures, and participant protection measures are in place for any research activities conducted using our platform, including but not limited to informed consent, non-disclosure agreement, video or photo release, guardian consent, or HIPAA authorization. Data around these activities may be stored in the Services, but they are not actively managed or maintained by the Services.
Payment Information: Your Stripe Customer ID may be shared with us through our payment services. Xperius does not store credit card information; all subsequent transactions will be made using the Stripe Customer ID.
Marketing Information: Third parties may supply data or demographic details, including information about your organization, industry, or other publicly accessible information from professional profiles. We may combine this with other data to enhance your Service experience or notify you of potentially relevant Services.
Other Users: Other Users may provide information about you through standard platform usage when creating content. We also obtain your email address from other users who provide it to invite you to our Services.
We and our service providers utilize personal data for the following purposes:
Unless otherwise specified in this Privacy Policy, we do not sell, trade, rent, or distribute your personal data to third parties for marketing without your consent. We do share personal data such as contact information with vendors who perform services for us. Our vendors are contractually bound to use your personal data solely under our direction and in compliance with this Privacy Policy.
You have the right to withdraw consent over the collection, processing, use, and disclosure of your personal data at any time. Such withdrawal does not affect the lawfulness of processing personal data occurring prior to consent withdrawal. To exercise your rights, refer to section 9 of this Privacy Policy.
Some Service features may necessitate "cookies" (small text files stored on your device). While you may delete and block all cookies from our Services, doing so may compromise functionality.
Certain cookies are essential for proper Service operation. For instance, we use cookies with encrypted information to uniquely identify you during sign in and transaction processing. We may employ local shared objects to store preferences or display content based on your viewing history. We record visited pages and error messages to enhance Service functionality and performance.
Some cookies can be declined. Through third parties (such as Google Analytics), we gather website information like visit locations and durations. This may include behavioral data from Google. We may also utilize third-party cookies to obtain visitor insights, monitor the sale of Services, advertise to website visitors, and assess campaign performance across platforms.
Because essential cookies are necessary for Services operation, there is no opt-out option for these cookies. Your use of the Services provides consent for the use of any Essential Cookies.
Your browser settings may allow automatic transmission of Global Privacy Control (GPC) signals to websites and online services. We recognize and honor GPC signals to the best of our technical ability, treating them as a request to opt out of the sale or sharing of personal data where applicable under privacy laws. When we receive a GPC signal from your browser, we will apply your privacy preferences to your browsing session and, if you have an account with us, to your account going forward. For more information about Global Privacy Control, visit https://globalprivacycontrol.org.
We may utilize third-parties as subprocessors for data handling. This encompasses website and application development, hosting, maintenance, backup, storage, infrastructure, analysis, and other services. While we will monitor their security, these subprocessors may take actions beyond our control.
We maintain a current, publicly available list of all vendors and subprocessors who may access personal data. Our Vendor and Subprocessor List includes each vendor's name, location, services provided, data access scope, and applicable safeguards. We provide 30-day advance notice before adding new subprocessors and allow customers to object to such additions.
Our Services enable integration with other third-party applications. We do not control third-party services and cannot manage your information once you activate them.
You must examine privacy policies on their respective websites, as we do not endorse, evaluate, or approve these services and bear no responsibility for their privacy practices, content, or use of any of your information.
During Service use, we share specific information about you with Service users within your account for collaboration. You can generate content that may include information about you, which others can access, share, edit, copy, and download. Your account details, including name, email address, and profile image, may be accessible to other authorized Service users. When you share information with other parties via the Website, Services, or visit websites or sites provided by other users; different rules may govern their use or disclosure of your information. Consequently, when collaborating with other users, you remain subject to those third parties' privacy policies and discretions.
When your organization permits you to use Xperius within their organizational account, your personal data becomes available to your administrator. Further, it is subject to the privacy policies within your organization.
We may access, preserve, and share your information with law enforcement, government agencies, or third parties if we believe it necessary to:
When responding to verified requests from law enforcement or government officials regarding criminal investigations or alleged illegal activity, we may (and you authorize us to) disclose your name, email address, user ID, fraud complaints, and usage history without a subpoena for investigations involving fraud, intellectual property infringement, piracy, or other unlawful activity.
