Privacy Policy
Effective Date: July 1, 2026
Last Updated: July 1, 2026
Version: en-US 2026-07-01
Contact: [email protected]
Controller Contact Address: Txaion LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States
This Privacy Policy explains how Txaion ("Txaion," "we," "us," or "our") collects, uses, discloses, and protects personal data when you use our websites, applications, hosted software, APIs, AI features, voice features, digital twin features, support, communications, and related services (collectively, the "Services").
This Privacy Policy is designed for a U.S. SaaS operating model, including Delaware privacy disclosure requirements, Delaware personal data privacy rights where applicable, U.S. state privacy laws, GDPR/UK GDPR practices, and international SaaS data protection expectations. It does not apply to third-party services that we do not control.
1. Roles and Scope
1.1 Txaion as Controller
Txaion acts as a controller or business when we decide how and why to process personal data, including for account registration, website operation, billing, marketing, security, analytics, product improvement, and customer support.
1.2 Txaion as Processor
For personal data contained in Customer Content that a business Customer submits to the Services, Txaion generally acts as a processor or service provider on behalf of the Customer. In that case, the Customer is responsible for its own privacy notices, lawful bases, consents, instructions, and data subject requests, and the Data Processing Addendum applies where required.
1.3 Customer Content
"Customer Content" includes prompts, files, text, images, audio, video, voice samples, digital twin materials, datasets, code, messages, metadata, and other content submitted to or generated through the Services by or for you.
2. Personal Data We Collect
Depending on your relationship with Txaion and how you use the Services, we may collect the following categories of personal data.
2.1 Account and Identity Data
Name, username, email address, phone number, organization name, role, password hash, account identifiers, authentication data, profile settings, and similar account information.
2.2 Billing and Transaction Data
Subscription plan, invoices, payment status, billing address, tax information, transaction identifiers, payment method metadata, and fraud prevention signals. Full payment card data is processed by payment processors and is not stored by Txaion unless expressly stated.
2.3 Usage and Device Data
IP address, device identifiers, browser type, operating system, referring pages, pages viewed, feature usage, API requests, logs, timestamps, approximate location, cookie identifiers, error reports, performance data, and diagnostic data.
2.4 Customer Content
Prompts, uploaded files, messages, images, documents, audio, video, voice samples, generated outputs, digital twin memory or profile materials, configuration data, and other content you provide or generate through the Services.
2.5 AI, Voice, and Digital Twin Data
When you use AI, voice, speech, likeness, or digital twin features, we may process prompts, instructions, audio recordings, speech samples, transcripts, voice embeddings, voice model settings, personality or memory data, generated media, and related metadata. Some of this data may be sensitive or biometric under certain laws, depending on how it is used.
Voiceprints, voice embeddings, face geometry, likeness templates, or similar measurements may be treated as biometric or sensitive personal data when they are used or intended to identify a specific individual. We process that data only where the feature supports it and where the required consent, authorization, notice, or other legal basis is in place.
Where legally required, biometric-related data, voiceprints, voice embeddings, likeness templates, or digital twin materials will be collected, used, retained, and deleted according to applicable notices, consents, product settings, contractual commitments, and retention requirements.
If a feature requires a separate biometric notice, voice notice, likeness release, digital twin authorization, employee notice, parental consent, or other consent flow, that notice or consent flow supplements this Privacy Policy, including the Biometric, Voice, Likeness, and Digital Twin Consent Notice where applicable. We may restrict, suspend, or disable a feature if required authorization is missing, withdrawn, disputed, or legally insufficient.
2.6 Communications Data
Support tickets, emails, chat messages, survey responses, feedback, call recordings if disclosed, marketing preferences, and other communications with Txaion.
2.7 Third-Party and Integration Data
Information from identity providers, OAuth providers, payment processors, analytics providers, referral partners, enterprise administrators, connected integrations, and third-party APIs that you authorize.
