Privacy Policy
1. Scope
This Privacy Policy explains how XInfoAI collects, uses, discloses, and protects personal information when you visit our websites, create an account, communicate with us, or use our software, agents, APIs, and related services.
XInfoAI is operated by AiYinFu Intelligent Technology (Shanghai) Co., Ltd. (Chinese registered name: 艾因孚智能科技(上海)有限公司), a company incorporated under the laws of the People’s Republic of China, with its registered address at 3rd Floor, No. 1, Lane 999, Huanke Road, China (Shanghai) Pilot Free Trade Zone, Shanghai, People’s Republic of China (“XInfoAI,” “we,” or “us”). For processing activities in which we determine the purposes and means of processing, AiYinFu Intelligent Technology (Shanghai) Co., Ltd. is the data controller. When we process personal information on behalf of a business customer, the customer generally acts as the controller and we act as its processor or service provider, subject to the applicable agreement and law.
2. Information we collect
Information you provide
We may collect account and profile information, business contact details, billing information, communications with us, product feedback, and the prompts, files, instructions, and settings you submit to the Services.
Payment information
Dodo Payments, our payment provider and merchant of record, collects payment details directly through its checkout. XInfoAI may receive customer and transaction identifiers, subscription status, plan, billing country, tax, and payment-status information, but does not receive full payment card numbers from Dodo Payments Checkout.
Information collected through use
We collect device and browser information, IP address, approximate location, log records, feature interactions, task status, usage and credit activity, diagnostic data, and cookie or similar technology data.
Information from other sources
We may receive information from services a user connects, payment and analytics providers, customer-provided records, public business sources, and licensed or otherwise authorized business-data providers. Depending on the customer’s task and available permissions, this may include company information and professional business contact information used to perform requested research or enrichment. We do not promise that every source or field is available.
Connected email account data
If you choose to connect a supported email account, XInfoAI may receive the account identifier, display name, email address, mailbox messages, replies, threads, attachments, labels or folders, and related metadata needed to identify and operate the connected mailbox. Related metadata may include message and thread identifiers, sender and recipient information, subject lines, timestamps, headers, and reply or delivery status. XInfoAI applies the same use, storage, sharing, security, retention, and deletion rules in Section 5 to connected-email data regardless of the email provider.
XInfoAI requests the Google OAuth scope gmail.send to send email from the connected Gmail account when you initiate or configure that action. XInfoAI requests the Google OAuth scope gmail.readonly to read Gmail messages, replies, threads, attachments, labels, and related metadata without modifying or deleting mailbox content. Related metadata may include message and thread identifiers, sender and recipient information, subject lines, timestamps, headers, and reply or delivery status available through Gmail.
For a connected Outlook or Microsoft 365 mailbox, XInfoAI uses delegated Microsoft Graph permissions. Mail.Send allows XInfoAI to send email as the signed-in user when you initiate or configure that action. Mail.Read allows XInfoAI to read messages, replies, threads, attachments, and related metadata without modifying or deleting mailbox content. User.Read and the openid, profile, and email scopes identify the signed-in user, and offline_access allows the connection to continue using a refresh token after the current access token expires. XInfoAI does not request permission to read or send mail from other users’ mailboxes unless that additional access is separately presented and authorized.
The exact permissions and connection method vary by provider and enabled feature. XInfoAI accesses connected-email data only after you or an authorized administrator approves the permissions presented during the applicable connection flow. Any provider-specific permission that is not described here will be disclosed before you authorize that connection.
3. How we use information
We use information to provide and personalize the Services; carry out authorized user instructions; research and organize business information; propose enrichment updates; prepare email drafts; organize available communication and task status; authenticate users; process subscriptions; deliver support; monitor performance; prevent fraud and abuse; protect our systems; improve features; communicate service updates; comply with law; and establish or defend legal claims.
The summary below describes our principal processing activities. The exact information, provider, and retention period depend on the features you choose, the instructions you provide, and applicable legal requirements.
