Privacy Policy

Last updated: March 13, 2026

1. Data Controller

Xueqin Technologies
12 Rue de la Paix, 75002 Paris, France
Contact: privacy@xueqin.ai

2. Data We Collect

  • Account data: email address, name (via Clerk authentication)
  • Usage data: conversation history, queries submitted to the AI
  • Technical data: IP address, browser type, device info, cookies
  • Payment data: processed by LemonSqueezy (we do not store card details)

3. How We Use Your Data

  • To provide and maintain the Service
  • To process payments and manage subscriptions
  • To improve our AI responses and knowledge base
  • To send transactional emails (receipts, account updates)
  • To comply with legal obligations

4. Legal Basis (GDPR — EU Users)

  • Contract performance: to provide the Service you subscribed to
  • Legitimate interest: to improve our Service and prevent fraud
  • Consent: for optional marketing communications (you can opt out anytime)

5. Data Sharing

We share data only with:

  • Clerk (authentication)
  • Anthropic (AI processing)
  • Pinecone (vector database)
  • LemonSqueezy (payments)
  • Vercel (hosting)

We do NOT sell your personal data to third parties.

6. Data Retention

  • Account data: retained while your account is active, deleted within 30 days of closure
  • Conversation data: retained for 90 days, then anonymized
  • Payment records: retained for 7 years (legal obligation)

7. Your Rights (GDPR — EU Users)

You have the right to: access your personal data, rectify inaccurate data, erase your data (“right to be forgotten”), restrict processing, data portability, object to processing, and withdraw consent.

To exercise these rights, email: privacy@xueqin.ai. We will respond within 30 days.

8. Your Rights (US Users — CCPA/CPRA)

California residents have the right to: know what personal data is collected, delete personal data, opt out of the sale of personal data (we do not sell data), and non-discrimination for exercising rights.

9. Cookies

We use essential cookies for authentication and session management. No advertising or tracking cookies are used.

10. International Transfers

Your data may be processed in the United States (Vercel, Anthropic, Pinecone). We ensure appropriate safeguards through Standard Contractual Clauses (SCCs) as required by GDPR.

11. Security

We implement industry-standard security measures including encryption in transit (TLS), encrypted storage, and access controls.

12. Children

The Service is not intended for users under 16. We do not knowingly collect data from children.

13. Changes

We may update this Privacy Policy. We will notify you by email or through the Service.

14. Contact

For privacy inquiries: privacy@xueqin.ai

For GDPR complaints, you may also contact the CNIL (France): www.cnil.fr