2.8 Sensitive Personal Data
We do not intentionally collect sensitive personal data unless you choose to provide it or a feature expressly supports it. Sensitive data may include precise location, government identifiers, health data, biometric data, children's data, financial account data, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, and similar information. Do not submit sensitive data unless you have all required rights and consents.
Unless Txaion signs a separate Business Associate Agreement, the Services are not intended for protected health information regulated by HIPAA. Unless Txaion expressly provides a PCI-compliant payment feature, do not submit full payment card numbers, CVV codes, or magnetic stripe data to the Services.
Where consent is required for sensitive personal data, biometric-related data, voice, likeness, or digital twin materials, the person or organization enabling the feature is responsible for obtaining and maintaining legally sufficient consent records unless Txaion expressly agrees otherwise in writing. We may request evidence of authorization and may suspend or delete materials if authorization is missing, withdrawn, or disputed.
3. Sources of Personal Data
We collect personal data from:
- You directly
- Your organization or account administrator
- Your use of the Services
- Devices, browsers, cookies, logs, and analytics tools
- Payment processors and fraud prevention providers
- Identity, OAuth, and single sign-on providers
- Third-party integrations you connect
- Public sources, business partners, or service providers where permitted by law
4. How We Use Personal Data
We use personal data for the following purposes:
- Provide, operate, maintain, and improve the Services
- Create and manage accounts, authentication, permissions, and organizations
- Process payments, invoices, taxes, renewals, refunds, and fraud prevention
- Provide AI, voice, speech, digital twin, memory, retrieval, and automation features
- Process Customer Content according to your instructions and product settings
- Provide support, troubleshooting, training, notices, and service communications
- Monitor performance, diagnose issues, prevent abuse, and secure the Services
- Enforce the Terms, Acceptable Use Policy, AI Policy, and other policies
- Personalize product experience and remember preferences
- Develop new features and improve reliability, quality, safety, and usability
- Conduct analytics, research, benchmarking, and aggregated reporting
- Send marketing communications where permitted and honor opt-out choices
- Comply with legal obligations, law enforcement requests, and regulatory requirements
- Protect rights, safety, property, users, Txaion, and the public
- Facilitate corporate transactions such as mergers, acquisitions, financings, or asset transfers
5. Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases:
- Contract: to provide the Services and manage your account
- Legitimate interests: to secure, improve, market, and operate the Services, prevent fraud, and protect rights
- Consent: for certain cookies, marketing, AI/voice uses, biometric or sensitive data where required, and optional features
- Legal obligation: to comply with law, tax, accounting, security, and regulatory obligations
- Vital interests or public interest: only where legally applicable and necessary
6. AI Training and Model Improvement
6.1 Customer Content
We do not sell Customer Content. Unless you expressly authorize otherwise in writing or through a product setting made available for that purpose, we do not use Customer Content to train, fine-tune, or improve third-party foundation models or Txaion general-purpose AI models.
Customer Content may still be processed for inference, retrieval, moderation, safety, abuse prevention, support, debugging, logging, security, and service delivery. If we offer optional model-improvement settings that use Customer Content, we will provide notices, controls, and consent or opt-out mechanisms required by applicable law and contract.
6.2 Service Improvement
We may use aggregated, de-identified, or anonymized data, usage metrics, safety signals, feedback, and evaluation data to improve reliability, quality, safety, abuse prevention, and usability of the Services. We do not attempt to re-identify de-identified or anonymized data except as permitted by law, such as to test safeguards or investigate abuse.
6.3 Human Review
Authorized personnel or contractors may review Customer Content only when reasonably necessary for support, abuse detection, safety review, security, debugging, legal compliance, or with your permission. We use access controls and confidentiality obligations for such review.
7. Cookies and Tracking Technologies
7.1 Types of Cookies
We and our service providers may use cookies, pixels, SDKs, local storage, and similar technologies for:
- Essential operations, authentication, security, and load balancing
- Preferences and settings
- Analytics, performance, and diagnostics
- Marketing, attribution, and campaign measurement where permitted
7.2 Choices
You can manage cookies through browser settings, consent banners if provided, and device controls. Disabling essential cookies may affect core functionality.
