Privacy Policy

Your data, our promise

We know, we know: few of you are excited to dive into a sea of legal jargon. But it’s important to know your rights and what we are doing. So we encourage you to read through this document. At Xperius, we collect the data we need to make our platform work brilliantly for you—things like how you use our tools, what integrations you connect, and the content you create. We're not in the business of selling your information or cluttering your inbox with irrelevant pitches. When we do use your data, it's to improve your experience, keep our services secure, and occasionally let you know about features that will matter to your work.

The bottom line: You control your data, we protect it fiercely, and we'll always be straight with you about what we're doing and why. We use industry-standard encryption, host everything securely in the US, and make it simple for you to access, correct, or delete your information whenever you want. No hidden agendas, no data mining schemes—just the transparency and control you'd expect from a tool built by people who understand that trust isn't just earned through new capabilities, but through how we handle the responsibility that comes with your data.

Version 1.0

1. Policy Overview

This Privacy Policy describes the collection, processing, use, and disclosure practices of Xperius, LLC ("Xperius," "we," "us," or "our") regarding personal data from users ("Client," "Customer," “User,” "you," or "your"). This policy applies to any information we obtain from any source or method, including but not limited to http://xperius.io (the "Website"), our web and mobile platforms, and any browser-based tools and widgets embedded in web applications (collectively, the "Services").

When you provide personal data to us, you consent to the collection, processing, use, and disclosure of your information as outlined in this Privacy Policy. Access to and full utilization of the Services requires certain personal data from you. This policy does not apply to third-party websites, applications, products, or services not owned or controlled by us.

In cases where our Services are made available through an organization (for instance, when your employer is our Customer and has made you an authorized user under their contract with us), that organization acts as the controller of information processed via the Services, including customer data. This Privacy Policy does not apply to such information, and we bear no responsibility for that organization's information and privacy practices. Your information will instead be governed by that organization's policies and procedures.

Our comprehensive privacy framework enables you to maintain control over your data (subject to the terms of our policies) while benefiting from advanced research capabilities. We provide an explanation of how we collect, process, use, govern, disclose, and share your personal data as well as notify you of your data privacy rights. We provide secure data storage, ensure regulatory compliance, and offer data ownership structures that protect both Xperius, LLC and our Users.

2. Information Collection Methods

2.1. Information Collected Automatically

Browser and System Information: Your browser provides information including operating system type and version, device specifications, browser type and version, IP addresses, and connection details when accessing our Services to improve service functionality, prevent spam, and monitor server performance.

Usage Analytics: We automatically collect and analyze information during your use of our Services. This encompasses usage information, metadata, and technical logs of visited pages and utilized features.

Tracking Technologies: We use cookies—small text files with anonymous unique identifiers—to track this information. These cookies are sent from our servers to your browser and stored on your device. This allows us to gather non-personal user information and record service usage preferences, both individually and collectively. We employ persistent cookies (remaining until manually deleted) and session cookies (expiring upon closing your browser).

Targeted Advertising: We use non-personal data collected through cookies to access advertising features on various platforms (for example, Google, Reddit, Instagram, LinkedIn). We gather data about visitor behavior and track conversions, such as account creation or subscription purchases. This information allows us to analyze and optimize advertising campaigns. All data is anonymous and does not reveal personal or financial information.

2.2. Information You Provide

Account Details: During account creation, we gather personal details including your name, email address, phone number, profile photo, and billing address. Profile photos are optional and can be substituted with initials.

Integration Credentials: Product integrations require authentication credentials like user IDs and passwords. We do not store these credentials on our systems but maintain authentication tokens that may need periodic renewal.

Communication Data: We collect personal data including email addresses, phone numbers, mailing addresses, and marketing preferences when you request Service information, subscribe to our newsletter, or contact us.

Customer Content: We gather information and materials you create or upload to the Services, such as notes, documents, images, and videos. User Content may include personal data like names, email addresses, and IP addresses of you, your customers, or clients.

Feedback and Support: You may voluntarily provide personal data about technical problems you experience or suggestions for Service enhancements. The information you share is completely discretionary. In providing Feedback and Support, we will never ask for any additional personal data other than what has already been gathered (although other portions of the Services may ask for this information).

Request for Information: When you submit forms on our website seeking information about our Enterprise solution, we may collect information including name, organization, email, address, country, and currency preference.

Employment Applications: We may gather information related to employment applications, including your name, contact details, occupation, educational background, and work experience as well as information required to verify your identity, work eligibility, or professional work reference’s contact information.

