XiuAI / Legal
Privacy Policy
Last updated: August 26, 2026
This Privacy Policy applies to the XiuAI website and all XiuAI products operated by XiuLab Inc, including XiuStore, XiuRouter, XiuBench, and official support channels. We use this one policy across the product family, regardless of where you enter.
1. Scope and operator
This policy covers XiuAI websites, sign-in services, the store, model APIs, testing and comparison features, documentation, and support conversations. XiuLab Inc operates these XiuAI services.
Payment processors, sign-in providers, model providers, and other third parties process information they directly control under their own privacy policies. This policy explains what XiuAI handles and what information must be passed to those providers to deliver the service.
2. Account and identity information
When you register or sign in, we process your email address, verification-code delivery and validation records, account status, and information needed to authenticate you. If you use Google, Apple, or another sign-in provider, we receive the account identifier, email, name, or avatar that provider returns under your authorization.
Passwords and verification codes are used to authenticate you. Do not send passwords, verification codes, or API keys through public support, social media, or unofficial channels.
3. Orders, payments, and delivery
When you use XiuStore or another transaction feature, we process product, order, amount, currency, payment channel, payment status, refund status, delivery, and support records. Payment-card details, wallet credentials, and similar information are generally handled directly by the payment provider; we receive the result and transaction identifiers needed to complete and reconcile the payment.
Some products require account identifiers, region, UID, authorization information, session information, or other details specifically requested on the page for activation or delivery. We use those details only for the relevant order, verification, delivery, support, and fraud prevention. Do not submit passwords, recovery codes, or payment details that the page does not request.
4. API requests and model data
When you use XiuRouter or another model API feature, we process API-key identifiers, selected model, request time, token or metered usage, charges, status codes, latency, errors, and routing results.
Prompts, inputs, files, and other request content are sent to the upstream provider that supplies the selected model capability so it can generate a result. We may temporarily process relevant request or response content when necessary to diagnose a problem, answer a support request, prevent abuse, or meet legal obligations. If a product screen gives a more specific notice about a particular flow, that notice describes how this policy applies to that flow.
5. Testing, comparison, and public-source data
When you use XiuBench testing or comparison features, we may process the model, service site, API address, test parameters, response results, and performance metrics you select so we can run the test and produce a report.
XiuBench also collects publicly accessible prices, products, models, and service status. Public-source data is not always personal information; if it identifies a person, we still handle it under applicable law and this policy.
6. Device, log, and analytics information
Websites, apps, and infrastructure may record IP address, browser and device type, operating system, system language, referring page, pages visited, timestamps, crashes, performance, interaction events, and logs needed to prevent fraud and protect service security.
Some public pages use website analytics and session replay to find confusing or broken interfaces. Privacy masking is enabled and recording scope is limited. These tools are not used to intentionally collect passwords, payment details, complete API content, or sensitive information you did not choose to submit.
We may use cookies, local storage, or similar technologies to maintain sign-in, save language and theme, restore a workflow, measure visits, and protect services. You can limit non-essential technologies through your browser, but some functions may stop working correctly.
7. Contact and support information
When you email us, start a support conversation, submit a ticket, or contact another official channel, we process contact details, account or order identifiers, messages, attachments, and operational records needed to resolve the issue.
To protect accounts and transactions, we may ask for enough information to verify that a request belongs to you. Support will not ask for your full password, verification code, recovery code, or complete payment credentials.
8. How we use information
We use information to create and protect accounts, provide products and APIs, complete payments and delivery, calculate usage and charges, generate test results, answer support requests, diagnose failures, prevent abuse, improve products, and meet tax, accounting, compliance, and other legal obligations.
We do not sell personal information or use personal information obtained through XiuAI services for targeted advertising unrelated to XiuAI.
9. Sharing, upstream providers, and processors
To provide the service, we may give necessary information to cloud hosting and delivery providers, model upstreams, payment and reconciliation providers, identity providers, email providers, analytics and error-diagnosis tools, support systems, and security vendors. They may process information only for the relevant task and under their contractual and security obligations.
We may also disclose information when required by law or reasonably necessary to investigate fraud or attacks, protect users and services, enforce agreements, or preserve legal rights. If the business is involved in a merger, financing, reorganization, or asset transfer, information may transfer with the business subject to applicable confidentiality and legal requirements.
10. Retention and security
Retention depends on the purpose. Account, order, payment, usage, security, and support records are kept as long as needed to provide services, reconcile accounts, resolve disputes, audit activity, prevent fraud, or meet legal obligations. Aggregated or de-identified data may be kept longer.
We use access controls, transmission protections, permission boundaries, logging, and other technical and organizational measures appropriate to the risk. No internet transmission, third-party platform, or storage system can be guaranteed completely secure.
11. Your choices and rights
You can update some account information, stop using services, limit non-essential analytics through browser controls, and avoid submitting sensitive information that is not needed to provide the service.
Where applicable law gives you these rights, you may request access to, correction of, deletion of, or export of information about you, restrict or object to certain processing, or withdraw consent-based processing. We may verify your identity to protect accounts, orders, and API assets, and may retain information required by law or needed to resolve disputes.
12. International processing
XiuLab Inc serves multiple regions and uses distributed infrastructure and global providers. Information may be processed outside your region, with contractual, access-control, or other safeguards applied as required by applicable law.
13. Minors
XiuAI services are not directed to minors who cannot provide valid consent on their own. Minors should use services only with a guardian's permission and guidance and should not independently purchase products, create API access, or submit sensitive personal information.
14. Policy changes
We may update this policy when product features, data practices, or legal requirements change. The new update date will appear on this page. Material changes will be explained through a page notice, account notice, or another appropriate channel.
Contact us
To exercise a privacy right, ask about this policy, or report a privacy concern, email contact@xiu.ai