7.3 Do Not Track and Global Privacy Control
Because there is no uniform industry standard for browser "Do Not Track" signals, we do not respond to all DNT signals. Where Global Privacy Control or a similar legally recognized opt-out preference signal communicates a valid request to opt out of sale, sharing, or targeted advertising, we will honor that signal for the browser, device, or account as required by applicable law. We may also provide account-level or cookie-level preference tools where available.
7.4 Third-Party Collection
Third parties may collect information about your online activities over time and across different websites or online services when you use the Services, including analytics, security, advertising, and embedded content providers, subject to their own policies and applicable law.
8. How We Disclose Personal Data
We may disclose personal data to:
- Cloud hosting, infrastructure, storage, CDN, DNS, and security providers
- AI model, speech, transcription, translation, and media processing providers
- Payment processors, tax providers, fraud prevention services, and banks
- Analytics, product telemetry, customer support, and communications providers
- Identity, OAuth, SSO, and integration providers
- Professional advisors, auditors, insurers, and legal counsel
- Affiliates, subsidiaries, and contractors under confidentiality obligations
- Enterprise administrators and authorized users within your organization
- Law enforcement, courts, regulators, or government authorities when legally required or necessary to protect rights and safety
- Parties involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets
- Other parties with your consent or at your direction
Our current subprocessor information is described in the Subprocessor List.
9. International Data Transfers
Txaion may process and transfer personal data in the United States, Taiwan, Japan, the European Economic Area, the United Kingdom, and other countries where we or our service providers operate. These countries may have data protection laws different from your jurisdiction.
Where required, we use appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent mechanisms, data processing agreements, transfer impact assessments, security measures, and supplementary safeguards.
10. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve business records.
Retention periods vary based on data type and context:
- Account data: for the account term and a reasonable period after closure
- Billing and tax records: as required by accounting and tax laws
- Security logs: for a limited period needed for security and fraud prevention
- Customer Content: according to product settings, account deletion, contract terms, backup cycles, and legal holds
- Voice, likeness, biometric-related, and digital twin materials: according to product settings, consent status, feature requirements, contractual commitments, applicable law, and deletion or withdrawal requests where required
- Support communications: as needed for support history, support-team training, quality, and disputes
- Marketing data: until you opt out or the data is no longer needed
Backups may persist for a limited period after deletion before being overwritten, unless legal or security obligations require longer retention.
11. Security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect personal data. Measures may include encryption in transit, access controls, authentication, logging, monitoring, vulnerability management, backups, least-privilege access, vendor review, and incident response. No system is completely secure. Please review the Security Policy for additional information.
12. Privacy Rights and Choices
Depending on your location and the laws that apply, you may have rights to:
- Access personal data
- Confirm whether we process personal data
- Correct inaccurate personal data
- Delete personal data
- Receive a portable copy of personal data
- Obtain a list of the categories of third parties to which we have disclosed personal data, where applicable
- Restrict or object to processing
- Withdraw consent
- Opt out of marketing communications
- Opt out of sale, sharing, targeted advertising, or certain profiling where applicable
- Limit the use or disclosure of sensitive personal data where applicable
- Appeal a denied privacy request where applicable
- Complain to a data protection authority
To exercise rights, contact [email protected]. We may need to verify your identity and authority before fulfilling a request. If your data is controlled by a business Customer, we may refer your request to that Customer.
We will respond to verified privacy requests within the timeframe required by applicable law. We will not require you to create a new account solely to exercise privacy rights, although we may ask you to use an existing account or provide information reasonably necessary to verify your request.
For Delaware consumer requests, this generally means responding without undue delay and no later than 45 days after receipt, subject to one lawful 45-day extension when reasonably necessary. If we decline to act on a request, we will provide the reason and appeal instructions within the legally required timeframe. We generally do not require authentication for opt-out requests where applicable law prohibits it, but we may deny an opt-out request if we have a good-faith, reasonable, and documented belief that the request is fraudulent and provide the legally required notice.