Please note: When our Services are used to conduct research studies, the rights and management of study participant data remain the responsibility of the Customer and/or User (that is, the organization or researcher conducting the study). Users must ensure appropriate consent mechanisms, data subject rights procedures, and participant protection measures are in place for any research activities conducted using our platform, including but not limited to informed consent, non-disclosure agreement, video or photo release, guardian consent, or HIPAA authorization. Data around these activities may be stored in the Services, but they are not actively managed or maintained by the Services.

2.3. Information from External Sources

Payment Information: Your Stripe Customer ID may be shared with us through our payment services. Xperius does not store credit card information; all subsequent transactions will be made using the Stripe Customer ID.

Marketing Information: Third parties may supply data or demographic details, including information about your organization, industry, or other publicly accessible information from professional profiles. We may combine this with other data to enhance your Service experience or notify you of potentially relevant Services.

Other Users: Other Users may provide information about you through standard platform usage when creating content. We also obtain your email address from other users who provide it to invite you to our Services.

3. Information Usage

We and our service providers utilize personal data for the following purposes:

  1. Deliver and enable Service access;
  2. Support research, development, and user experience enhancement;
  3. Analyze traffic patterns and website/Service usage;
  4. Process payments for subscription services;
  5. Communicate about Service-related topics;
  6. Deliver customer support and maintain Service security;
  7. Recommend services or additional features (you may withdraw consent anytime);
  8. Contact current and prospective customers about our products and services; 
  9. Facilitate merger, acquisition, reorganization, or similar business transactions; or
  10. Support recruitment and employment processes.

Unless otherwise specified in this Privacy Policy, we do not sell, trade, rent, or distribute your personal data to third parties for marketing without your consent. We do share personal data such as contact information with vendors who perform services for us. Our vendors are contractually bound to use your personal data solely under our direction and in compliance with this Privacy Policy.

You have the right to withdraw consent over the collection, processing, use, and disclosure of your personal data at any time. Such withdrawal does not affect the lawfulness of processing personal data occurring prior to consent withdrawal. To exercise your rights, refer to section 9 of this Privacy Policy.

3.1. Cookie Usage

Some Service features may necessitate "cookies" (small text files stored on your device). While you may delete and block all cookies from our Services, doing so may compromise functionality.

3.1.1. Required Cookies

Certain cookies are essential for proper Service operation. For instance, we use cookies with encrypted information to uniquely identify you during sign in and transaction processing. We may employ local shared objects to store preferences or display content based on your viewing history. We record visited pages and error messages to enhance Service functionality and performance.

3.1.2. Optional Cookies

Some cookies can be declined. Through third parties (such as Google Analytics), we gather website information like visit locations and durations. This may include behavioral data from Google. We may also utilize third-party cookies to obtain visitor insights, monitor the sale of Services, advertise to website visitors, and assess campaign performance across platforms.

3.2. Preference Management

3.2.1. Essential Cookies

Because essential cookies are necessary for Services operation, there is no opt-out option for these cookies. Your use of the Services provides consent for the use of any Essential Cookies.

3.2.2. Optional Cookies
  • Google: You can opt out of Google Marketing Platform cookie usage by visiting the My Ad Center page or the Network Advertising Initiative opt-out page.
  • LinkedIn: LinkedIn users may opt out of cookie tracking through user controls. LinkedIn's privacy policy is available for review.
  • Google Analytics: Google's use and sharing of Google Analytics information is governed by the Google Analytics Terms of Service and Google Privacy Policy. You may learn more about Google's data collection and processing practices with Google Analytics. Google's privacy policy is available for review.

3.3. Global Privacy Control Signal Response

Your browser settings may allow automatic transmission of Global Privacy Control (GPC) signals to websites and online services. We recognize and honor GPC signals to the best of our technical ability, treating them as a request to opt out of the sale or sharing of personal data where applicable under privacy laws. When we receive a GPC signal from your browser, we will apply your privacy preferences to your browsing session and, if you have an account with us, to your account going forward. For more information about Global Privacy Control, visit https://globalprivacycontrol.org.

4. Information and Data Sharing

4.1. Subprocessors, Service Providers, Integrations, and Third-Party Services

We may utilize third-parties as subprocessors for data handling. This encompasses website and application development, hosting, maintenance, backup, storage, infrastructure, analysis, and other services. While we will monitor their security, these subprocessors may take actions beyond our control.