Account, subscription, and service administration
We use account and profile details, authentication records, subscription and transaction status, support communications, and usage or credit records to create and administer accounts, provide purchased features, respond to requests, and maintain service records. Where applicable, we process this information to perform our contract with you, comply with legal obligations, and pursue legitimate interests in operating and supporting the Services. It may be shared with hosting, authentication, support, communications, and payment providers and retained while the account is active and afterward as reasonably required for legal, tax, accounting, security, and dispute-resolution purposes.
Customer Content and AI-assisted features
We process prompts, files, instructions, selected business records, connected-service data, and generated results to perform the task you request, preserve task context, provide support, secure the Services, and maintain the functionality you enable. Depending on the feature, only the portions reasonably needed for the requested result may be sent to cloud, storage, search, business-data, or AI-model providers acting on our behalf. The principal legal basis is performance of the service contract or processing on the business customer’s documented instructions; additional processing for security, legal compliance, or service reliability may rely on legal obligations or legitimate interests where permitted.
Professional business information
We may process company details and professional contact information supplied by a customer, obtained from a connected source, or available from public or licensed business sources to perform user-requested research and enrichment. Depending on the activity, the customer may be the controller and XInfoAI its processor, or XInfoAI may act as a controller for limited source management, security, legal compliance, and operation of its own business-data features. Where we act as controller, we rely on consent, contractual necessity, legal obligations, or legitimate interests in providing business-to-business services, as appropriate, after considering the individual’s rights and reasonable expectations.
Website, device, and security information
We use IP address, browser and device information, approximate location, logs, diagnostics, and security events to deliver pages, localize available content, protect accounts, detect abuse, troubleshoot errors, and understand service reliability. We rely on contractual necessity, legal obligations, consent where required, and legitimate interests in providing a secure and functional service. This information may be processed by hosting, content-delivery, security, diagnostics, and payment providers and is retained according to operational and security needs.
4. Customer data and AI processing
This section applies to Customer Content generally. Information received from Google APIs, Microsoft Graph, or another connected platform is also subject to the more specific and, where stricter, controlling limits in Section 5 and the applicable provider terms.
When a business customer uses XInfoAI to process information about prospects, suppliers, customers, or other people, the customer generally determines why and how that information is used. Subject to the applicable agreement, XInfoAI processes that information on the customer’s behalf and according to the customer’s instructions.
Customers are responsible for ensuring that imported records, connected accounts, data sources, enrichment requests, email recipients, monitoring instructions, and use of outputs have an appropriate lawful basis and comply with applicable law and third-party terms. XInfoAI is not intended for unauthorized data access, email harvesting, unsolicited mass messaging, or unlawful surveillance.
AI-assisted processing. When a requested feature uses an AI model, XInfoAI may send the minimum Customer Content and task context reasonably needed to generate the requested result to an AI-model provider acting on our behalf. We require providers to process that information only to deliver the contracted service and subject to applicable confidentiality, security, and data-use restrictions. We do not use Customer Content to train generalized or shared AI models unless the customer has expressly opted in or a separate written agreement clearly permits that use. We will provide additional notice and any legally required choice before introducing a materially different training use.
Human access and review. We do not routinely have personnel read Customer Content. Access may occur when a user expressly requests support involving specific content, when limited review is reasonably necessary to investigate abuse or a security incident, to comply with law, or to evaluate service quality using access controls and data minimization. Personnel and service providers with authorized access are subject to confidentiality and need-to-know restrictions.
AI-generated results may be incomplete, inaccurate, outdated, or similar to results provided to other users. Users must review results before relying on them or using them to communicate with or make decisions about a person. The Services are not intended to make solely automated decisions that produce legal or similarly significant effects about individuals unless that use is expressly supported by the applicable product, agreement, and law.
Requests concerning information controlled by an XInfoAI customer should normally be directed to that customer. We will assist customers with applicable requests as required by contract or law.
