Legal
Xebit Privacy Policy
Effective date: 2026-04-22
Introduction
Xebit Corp is a company registered in the United States (State of Delaware). We are dedicated to safeguarding personal information. This policy details how we collect, use, disclose, and protect data submitted through our websites, platform, demo sessions, and job applications. This policy complies with applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act (CCPA), and where applicable, the EU General Data Protection Regulation (GDPR) for users in the European Economic Area.
Key Definitions:
"Xebit" refers to Xebit Corp, a Delaware corporation, and its affiliates/subsidiaries.
"Personal Information" encompasses any data identifying an individual, including names, identification numbers, location data, IP addresses, and factors relating to physical, physiological, genetic, mental, economic, cultural, or social identity.
"Demo Session" refers to a live, AI-powered product demonstration conducted through the Xebit platform inside a video meeting (Google Meet, Zoom, or Microsoft Teams).
1. Limited Data Sharing
Xebit Corp shares personal information only for:
- User requests
- Processing transactions authorized by the user
- Legal disclosure requirements
- Assistance from marketing, recruiting, and service companies
- Professional advisory services
- Providing and improving the Xebit demo platform services
2. Processing Purpose and Legal Basis
The following data is collected and processed:
Website visitor data, contact details, IP address — For website provision and request responses (Legal basis: Contract performance or legitimate interests)
Demo session data (visitor name, email, meeting transcripts, browser actions, voice recordings) — For conducting and improving AI-powered product demos (Legal basis: Contract performance or legitimate interests)
Geolocation data (city, country, coordinates derived from IP) — For analytics and service optimization (Legal basis: Legitimate interests)
Transaction and communication records — For processing authorized transactions (Legal basis: Contract performance)
Contact information — For periodic product/service updates (Legal basis: User consent)
Server diagnostic data — For platform administration (Legal basis: Legitimate interests)
Job application materials — For recruitment administration (Legal basis: Pre-contract steps or legitimate interests)
All data types — For legal/regulatory compliance (Legal basis: Legal obligation)
3. Security Safeguards
Xebit Corp restricts information access to employees requiring it for job duties. The company maintains physical, electronic, and procedural safeguards complying with industry standards. Information systems and the platform undergo routine testing to prevent unauthorized access.
All demo session data, including meeting transcripts and voice recordings, is encrypted in transit and at rest. Access to session data is restricted to authorized personnel and the customer organization that initiated the demo.
4. Data Retention
Retention periods depend on:
- Query-related data: reasonable period after relationship concludes
- Demo session data (transcripts, recordings, browser actions): retained for the duration of the customer's subscription plus 30 days, unless earlier deletion is requested
- Contract/service data: duration of service delivery plus reasonable query period
- Visitor information from public demo links: retained for analytics purposes for up to 12 months
- Claims-related data: applicable legal claim period
- Regulatory requirements: as mandated by law
- Job applications: limited talent pool retention
5. International Data Transfers
Xebit Corp is headquartered in the United States, and our primary data processing occurs within the US. Personal information may also be processed in other regions through our service providers.
Service Providers and Data Processing:
Cloud Infrastructure (AWS) — United States and India — Storage, compute, and security — Customer data, demo session data, voice recordings, meeting transcripts
Meeting Bot Services (Recall.ai) — United States — Meeting bot management and real-time transcription — Meeting audio, participant information, transcripts
Voice and AI Services (OpenAI, Google) — United States — Real-time voice processing and language model inference — Voice audio streams, conversation context
Authentication (Clerk) — United States — User authentication and identity management — User credentials, organization data
For Users Outside the United States:
If you are located outside the United States, please be aware that your data will be transferred to and processed in the United States, where our servers and central database operate. The data protection laws of the United States may differ from those in your jurisdiction. By using our Services, you consent to the transfer of your data to the United States.
For users in the European Economic Area (EEA), UK, or Switzerland, Xebit Corp transfers personal data using Standard Contractual Clauses (SCCs) and applicable adequacy decisions to ensure equivalent protection levels.