You maintain the following rights concerning your personal data and information:
To exercise these rights, refer to section 9 of this Privacy Policy. We will handle your request according to applicable laws and verify your identity to protect your privacy before fulfillment. We will respond to your request within 30 days. When you use our Services on behalf of an organization like your employer, please note that the organization may be responsible for fulfilling the individual rights requests mentioned above.
Please note that we may preserve certain information in anonymized and aggregated form, in archived or backup copies as mandated by records retention obligations, or otherwise as required or permitted by law. This includes but is not limited to data access logs, website analytics, purchase and account history. Furthermore, as some data, including but not limited to email, password, phone number, is critical for the operation of the Services, certain correction, deletion, or processing restriction requests for your personal data will require the suspension of your account. You will be notified in situations where that is the resulting action.
As a reminder, Your use of the Services in many cases provides consent for Our sharing of your personal data. While this Privacy Policy gives you the right to request deletion of your personal data and the right to request that your personal data be amended or corrected, this only applies to Our use and storage of Your personal data on the Services We control. Once your information has been shared or transmitted outside of the Services to third parties we do not control, we are unable to delete or amend your personal data on that third-party’s application or website.
Xperius exclusively hosts data with service providers located in the United States. We use Amazon Web Services for Service hosting in the US East (Ohio) region for website data hosting and management. This means we may transfer, process, and store your information outside your country of residence to locations where we or our third-party infrastructure subprocessors operate.
We implement data encryption during storage and transmission to ensure continuous information security. Our Services are built according to Privacy by Design architecture, incorporating data protection principles into every system component from initial design through deployment. We maintain stringent access controls with role-based permissions, multi-factor authentication, and regular access audits. Additionally, we maintain comprehensive audit trails for all data processing activities and perform regular compliance monitoring to ensure ongoing adherence to privacy regulations. To protect Customers using our Service, accounts and users are isolated by organization ID, with all information retrieval dependent on that ID to prevent inadvertent disclosure between organizations.
Your account is secured by your account password, and we urge you to protect personal data by maintaining password confidentiality and signing out after each session. By using our website and Services, you acknowledge that personal data you submit for publication through our website may be accessible globally via the internet to other Users within your organizational account. We cannot prevent the use or misuse of such personal data by others.
Please note, we will never request personal data over email, text message, or chat except to initially validate your identity on support and services calls that you initiate. WE WILL NEVER REQUEST YOUR PASSWORD THROUGH ANY COMMUNICATION CHANNEL.
We implement comprehensive safeguards for international data transfers as required by applicable privacy laws. For transfers from the European Economic Area, we rely on adequacy decisions where available and implement Standard Contractual Clauses (SCCs) approved by the European Commission where such laws apply. We conduct Transfer Impact Assessments to evaluate government surveillance risks and implement supplementary technical and organizational measures where necessary. For transfers from other jurisdictions, we ensure appropriate contractual protections and technical safeguards are in place to maintain data protection standards equivalent to the originating jurisdiction.
We maintain a comprehensive data inventory documenting all personal data we collect, process, and store. This inventory includes data categories, sources and how it is collected, purposes, storage locations and any transformations that may occur between storage locations, retention periods, and sharing arrangements. You can access our current Data Inventory Documentation which details exactly what personal data we maintain and how it is categorized and managed.
In the event of a security breach that affects personal data, we have established comprehensive incident response procedures:
For Your personal data that is used and stored in the Services, You serve as the Controller and retain the authority over such information as documented in Section 5 of this Policy. You can manage organizational access, assign roles, modify settings, and perform actions including accessing, modifying, exporting, sharing, and removing information. As processors, we only handle your personal data as documented in this Policy, the Terms and Condition, and any other policy we have in place now or may develop in the future, as we may update them from time to time. We will handle your personal data upon Your request or when necessary according to law and for Service delivery. We function as Controller for personal data we collect as described in Section 2 and other sections of this Policy as documented.
We retain personal data for the minimum period necessary to accomplish purposes described in this Privacy Policy, unless a longer retention period is mandated or permitted by law. Our retention practices follow these principles:
We implement automated deletion processes to ensure data is removed according to our retention schedules without requiring manual intervention. Customers can request earlier deletion of their data, subject to legal and contractual obligations.
We retain the right to modify this Privacy Policy at any time, with changes becoming effective immediately. You should regularly check the Website and this page for updates. We will provide email notification of any material changes to this Privacy Policy.
If you have questions or concerns about how your information is processed, please contact us at: