Privacy Notice
Xaviour product and website · Last updated 2 September 2026
This notice explains what Xaviour collects, why, where it is processed, and what you can do about it. Part A covers the Xaviour product once you connect a Google account (Gmail and Google Calendar). Part B covers this website and Early Access registration.
Who is responsible
Xaviour AI Limited is the controller of the personal data described here.
Xaviour AI Limited — a private company limited by shares, registered in Ireland · CRO 806134
Registered office and full company details: Company Information
Privacy enquiries: privacy@xaviour.ai · General contact: christopher@xaviour.ai
Xaviour AI Limited is established in Ireland, so no EU representative under Article 27 GDPR is required. We have not appointed a Data Protection Officer.
Part A — The Xaviour product (connected Google account)
Xaviour is an AI-assisted communication system. After you sign in with Google, Xaviour asks you through Google's consent screen to grant Gmail and Google Calendar permissions. Xaviour cannot access either service until you grant those permissions. A short, reviewer-friendly summary of the Google permissions is at How Xaviour uses Google data.
Google data Xaviour accesses
Xaviour requests two Google data permissions, and nothing broader:
| Permission | What Xaviour does with it |
|---|---|
Gmail (gmail.modify) | Reads message metadata and, when a feature needs it, message content to understand conversations, prioritise what needs you, and answer your questions about your own mail. Prepares and saves drafts in your Gmail Drafts. Sends a message, applies or removes Xaviour's own labels, archives, and marks read or unread — only as actions you approve. Xaviour never permanently deletes mail; deletion has no code path in the product. |
Google Calendar (calendar.events) | Reads your primary calendar's events to show the day's commitments beside your mail. Creates an event, with attendees, only after you confirm the exact title, time and attendee list; Google then sends the invitations. |
Consequential actions — sending a message, creating a calendar event — always require your explicit confirmation of that specific action. Xaviour proposes; you decide.
What Xaviour stores
- Your Google connection: your Google account identifier and email address, the permissions you granted, and a refresh token. The refresh token is encrypted with a key that is itself wrapped by a dedicated AWS KMS key and bound to your account; access tokens are held in memory only and never written to the database.
- Message metadata: sender name and address, subject, thread and message identifiers, dates, label state (inbox, unread) and Xaviour's category for each message, refreshed on each sync.
- Xaviour's own records: the decisions and follow-ups it surfaced (subject, proposed action, its reasoning signals, your responses), rules you asked it to learn, and sender profiles built from your own mail history.
- Action ledger: every action Xaviour proposed, you confirmed, and it executed. The proposal you reviewed keeps the recipient or attendee addresses and subject you approved, so the record shows exactly what you confirmed; the execution record stores Google identifiers, timestamps and counts only.
- Usage records: counts and timings for voice features, without the audio or transcript.
What Xaviour does not persist: message bodies are fetched from Gmail when a feature needs them, used in memory, and not written to the database. Drafts exist only in your Gmail Drafts. Xaviour never receives or stores your Google password.
Where and how it is processed
The product runs on Amazon Web Services in the EU (Ireland, region eu-west-1). Its database sits in private network subnets with no route to the internet, is encrypted at rest with an AWS KMS key, and accepts only TLS connections. All traffic between you, Xaviour and Google uses HTTPS. Application credentials are held in AWS Secrets Manager and are readable only by the running service. Development and production use separate databases and separate credentials.
Who processes it for us
| Provider | Role | Where |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, encrypted PostgreSQL database, key management, secrets, application logs | EU (Ireland), eu-west-1 |
| Amazon Bedrock (AWS) — Anthropic Claude models | AI processing when model-backed features are enabled: understanding message context, answering your questions, preparing drafts. Only the bounded excerpts a feature needs are sent, with names and addresses of third parties pseudonymised first; your own composed text is sent as you wrote it. AWS states that Bedrock does not store prompts or use them to train models. | AWS Europe cross-region inference (EU regions) |
| OpenAI API | Only when you use a voice feature: transcribing your spoken request and producing spoken replies. The audio or text of that request is sent and not retained by Xaviour. Used under OpenAI's API terms, which state API inputs are not used to train their models. | OpenAI, United States, under its EU data transfer terms |
| Google (Gmail and Calendar APIs) | The source of your data; Xaviour acts on it only through the permissions you granted | Google's own terms |
No other third party receives your Google data. We do not sell it, and we do not share it with advertisers or data brokers.
Google API Services User Data Policy and Limited Use
Xaviour's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data (including Google Workspace data) is:
- used only to provide and improve the Xaviour features you see and use;
- not sold;
- not used for advertising, and not shared with advertisers or advertising platforms;
- not used to build, train or improve generalised AI or machine-learning models. AI providers process it only to produce the immediate result for your request, as described above;
- read by a human only with your explicit permission, for security or abuse investigation, to comply with law, or after it has been aggregated and anonymised.