6. B2B Commercial Level
Services target B2B commercial use exclusively. Consumers or those seeking non-commercial use should not register or submit personal information. Mistaken personal data collection will be deleted upon contact at legal@xebit.ai.
7. Data Collected During Demo Sessions
When a visitor launches a demo through a public demo link or an embedded widget, the following data may be collected:
- Visitor-provided information (name, email, phone, and any other fields configured by the customer)
- IP address (resolved to approximate geographic location: city, country, coordinates)
- Browser user agent and device type
- Referring website URL
- Meeting transcript (real-time speech-to-text of the demo conversation)
- Session duration and status (active, completed, missed, failed)
- Browser actions performed by the AI agent during the demo
This data is associated with the customer's organization and is accessible through the Xebit dashboard. Visitors are informed of data collection through a consent checkbox on the demo launch form, which must be accepted before proceeding.
8. User Rights and Additional Information
Feedback and Complaints:
Contact: legal@xebit.ai or written correspondence to Xebit Corp's address. Users may lodge complaints with their country's Data Protection Authority if they believe Xebit Corp violates data protection obligations.
Policy Modifications:
Changes to this policy will be posted on the website with notification via contact email, including impact explanations. Users are encouraged to review updates periodically.
Individual Rights (as applicable by jurisdiction):
- Access to held personal information
- Correction of inaccurate data
- Processing restriction or objection
- Erasure when retention is unnecessary
- Data portability in machine-readable formats
- Automated decision-making objection
- Consent withdrawal
Data Provision Notice:
Submitted personal information is necessary for service provision. Failure to provide data may prevent service access. Xebit Corp does not employ automatic decision-making or profiling for consequential decisions.
9. Marketing Communications
With consent, Xebit Corp retains names, addresses, and contact details for product/service awareness and industry updates. Recipients may object or revoke consent via unsubscribe options or by contacting the company at legal@xebit.ai.
10. Security Statement
Xebit Corp implements appropriate technical and organizational measures including encryption of data in transit (TLS) and at rest, system confidentiality protection, incident recovery capability, and regular security testing. Voice data processed through third-party AI providers (OpenAI, Google) is transmitted over encrypted connections and is not retained by those providers beyond the processing window. Only employees needing specific information access it, and all staff receive ongoing security training.
11. Google User Data and Limited Use
Xebit accesses a limited set of Google user data through the Google Workspace APIs, and only with the user's explicit consent:
- Google Calendar (read-only): upcoming event titles, times, organisers and conferencing links. Used to list meetings the user can import and to schedule an AI-run demo against one of them. Xebit never creates, modifies or deletes calendar entries.
- Google Meet (create only): creating a new Meet space for a demo session. Xebit has no access to the user's existing meetings, participants, recordings or transcripts.
Xebit's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Use of artificial intelligence: Xebit uses third-party AI services (OpenAI and Google Vertex AI) to operate its demo agent and to summarise completed sessions. Google user data is not used to develop, improve or train generalised artificial intelligence or machine learning models, whether by Xebit Corp or by any third party, and the AI providers Xebit uses do not train their models on data submitted through their APIs.
Self-hosted models: Xebit's knowledge-base search uses an embedding model that runs entirely within Xebit Corp's own infrastructure. Data processed by that model is handled locally and is never transmitted to the model's provider for training or any other secondary purpose.
12. Cookies and Analytics
Xebit Corp uses cookies and analytics tools on its website. Depending on location, users may provide consent for non-essential cookies. The Xebit dashboard uses session-based authentication via Clerk and does not use tracking cookies.
13. Third-Party Websites
This policy does not cover third-party websites linked from Xebit Corp platforms. Users bear responsibility for third-party data use and should review their privacy policies independently.
14. Contact Information
For any questions or concerns regarding this Privacy Policy, please contact us at:
Xebit Corp
Email: legal@xebit.ai
Website: https://xebit.ai