We maintain a current, publicly available list of all vendors and subprocessors who may access personal data. Our Vendor and Subprocessor List includes each vendor's name, location, services provided, data access scope, and applicable safeguards. We provide 30-day advance notice before adding new subprocessors and allow customers to object to such additions.

Our Services enable integration with other third-party applications. We do not control third-party services and cannot manage your information once you activate them.

You must examine privacy policies on their respective websites, as we do not endorse, evaluate, or approve these services and bear no responsibility for their privacy practices, content, or use of any of your information.

4.2. User Collaboration

During Service use, we share specific information about you with Service users within your account for collaboration. You can generate content that may include information about you, which others can access, share, edit, copy, and download. Your account details, including name, email address, and profile image, may be accessible to other authorized Service users. When you share information with other parties via the Website, Services, or visit websites or sites provided by other users; different rules may govern their use or disclosure of your information. Consequently, when collaborating with other users, you remain subject to those third parties' privacy policies and discretions.

When your organization permits you to use Xperius within their organizational account, your personal data becomes available to your administrator. Further, it is subject to the privacy policies within your organization.

4.3. Legal Compliance

We may access, preserve, and share your information with law enforcement, government agencies, or third parties if we believe it necessary to:

  1. Comply with law enforcement or national security requests and legal processes, including court orders or subpoenas;
  2. Protect the rights, property, or safety of you, us, or others; 
  3. Enforce our policies and contracts;
  4. Investigate fraud;
  5. Collect debts owed to us; 
  6. Prevent financial losses; or 
  7. Support investigation or prosecution of suspected or actual illegal activity when we believe disclosure is warranted.

When responding to verified requests from law enforcement or government officials regarding criminal investigations or alleged illegal activity, we may (and you authorize us to) disclose your name, email address, user ID, fraud complaints, and usage history without a subpoena for investigations involving fraud, intellectual property infringement, piracy, or other unlawful activity.

5. Data Privacy Rights

You maintain the following rights concerning your personal data and information:

  • Transparency: This Privacy Policy documents the collection, processing, use, sharing, and deletion of your personal data.
  • Data Access: You can verify whether we are processing your personal data and obtain electronic copies of personal data you have supplied.
  • Data Portability: You may request that we transmit that information to another company.
  • Correction: When your personal data is inaccurate or incomplete, you can request correction.
  • Deletion: You can request removal of your personal data.
  • Processing Restriction or Objection: You can request limitation of or object to our processing of your personal data.
  • Consent Withdrawal: You can revoke consent to our processing of your personal data.
  • Marketing Opt-out: You can unsubscribe from marketing communications.
  • Filing Complaints: You have the right to file complaints with a supervisory authority or administrator if you believe our processing of your personal data violates applicable law.

To exercise these rights, refer to section 9 of this Privacy Policy. We will handle your request according to applicable laws and verify your identity to protect your privacy before fulfillment. We will respond to your request within 30 days. When you use our Services on behalf of an organization like your employer, please note that the organization may be responsible for fulfilling the individual rights requests mentioned above.

Please note that we may preserve certain information in anonymized and aggregated form, in archived or backup copies as mandated by records retention obligations, or otherwise as required or permitted by law. This includes but is not limited to data access logs, website analytics, purchase and account history. Furthermore, as some data, including but not limited to email, password, phone number, is critical for the operation of the Services, certain correction, deletion, or processing restriction requests for your personal data will require the suspension of your account. You will be notified in situations where that is the resulting action.

As a reminder, Your use of the Services in many cases provides consent for Our sharing of your personal data. While this Privacy Policy gives you the right to request deletion of your personal data and the right to request that your personal data be amended or corrected, this only applies to Our use and storage of Your personal data on the Services We control. Once your information has been shared or transmitted outside of the Services to third parties we do not control, we are unable to delete or amend your personal data on that third-party’s application or website.

6. Data Storage and Transfer

Xperius exclusively hosts data with service providers located in the United States. We use Amazon Web Services for Service hosting in the US East (Ohio) region for website data hosting and management. This means we may transfer, process, and store your information outside your country of residence to locations where we or our third-party infrastructure subprocessors operate.

We implement data encryption during storage and transmission to ensure continuous information security. Our Services are built according to Privacy by Design architecture, incorporating data protection principles into every system component from initial design through deployment. We maintain stringent access controls with role-based permissions, multi-factor authentication, and regular access audits. Additionally, we maintain comprehensive audit trails for all data processing activities and perform regular compliance monitoring to ensure ongoing adherence to privacy regulations. To protect Customers using our Service, accounts and users are isolated by organization ID, with all information retrieval dependent on that ID to prevent inadvertent disclosure between organizations. 

