Skip to content

Privacy Policy

XOXO Systems
effective September 3, 2026
english (en)

This Privacy Policy explains how XOXO Systems, Inc. (“XOXO,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with our websites, applications, APIs, Model Context Protocol (“MCP”) servers and clients, integrations, dashboards, documentation, and related software, products, and solutions (collectively, the “Services”).

This Policy applies to visitors, account holders, and other individuals who interact with us. Individual XOXO products may also publish product-specific notices. Those notices control that product’s collection, use, retention, and sharing practices to the extent they conflict with this Policy.

If you use the Services to process personal information about other people (for example, data in systems you connect, files you upload, or content processed by agents), that information is governed by the Data Processing Agreement and your Consumer Terms or Enterprise Service Agreement, not by the controller practices described in most of this Policy. See Section 2.

1. Who we are

XOXO Systems, Inc. is a Delaware corporation with offices at 801 International Pkwy STE 550143, Flower Mound, TX 75022, USA.

Questions about this Policy: legal@xoxo.systems.

2. Scope and roles

2.1 When we are a controller. We act as a controller (or “business” under some U.S. laws) for personal information we collect about you to operate our company and the Services themselves. That includes account and billing information, communications with us, website and product telemetry, and similar information described in Section 3.

2.2 When we are a processor. We act as a processor (or “service provider”) for personal information that you or your organization submit to, or instruct us to retrieve into, the Services (“Customer Content”). Customer Content includes prompts, files, connected-system data, MCP payloads, agent Inputs and Outputs, and similar material you make available. We process Customer Content only to provide, maintain, secure, and support the Services for you, as described in the DPA. This Policy does not let us use Customer Content for our own independent purposes, including advertising or training generally available AI models.

2.3 Product-specific terms. Fees, plan structure, metering, and retention are determined at the product level. A product’s terms, pricing page, or in-product disclosures control those commercial details if they conflict with this Policy.

3. Personal information we collect

The information we collect depends on how you use the Services.

3.1 Information you provide.

  • Identity and contact data: name, email address, username, organization, role, and similar identifiers when you create an account, join a workspace, or contact us.
  • Account credentials: passwords, API keys, tokens, and MCP connection settings you configure. We store secrets using industry-standard protections; we do not use them except to provide the Services you requested.
  • Billing data: plan selections, invoices, and limited payment metadata. Full payment card numbers are collected by our payment processor, not stored by XOXO.
  • Communications: messages you send to support, sales, or legal, including attachments.
  • Customer Content: Inputs, Outputs, files, connected data, and other content you choose to submit or connect. You control what you put in the Services.

3.2 Information collected automatically.

  • Usage Data: technical logs, device and browser type, IP address, approximate location derived from IP, referring URLs, feature usage, performance metrics, error reports, and authentication metadata. Usage Data excludes the substance of Customer Content.
  • Cookies and similar technologies: as described in Section 8.

3.3 Information from others.

  • Connected Systems: if you connect a third-party account, warehouse, API, MCP server, or similar source, we receive the data that connection is configured to provide.
  • Organization administrators: if you join a company workspace, an administrator may provide your name, email, and role, and may later control or claim the account.
  • Vendors and partners: payment processors, identity providers, and similar vendors may send us confirmation that a transaction or login succeeded.
  • Public or commercial sources: limited professional contact data if you ask us about the Services.

3.4 Sensitive information. We do not request sensitive personal information to create an account. The Services are not designed for Restricted Data described in Section 15. If you include sensitive information in Customer Content, you do so at your own risk and remain responsible for having a lawful basis.

We do not collect all of the above from every person. Visitors who only browse the public site typically generate Usage Data and cookie data. Account holders generate more.

4. How we use personal information

We use personal information to:

  • provide, operate, maintain, and support the Services you request, including generating Outputs and performing Actions you authorize;
  • create and secure accounts, authenticate users, and enforce Plan Limits;
  • process payments, prevent fraud, and keep billing records;
  • communicate about the Services, including transactional notices, security alerts, and (where permitted) product updates;
  • monitor reliability, debug, and improve security and performance, using Usage Data and de-identified or aggregated information;
  • protect the Services, our users, and the public, including investigating abuse, security incidents, and violations of our terms;
  • comply with law, legal process, and government requests; and
  • enforce our agreements and establish, exercise, or defend legal claims.