How Xaviour uses AI
Xaviour combines deterministic rules with AI models. Where model-backed features are enabled, the model may describe a message, summarise context, answer a question from bounded excerpts, or prepare a draft. It never holds your Google credentials, has no tools, and cannot act: a deterministic policy decides what may happen, and consequential actions run only after your confirmation. AI output can be wrong or incomplete, and where you interact with an AI feature directly this is identifiable to you.
Retention and deletion
- Google connection: when you disconnect Google inside Xaviour, the product revokes its access at Google first and then destroys the stored refresh token immediately. You can also revoke Xaviour at any time from your Google Account permissions; Xaviour then cannot access anything further.
- Message metadata and Xaviour's records: kept while your account is connected so the product can work. Email privacy@xaviour.ai to have your product data erased; we handle this manually and aim to complete it within one month.
- Application logs: up to 6 months for the product, up to 3 months for this website. Logs record outcomes and identifiers, never message content.
International transfers
Product data is stored in the EU (AWS, Ireland). AI processing on Amazon Bedrock stays within AWS European regions. Voice features send that request's audio or text to OpenAI in the United States under its standard contractual clauses. AWS and Google are global providers whose support functions may involve access from outside the EEA under their transfer safeguards.
Part B — This website and Early Access registration
What we collect through this site
Only what you enter in the Early Access form, plus the records created when we handle your registration:
- Email address
- First name (optional)
- What takes your time in email (optional free text)
- Intended use: personal, business, or both
- Company name (optional, only where you indicate business use)
- Registration state (pending, accepted, invited, declined) and the related timestamps
- Founding Cohort number, if you are invited and accept a place
- Email delivery metadata, such as the Amazon SES message identifier and send time
- Ordinary security and technical logs, such as IP address, request time and outcome
Our website logs record outcomes only — never your email address, name, or what you wrote in the form.
Purposes and lawful bases
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the Xaviour product you connected, including the Google features above | Google connection, message metadata, Xaviour's records, action ledger | Performance of the Early Access agreement — Art. 6(1)(b) GDPR |
| Managing your Early Access application, including selection for the Founding Cohort | Email, name, registration state, cohort number | Steps taken at your request prior to a contract — Art. 6(1)(b) |
| Communicating with you about Early Access access and invitations | Email, name | Steps taken at your request prior to a contract — Art. 6(1)(b) |
| Product research and improvement — understanding who Xaviour is for and what problem to solve | Intended use, company name, free-text answer | Legitimate interests — Art. 6(1)(f), balanced against the limited, non-sensitive data involved |
| Security, abuse prevention and rate limiting | IP address, request logs | Legitimate interests — Art. 6(1)(f); protecting the service |
| Reliable delivery of Early Access emails, including safe retries | Email, SES message identifier, send timestamps | Legitimate interests — Art. 6(1)(f); operating a service that works |
| Marketing unrelated to your Early Access request, such as a newsletter | Email, name | Consent — Art. 6(1)(a), collected separately and never bundled |
Joining Early Access is not consent to unrelated marketing. The emails you receive by joining are limited to your Early Access request — confirmation, invitation, and setup information. If we ever send anything else, we will ask for your consent separately, with an unticked opt-in, and you can withdraw it at any time.
What we do not collect through this site
- No analytics, advertising or marketing trackers of any kind.
- No profiling and no automated decision-making producing legal or similarly significant effects.
- The website itself has no access to your mailbox or calendar. Xaviour reads your communication only after you connect a Google account inside the product, as described in Part A.
- No payment details — Early Access is free and takes no card.
- No special-category data. Please do not include sensitive details in the free-text field.
Website processors
| Provider | Role | Where |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, encrypted PostgreSQL database, application logs | EU (Ireland), eu-west-1 |
| Amazon SES (AWS) | Sending Early Access emails | EU (Ireland), eu-west-1 |
| CookieYes | Cookie consent preference management on this website | See CookieYes' own privacy information |
Nothing you type into the Early Access form is sent to an AI provider.
How long we keep website data
- Early Access registrations: retained for 24 months after your last meaningful Early Access interaction (for example your registration, a reply, or accepting an invitation), then deleted — subject to any earlier deletion request you make, and to any longer period genuinely required by law or for security purposes.
- Website logs: 3 months or less.
Security
At a high but truthful level: databases are encrypted at rest, sit in private network subnets with no route to the internet, and are not publicly reachable. Traffic is HTTPS only. Development and production data live in separate databases with separate credentials that cannot reach each other. Application credentials are held in AWS Secrets Manager, never in code. Access to records requires our own authenticated cloud identity. No system is perfectly secure, and we do not claim otherwise.
Children
Xaviour is intended for people aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, contact privacy@xaviour.ai and we will delete it.
Your rights
Under the GDPR you have the right to access your data; to have it corrected; to have it erased; to restrict processing; to object to processing based on legitimate interests; to data portability where applicable; and, where we rely on consent, to withdraw that consent at any time without affecting processing already carried out.
Email privacy@xaviour.ai and we will handle your request manually. We aim to respond within one month.
You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie), or with the supervisory authority where you live or work.
Changes
If this notice changes materially we will update the date above and, where the change affects you, tell you by email.