5. Connected services and email accounts
XInfoAI uses information received from a supported connected email provider, including Gmail, Outlook, Microsoft 365, or another provider you choose to connect, only to provide or improve user-facing connected-email features that you request or enable. XInfoAI may authenticate and maintain the mailbox connection; send user-initiated or user-configured business emails on your behalf; detect and read replies; associate replies with the relevant task, campaign, contact, or conversation; and display replies and related message information in the XInfoAI unified inbox. We may also use the data to prepare drafts, classify replies, maintain delivery and communication status, preserve task context, provide user-requested support, prevent abuse, and protect the Services. These purpose limitations apply in the same way regardless of the connected email provider.
XInfoAI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Connection credentials and token storage. When a mailbox is connected through OAuth 2.0, XInfoAI does not receive or store the mailbox password. To keep the mailbox connected, XInfoAI stores the OAuth access token and, when issued by the provider, the refresh token in access-controlled XInfoAI backend systems hosted by our cloud infrastructure providers. If a supported provider uses another connection method, XInfoAI discloses the credential required before connection and protects it using the same encryption, access-control, isolation, retention, and deletion safeguards described in this section. Connection credentials are transmitted using encrypted connections and encrypted at rest. They are logically associated with the applicable customer and mailbox, are not exposed to other customers, and are available only to authorized service components that need them to operate the connection. Human access to credential or token values is prohibited except when strictly necessary to investigate a security incident, comply with law, or provide support specifically requested and authorized by the user.
Email data processing and storage. XInfoAI does not create a permanent backup or archive of a connected mailbox. We retrieve only the messages and data needed for the enabled feature. Short-lived processing copies and operational caches are removed when processing is complete or when the cache is no longer required. To operate the unified inbox and preserve task context, XInfoAI may retain message and thread identifiers, sender and recipient information, subject lines, timestamps, headers, reply or delivery status, generated drafts, reply classifications, and the portions of message content needed for the applicable task or conversation. Email bodies and attachments are retained only when and for as long as needed to display or provide an enabled feature; attachments are not used for an unrelated purpose.
Sharing and AI processing. We may disclose the limited connected-email data needed for an enabled feature to cloud hosting, database and storage, email processing, security, customer-support, and AI-model service providers acting on our behalf. These providers may process the data only to provide the contracted service to XInfoAI. We do not sell connected-email data, use it for advertising, transfer it to data brokers or information resellers, or use it to determine creditworthiness or for lending purposes.
When an enabled feature uses artificial intelligence, only the portions of connected-email data needed to produce the requested result may be processed by an AI-model service provider. We do not permit the provider to use that data for its own purposes or to train its generalized models. XInfoAI does not use connected-email data obtained through Google Workspace APIs, Microsoft Graph, or another email provider to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
Human access. XInfoAI personnel, contractors, and service providers are not permitted to read connected-email content except when the user has expressly requested and authorized access to specific data for support, when access is necessary to investigate abuse or a security incident, or when required by applicable law. Access is limited to the data necessary for that purpose and is subject to access controls and confidentiality obligations.
Security. Connected-email data is protected using encryption in transit and at rest, least-privilege access controls, logical separation between customer accounts, restricted production access, and administrative, technical, and organizational safeguards designed to prevent unauthorized access, loss, misuse, alteration, or disclosure.
Retention, disconnection, and deletion. Connection credentials, including OAuth access and refresh tokens, are retained only while needed to maintain the mailbox connection. If you disconnect a mailbox in XInfoAI or revoke access through the controls provided by your email provider, XInfoAI stops future access and deletes the active connection credentials from its production systems. Message bodies and attachments retrieved from the provider are removed from active systems when they are no longer needed for an enabled feature or after the related mailbox, task, or conversation is deleted. Message metadata, reply and delivery status, generated drafts, classifications, and other task results may be retained while your XInfoAI account or the related task remains active so that the product can display its history and results. You may delete the related task or request deletion if you do not want this information retained.
When you close your XInfoAI account or request deletion, we delete or anonymize retained connected-email data without undue delay, except where limited retention is required by law, security needs, fraud prevention, or dispute resolution. Protected backup copies are isolated from ordinary use, are not restored except for disaster recovery, and are deleted or overwritten through the applicable backup cycle. You may request access to or deletion of retained connected-email data by contacting info@xinfoai.com. Disconnecting a mailbox may cause sending, reply-monitoring, and unified-inbox features to stop working.