We do not use Customer Content to train, improve, or develop generally available AI models or services. Processing Customer Content to generate Outputs and perform Actions for you, and a provider’s processing for safety, security, or legal compliance, is not training.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

5. Legal bases (EEA, UK, and Switzerland)

If European data protection law applies, we process personal information on these bases:

  • Contract: to provide the Services you requested and to perform our agreement with you.
  • Legitimate interests: to secure and improve the Services, prevent abuse, understand how features are used, and communicate about products you already use, where those interests are not overridden by your rights.
  • Consent: where we ask for it, including certain cookies or optional marketing. You may withdraw consent at any time.
  • Legal obligation: to keep records, respond to lawful requests, and meet other legal duties.

When we act as a processor, the customer is responsible for the legal basis for Customer Content.

6. How we share personal information

We share personal information with:

  • Service providers and subprocessors that host infrastructure, process payments, send email, provide customer support tools, or run models and related AI inference, solely to provide the Services. They may process data only on our instructions, except where they independently process it for safety, security, or legal compliance.
  • AI and model providers when you use AI, agent, or MCP features. Relevant Customer Content is sent as needed to generate Outputs and perform Actions. Those providers are not permitted to use that content to train generally available models.
  • Your organization if you use a work email or join a company workspace. Administrators may access, monitor, or transfer your account as described in our terms.
  • Other users you designate, such as workspace members or people you share Outputs with.
  • Professional advisers (lawyers, accountants, insurers) under confidentiality.
  • Authorities when we believe disclosure is required by law, necessary to protect rights or safety, or needed to investigate abuse.
  • A buyer or successor if we are involved in a merger, acquisition, financing, or sale of assets. We will require the recipient to honor this Policy or give you notice.

We may disclose de-identified or aggregated information that cannot reasonably identify you.

We do not disclose personal information to data brokers. We do not use Customer Content for third-party advertising.

A current description of subprocessor categories is in the DPA. You may request a then-current list of subprocessors that process Customer Content by emailing legal@xoxo.systems.

7. AI, agents, MCP, and connected systems

The Services may include artificial intelligence, agents, automations, and MCP interfaces. If you enable those features:

  • we process Inputs you provide or that the Services retrieve from Connected Systems you authorize;
  • we may send relevant data to subprocessors and model providers to generate Outputs and perform Actions, including reading from or writing to systems, sending messages, and calling tools;
  • you are responsible for the permissions you grant, the systems you connect, and reviewing Actions before relying on them;
  • connected third parties process data under their own terms and privacy policies; and
  • automated systems, agents, and MCP clients you authorize count as your use of the Services.

We do not control third-party MCP servers, models, or tools you bring (including your own API keys). Those providers’ practices apply to their services.

8. Cookies and similar technologies

We use cookies, local storage, pixels, and similar technologies to:

  • keep you signed in and protect accounts (essential);
  • remember preferences (functional); and
  • understand how the public site and product are used (analytics), where enabled.

You can control cookies through your browser. Blocking essential cookies may prevent the Services from working. Where required by law, we will request consent before setting non-essential cookies.

We honor legally required opt-out preference signals, including the Global Privacy Control (GPC), as a request to opt out of “sale” or “sharing” of personal information as those terms are defined under applicable U.S. state law. Because we do not sell or share personal information for cross-context advertising, those signals confirm our existing practice.

9. Retention

We retain personal information only as long as needed for the purposes in this Policy, including to provide the Services, comply with law, resolve disputes, and enforce agreements.

Account and billing records are typically kept for the life of the account and a commercially reasonable period afterward as required for tax, accounting, and legal purposes.

Customer Content retention, including logs, telemetry, stored files, and similar data, is a product-specific Plan Limit. After the applicable retention period, we may delete that data. The Services are not an archival product. Export anything you need to keep.

Usage Data is retained for as long as reasonably needed to operate, secure, and improve the Services, then deleted or de-identified.

When we delete information, residual copies may remain in backups for a limited period until those backups cycle, and we may retain information when required by law or needed to prevent abuse.

10. Security

We use commercially reasonable administrative, technical, and physical measures designed to protect personal information. No method of transmission or storage is completely secure. You are responsible for credentials, Connected System permissions, agent settings, and MCP tool grants under your control.