Your account is secured by your account password, and we urge you to protect personal data by maintaining password confidentiality and signing out after each session. By using our website and Services, you acknowledge that personal data you submit for publication through our website may be accessible globally via the internet to other Users within your organizational account. We cannot prevent the use or misuse of such personal data by others.

Please note, we will never request personal data over email, text message, or chat except to initially validate your identity on support and services calls that you initiate. WE WILL NEVER REQUEST YOUR PASSWORD THROUGH ANY COMMUNICATION CHANNEL.

6.1. Enhance International Transfer Safeguards

We implement comprehensive safeguards for international data transfers as required by applicable privacy laws. For transfers from the European Economic Area, we rely on adequacy decisions where available and implement Standard Contractual Clauses (SCCs) approved by the European Commission where such laws apply. We conduct Transfer Impact Assessments to evaluate government surveillance risks and implement supplementary technical and organizational measures where necessary. For transfers from other jurisdictions, we ensure appropriate contractual protections and technical safeguards are in place to maintain data protection standards equivalent to the originating jurisdiction.

6.2. Data Inventory

We maintain a comprehensive data inventory documenting all personal data we collect, process, and store. This inventory includes data categories, sources and how it is collected, purposes, storage locations and any transformations that may occur between storage locations, retention periods, and sharing arrangements. You can access our current Data Inventory Documentation which details exactly what personal data we maintain and how it is categorized and managed.

6.3. Security Incident Management

In the event of a security breach that affects personal data, we have established comprehensive incident response procedures:

  • Immediate Response: Upon discovering a security incident, we will assess the scope and impact within 24 hours and begin containment measures immediately.
  • Client Notification: We will notify affected clients within 72 hours of becoming aware of a breach that poses a risk to personal data, providing details about the nature of the breach, data involved, and mitigation steps taken.
  • Regulatory Notification: We will notify relevant supervisory authorities within legally required timeframes (typically 72 hours for GDPR compliance).
  • Law Enforcement Cooperation: We will fully cooperate with law enforcement agencies investigating security incidents, providing necessary information and assistance while protecting user privacy to the extent legally permissible.
  • Mitigation Actions: Our incident response includes immediate containment, forensic analysis, system hardening, affected user notification, and implementation of additional safeguards to prevent similar incidents.
  • Documentation and Reporting: We maintain detailed incident logs and will provide affected clients with written incident reports including root cause analysis and remediation steps.

7. Data Governance

7.1. Data Controller and Processor

For Your personal data that is used and stored in the Services, You serve as the Controller and retain the authority over such information as documented in Section 5 of this Policy. You can manage organizational access, assign roles, modify settings, and perform actions including accessing, modifying, exporting, sharing, and removing information. As processors, we only handle your personal data as documented in this Policy, the Terms and Condition, and any other policy we have in place now or may develop in the future, as we may update them from time to time. We will handle your personal data upon Your request or when necessary according to law and for Service delivery. We function as Controller for personal data we collect as described in Section 2 and other sections of this Policy as documented.

7.2. Data Retention

We retain personal data for the minimum period necessary to accomplish purposes described in this Privacy Policy, unless a longer retention period is mandated or permitted by law. Our retention practices follow these principles:

  • Account Information: Retained for the duration of your account plus 30 days after account closure for backup purposes, then permanently deleted.
  • Usage and Analytics Data: Retained for 24 months for service improvement purposes, then anonymized or deleted, in Our discretion.
  • Customer Content: Controlled by the Customer; we retain only as long as directed by the Customer or until account closure.
  • Communication Records: Retained for 3 years for customer service and legal compliance purposes.
  • Financial and Billing Data: Retained for 7 years to comply with tax and financial record-keeping requirements.

We implement automated deletion processes to ensure data is removed according to our retention schedules without requiring manual intervention. Customers can request earlier deletion of their data, subject to legal and contractual obligations.

8. Privacy Policy Changes

We retain the right to modify this Privacy Policy at any time, with changes becoming effective immediately. You should regularly check the Website and this page for updates. We will provide email notification of any material changes to this Privacy Policy.

9. Contact Information

If you have questions or concerns about how your information is processed, please contact us at:

legal@xperius.io