Privacy policy
Last updated: 22 August 2026
This policy describes what xich.ai collects when you use the site, the API, or the MCP server, why we collect it, and how to have it removed. Questions or requests: vic@xichai.email.
What we collect
Account details. Sign-in is handled by Auth0. When you sign in we store the identifier Auth0 gives us, your email address, the sign-in provider you used, and — where you supply them — your display name and profile picture. We record the time of your last login.
What you send the agent. Prompts, conversations, graph and lab inputs, and the answers returned to you are stored against your account so your history is available when you come back.
Usage and billing records. Per-request token counts and cost estimates, your plan and token balance, API-key metadata (a hash of the key, its prefix, label, and when it was last used), and payment records — amount, currency, processor payment id, and status.
Security and diagnostic logs. Login and login-failure events, including the IP address and user agent of the request, plus server error logs that may carry the route, status code, and a request identifier.
What we do not collect
We do not run advertising or third-party analytics trackers, and we set no advertising cookies. The only cookie we rely on is the session cookie that keeps you signed in.
We never receive your card number, bank details, crypto wallet keys, or Auth0 password — those go directly to the relevant provider.
Who we share it with
We share only what each provider needs to do its job:
- Auth0 — authentication and account identity.
- The model provider (currently DeepSeek; OpenRouter or Hugging Face when configured) — receives the prompt text needed to answer your question, and handles it under its own terms.
- NowPayments and PayPal — payment processing and subscription billing.
- Railway — hosting for the application, database, and cache.
We do not sell your data or share it with advertisers. We may disclose data where the law requires it.
How we use it
To run the service and keep your history, to meter and bill token usage, to detect abuse and debug failures, and to contact you about your account. We do not use your conversations to train models.
Retention and deletion
Account, conversation, usage, and payment records are kept while your account exists; payment records may be kept longer where tax or accounting rules require it. Security and error logs are kept for a limited period for troubleshooting.
Email vic@xichai.email to request a copy of your data or to have your account and its data deleted. Deleting your account removes your conversations and preferences; anonymised billing records may be retained as above.
Changes
If this policy changes materially we will update the date at the top of this page.
What xich.ai collects, why, who it is shared with, and how to get it deleted.