If we become aware of a security incident affecting personal information we hold, we will notify affected customers or individuals as required by law and our agreements.

11. International transfers

XOXO is based in the United States. Personal information may be processed in the United States and in other countries where we or our subprocessors operate. Those countries may have data-protection laws different from the laws of your country.

Where required, we use appropriate transfer mechanisms, including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and similar Swiss terms, as described in the DPA.

12. Your rights

Depending on where you live, you may have the right to:

  • access personal information we hold about you;
  • correct inaccurate information;
  • delete information;
  • receive a portable copy;
  • object to or restrict certain processing;
  • withdraw consent; and
  • lodge a complaint with a supervisory authority.

To exercise these rights for information we control, email legal@xoxo.systems. We may need to verify your identity. If we deny a request, you may appeal by replying to our decision and stating that you are appealing.

Customer Content. If we process your information only as a processor for a customer (for example, because your employer uses the Services), we will direct you to that customer. We will assist the customer as required by the DPA.

These rights are not absolute. We may decline a request where an exception applies, including where information is needed to provide the Services, comply with law, or prevent fraud or abuse.

13. Additional U.S. state privacy information

This Section applies to residents of California, Texas, and other U.S. states with similar consumer privacy laws, to the extent those laws apply to us.

13.1 Categories collected. In the past 12 months we may have collected the categories in Section 3: identifiers; commercial information (plan and billing metadata); internet or electronic network activity (Usage Data); approximate geolocation from IP address; professional information (role and organization); and inferences drawn from Usage Data to understand product use. Customer Content may include any category you choose to submit.

13.2 Sources and purposes. Sources are described in Section 3. Purposes are described in Section 4.

13.3 Disclosure. We disclose personal information to service providers and the other parties in Section 6 for business purposes. We do not sell personal information and have not sold it in the past 12 months. We do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, other than as needed to provide the Services you requested.

13.4 Retention. See Section 9.

13.5 Rights. Subject to verification and exceptions, you may request to know, access, correct, delete, or obtain a portable copy of personal information, and to opt out of sale, sharing, or targeted advertising. You may use an authorized agent. We will not discriminate against you for exercising your rights.

13.6 Shine the Light. California Civil Code § 1798.83 does not apply because we do not disclose personal information to third parties for their direct marketing.

13.7 Texas. Texas residents may exercise rights under the Texas Data Privacy and Security Act by contacting us as described in Section 12. You may appeal a refusal as described there. You may also contact the Texas Attorney General.

14. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. You must be at least 13 to use the Services. If you are under 18 (or the age of majority where you live), you may use the Services only with a parent or guardian’s consent, as described in our terms.

If you believe we have collected information from a child under 13, contact legal@xoxo.systems. We will delete it.

15. Restricted data

The Services are not designed for data subject to heightened regulatory regimes, including:

  • protected health information under HIPAA;
  • payment card data protected by PCI-DSS; and
  • nonpublic personal information under the Gramm-Leach-Bliley Act.

Do not submit that data. We do not offer a HIPAA business associate agreement. You assume all risk if you submit biometric identifiers, precise geolocation, genetic data, or health-related data.

16. Third-party sites and services

The Services may link to, or integrate with, third-party websites, models, payment processors, identity providers, and Connected Systems. Their privacy practices are not covered by this Policy. Review their policies before using them.

17. Changes

We may update this Policy by posting a revised version and updating the effective date, or by providing notice through the Services or email. Material changes will be effective no sooner than 30 days after notice, except that changes required by law or to address an imminent security or abuse issue may take effect immediately. Continued use after the effective date constitutes acceptance. If you do not agree, stop using the Services.

If you have an Order Form with a fixed term of twelve (12) months or longer, material changes to how we process Customer Content as a processor instead take effect as described in the DPA and the Enterprise Service Agreement.

18. Contact

XOXO Systems, Inc.
Attn: Legal / Privacy
801 International Pkwy STE 550143
Flower Mound, TX 75022
United States

Email: legal@xoxo.systems

EEA, UK, and Swiss individuals may also contact their local supervisory authority. For processor issues involving Customer Content, contact the organization that provided your information to the Services.


xoxo systems

ⓒ 2026 XOXO Systems, Inc.
All rights reserved.

Privacy Policy Terms of Service: Consumer Terms of Service: Enterprise Data Processing Agreement