If we deny a request, you may appeal by contacting [email protected] with the subject line "Privacy Appeal." Where Delaware law applies, we will respond to appeals within 60 days after receipt and, if the appeal is denied, provide an available online mechanism or other method for contacting the Delaware Department of Justice.
If we sell personal data, share personal data for cross-context behavioral advertising, or process personal data for targeted advertising where an opt-out right applies, we will provide a clear method to opt out, which may include a "Your Privacy Choices" link, browser signal handling, account settings, or another online mechanism appropriate to the Services.
If we process personal data based on consent and applicable law gives you a right to revoke that consent, we will provide a reasonably accessible revocation method. Where Delaware law applies, we will stop the consent-based processing as soon as practicable and no later than 15 days after receiving a valid revocation request, unless an exception applies.
13. U.S. State Privacy Disclosures
13.1 Delaware Residents
Where the Delaware Personal Data Privacy Act applies, Delaware residents may have rights to know, access, correct, delete, obtain a copy of personal data, opt out of sale, targeted advertising, and certain profiling, limit sensitive data uses where applicable, and receive equal treatment for exercising privacy rights.
Txaion provides this Privacy Policy to identify categories of personal data processed, purposes, categories shared with third parties, third-party categories, consumer rights, and contact information. Txaion processes personal data only as reasonably necessary, proportionate, and relevant to disclosed purposes, subject to applicable exceptions.
Delaware residents may designate an authorized agent to submit opt-out requests where permitted by law. Where Delaware law applies and we process personal data for targeted advertising or sell personal data, we will honor valid opt-out preference signals as required by law. If we know or willfully disregard that a Delaware consumer is at least 13 and under 18, we will not sell that consumer's personal data or process it for targeted advertising without consent where required by law. If your appeal is denied and Delaware law applies, you may contact the Delaware Department of Justice using the complaint mechanism it makes available, currently including [email protected].
13.2 California Residents
Where the California Consumer Privacy Act, as amended by the CPRA, applies, California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination. We do not sell personal information for money. If we engage in activities considered a "sale" or "sharing" under California law, we will provide legally required notices and opt-out mechanisms.
13.3 Other U.S. State Residents
Residents of Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, New Jersey, and other states with privacy laws may have similar rights depending on applicability thresholds and exemptions. We will honor applicable rights where legally required.
14. EEA, UK, and Swiss Users
If you are located in the EEA, UK, or Switzerland, you may have rights under GDPR, UK GDPR, or Swiss data protection law. You may contact us to exercise rights, and you may lodge a complaint with your local supervisory authority. If Txaion is required to appoint an EU or UK representative or data protection officer, we will publish the relevant contact information.
15. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13 in violation of applicable law.
The Services are intended for general audiences and are not designed primarily for children or minors.
If you believe a child under 13 has provided personal data to us, contact [email protected]. We will take appropriate steps to delete the data unless retention is legally required.
Users under the age of majority may use the Services only with permission and supervision from a parent or legal guardian where required by applicable law.
We do not knowingly use personal data to market or advertise legally restricted products to children in violation of Delaware online privacy law or similar laws. We also do not knowingly sell children's personal data or process children's personal data for targeted advertising without legally required consent. The Services are not intended to require operators to collect age information from all users unless a specific feature, law, or platform rule requires age gating or verification.
16. Marketing Communications
You may opt out of marketing emails by using the unsubscribe link or contacting us. You may still receive transactional or service messages, such as account, security, billing, and legal notices.
17. Third-Party Links and Services
The Services may contain links to third-party websites, apps, integrations, or services. We are not responsible for third-party privacy practices. Review the policies of third-party services before using them.
18. Business Transfers
If Txaion is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality and legal protections.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email, in-product notice, website notice, or other reasonable method. The updated policy will identify its effective date. Continued use after the effective date means the updated policy applies.
20. Contact
For privacy questions, requests, appeals, or complaints, contact:
Txaion Privacy
Email: [email protected]