What this policy covers
This Privacy Policy applies to personal data processed when a visitor browses the public site, creates an account, signs in, purchases credits, uses the customer console, opens a support ticket, or sends traffic through customer-facing XVAPI request paths.
It is scoped to the current live product. It does not treat undeployed ideas, private back-office experiments, or unpublished operational tooling as part of the public privacy contract.
Information we may collect
We may collect account information such as email address, sign-in method, profile fields, verification state, account status, and API key metadata required to operate customer access and account security.
We may collect billing and operational records such as wallet balance changes, order references, payment event identifiers, support-ticket content, request logs, rate-limit events, fraud or abuse signals, IP address, user agent data, and request timing information.
How information is used
Personal data may be used to provide access to the service, manage authentication, issue and control API keys, operate the prepaid wallet, settle usage charges, answer support requests, investigate abuse, and preserve system integrity.
We also use data for operational diagnostics, risk review, request-level billing traceability, payment reconciliation, dispute handling, and security monitoring where reasonably necessary to protect the platform and its users.
Payments, wallet records, and billing evidence
When you interact with billing features, we may process wallet entries, payment references, order identifiers, adjustment records, reconciliation data, and other bookkeeping details required to keep customer balances accurate and supportable.
We do not disclose private merchant credentials, provider secrets, or confidential provider-side verification data in public user-facing surfaces, but we may process those systems server-side as part of payment operations.
Retention and deletion posture
We retain account, billing, request, and support records for as long as reasonably necessary to operate the service, preserve auditable billing history, investigate disputes or abuse, maintain security, and satisfy applicable legal or accounting obligations.
Retention periods may vary by data category. Browser-local storage periods used by the site are described separately in the Cookie Policy and may also be shortened by user-side deletion actions.
User choices and privacy requests
You may review or update certain account information through the customer console where that functionality is currently exposed. You may also clear cookies or local storage through browser settings, although clearing necessary storage may interrupt sign-in or verification flows.
Privacy-related questions or requests should be submitted through ops@xvapi.com or the official support workflow and should include enough detail to identify the account and evaluate the request responsibly.
Security posture and policy boundaries
We apply account security, access control, request logging, and operational review mechanisms intended to reduce unauthorized access, billing disputes, and platform abuse. No online system can promise absolute security, but the service is designed to keep customer-impacting workflows reviewable and controlled.
This policy describes the public handling posture of the current service. It should not be interpreted as a public disclosure of hidden routing logic, confidential infrastructure details, or private incident response methods.
Policy updates
We may update this Privacy Policy as the product, legal requirements, billing flows, support processes, or operational systems evolve.
When material changes affect the public data-handling posture, the revised policy should be published through the site or another customer-facing notice mechanism.