8. International data transfers
XInfoAI is based in the People’s Republic of China. Depending on the feature and providers selected, XInfoAI and its service providers may process information in China and in other countries where our cloud, communications, payment, security, business-data, support, or AI-model providers operate. Those countries may have privacy laws different from the laws where you live.
Where required for an international transfer, we use recognized safeguards such as an adequacy decision, approved standard contractual clauses, a data-transfer agreement, security measures, consent, or another lawful mechanism. Where applicable, you may contact info@xinfoai.com to request information about the relevant safeguard. For personal information transferred out of China, we provide any additional notice, consent, contract, assessment, or filing required by applicable Chinese law.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described here, including providing the Services, meeting contractual commitments, maintaining security, resolving disputes, and complying with legal, tax, accounting, and audit obligations. Retention periods vary based on the type of information and how it is used.
In general, account and Customer Content are retained while the applicable account or task remains active; connected-email information follows the more specific rules in Section 5; transaction, tax, and accounting records are retained for the period required by applicable law; support and contract records are retained while needed to manage the relationship and disputes; and security logs are retained for a limited period appropriate to detecting, investigating, and documenting abuse or incidents. A customer agreement, product control, or legal hold may require a different period.
When information is no longer needed, we delete or anonymize it unless the law requires longer retention.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No online service can guarantee absolute security, so you should protect your credentials and notify us promptly if you suspect unauthorized account activity.
11. Your privacy rights and choices
Depending on where you live, you may have rights to know whether and how we process personal information; access, correct, delete, or obtain a portable copy; object to or restrict certain processing; withdraw consent; opt out of legally defined sale, sharing, targeted advertising, or qualifying profiling; limit certain uses of sensitive personal information; or appeal a decision about a request. You may also opt out of marketing messages using the link in those communications. Exercising a privacy right will not result in unlawful discrimination.
To submit a privacy request, email info@xinfoai.com with the subject “Privacy Request.” Describe the right you want to exercise, your country or state of residence, and the XInfoAI account, email address, website interaction, or business record involved. Please do not send passwords, government identification numbers, payment card details, or other unnecessary sensitive information by email.
XInfoAI does not sell personal information for money. Some laws define sale or sharing more broadly. If you believe a broader opt-out right applies to information processed by XInfoAI, identify that request in your email and we will evaluate and respond under the applicable law. We honor legally required browser-based opt-out preference signals for processing to which those signals apply.
We may ask for information reasonably necessary to verify your identity, authority, and relationship with XInfoAI. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification. We will respond within the period required by applicable law. If we deny a request, our response will explain the reason and any appeal method available to you.
If XInfoAI processes information solely on behalf of a business customer, we may direct the request to that customer and assist it as required. You may also complain to the privacy or data-protection regulator in your place of residence where applicable.
You may unsubscribe from marketing email using the link in the message. You may revoke Google or Microsoft access through the security settings of the connected account and, where available, disconnect it in XInfoAI. You can use browser controls to delete or block cookies and similar storage, although blocking technologies necessary for security or requested functionality may prevent some features from working.
12. Children
The Services are intended for business users and are not directed to children. We do not knowingly collect personal information from children below the minimum age required by applicable law. If you believe a child has provided information to us, email info@xinfoai.com so we can take appropriate action.
13. Changes to this policy
We may update this policy as our Services, practices, or legal obligations change. We will post the revised policy, update the effective date, and provide additional notice when required.
14. Contact us
Data controller and operator: AiYinFu Intelligent Technology (Shanghai) Co., Ltd. (艾因孚智能科技(上海)有限公司). Registered address: 3rd Floor, No. 1, Lane 999, Huanke Road, China (Shanghai) Pilot Free Trade Zone, Shanghai, People’s Republic of China. Privacy contact email: info@xinfoai.com. You may use this address for privacy questions, connected-email data questions, or access and deletion requests.