Privacy Notice

Xaviour product and website · Last updated 2 September 2026

This notice explains what Xaviour collects, why, where it is processed, and what you can do about it. Part A covers the Xaviour product once you connect a Google account (Gmail and Google Calendar). Part B covers this website and Early Access registration.

Who is responsible

Xaviour AI Limited is the controller of the personal data described here.

Xaviour AI Limited — a private company limited by shares, registered in Ireland · CRO 806134
Registered office and full company details: Company Information

Privacy enquiries: privacy@xaviour.ai · General contact: christopher@xaviour.ai

Xaviour AI Limited is established in Ireland, so no EU representative under Article 27 GDPR is required. We have not appointed a Data Protection Officer.

Part A — The Xaviour product (connected Google account)

Xaviour is an AI-assisted communication system. After you sign in with Google, Xaviour asks you through Google's consent screen to grant Gmail and Google Calendar permissions. Xaviour cannot access either service until you grant those permissions. A short, reviewer-friendly summary of the Google permissions is at How Xaviour uses Google data.

Google data Xaviour accesses

Xaviour requests two Google data permissions, and nothing broader:

PermissionWhat Xaviour does with it
Gmail (gmail.modify)Reads message metadata and, when a feature needs it, message content to understand conversations, prioritise what needs you, and answer your questions about your own mail. Prepares and saves drafts in your Gmail Drafts. Sends a message, applies or removes Xaviour's own labels, archives, and marks read or unread — only as actions you approve. Xaviour never permanently deletes mail; deletion has no code path in the product.
Google Calendar (calendar.events)Reads your primary calendar's events to show the day's commitments beside your mail. Creates an event, with attendees, only after you confirm the exact title, time and attendee list; Google then sends the invitations.

Consequential actions — sending a message, creating a calendar event — always require your explicit confirmation of that specific action. Xaviour proposes; you decide.

What Xaviour stores

What Xaviour does not persist: message bodies are fetched from Gmail when a feature needs them, used in memory, and not written to the database. Drafts exist only in your Gmail Drafts. Xaviour never receives or stores your Google password.

Where and how it is processed

The product runs on Amazon Web Services in the EU (Ireland, region eu-west-1). Its database sits in private network subnets with no route to the internet, is encrypted at rest with an AWS KMS key, and accepts only TLS connections. All traffic between you, Xaviour and Google uses HTTPS. Application credentials are held in AWS Secrets Manager and are readable only by the running service. Development and production use separate databases and separate credentials.

Who processes it for us

ProviderRoleWhere
Amazon Web Services (AWS)Hosting, encrypted PostgreSQL database, key management, secrets, application logsEU (Ireland), eu-west-1
Amazon Bedrock (AWS) — Anthropic Claude modelsAI processing when model-backed features are enabled: understanding message context, answering your questions, preparing drafts. Only the bounded excerpts a feature needs are sent, with names and addresses of third parties pseudonymised first; your own composed text is sent as you wrote it. AWS states that Bedrock does not store prompts or use them to train models.AWS Europe cross-region inference (EU regions)
OpenAI APIOnly when you use a voice feature: transcribing your spoken request and producing spoken replies. The audio or text of that request is sent and not retained by Xaviour. Used under OpenAI's API terms, which state API inputs are not used to train their models.OpenAI, United States, under its EU data transfer terms
Google (Gmail and Calendar APIs)The source of your data; Xaviour acts on it only through the permissions you grantedGoogle's own terms

No other third party receives your Google data. We do not sell it, and we do not share it with advertisers or data brokers.

Google API Services User Data Policy and Limited Use

Xaviour's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Google user data (including Google Workspace data) is:

How Xaviour uses AI

Xaviour combines deterministic rules with AI models. Where model-backed features are enabled, the model may describe a message, summarise context, answer a question from bounded excerpts, or prepare a draft. It never holds your Google credentials, has no tools, and cannot act: a deterministic policy decides what may happen, and consequential actions run only after your confirmation. AI output can be wrong or incomplete, and where you interact with an AI feature directly this is identifiable to you.

Retention and deletion

International transfers

Product data is stored in the EU (AWS, Ireland). AI processing on Amazon Bedrock stays within AWS European regions. Voice features send that request's audio or text to OpenAI in the United States under its standard contractual clauses. AWS and Google are global providers whose support functions may involve access from outside the EEA under their transfer safeguards.

Part B — This website and Early Access registration

What we collect through this site

Only what you enter in the Early Access form, plus the records created when we handle your registration:

Our website logs record outcomes only — never your email address, name, or what you wrote in the form.

Purposes and lawful bases

PurposeData usedLawful basis
Providing the Xaviour product you connected, including the Google features aboveGoogle connection, message metadata, Xaviour's records, action ledgerPerformance of the Early Access agreement — Art. 6(1)(b) GDPR
Managing your Early Access application, including selection for the Founding CohortEmail, name, registration state, cohort numberSteps taken at your request prior to a contract — Art. 6(1)(b)
Communicating with you about Early Access access and invitationsEmail, nameSteps taken at your request prior to a contract — Art. 6(1)(b)
Product research and improvement — understanding who Xaviour is for and what problem to solveIntended use, company name, free-text answerLegitimate interests — Art. 6(1)(f), balanced against the limited, non-sensitive data involved
Security, abuse prevention and rate limitingIP address, request logsLegitimate interests — Art. 6(1)(f); protecting the service
Reliable delivery of Early Access emails, including safe retriesEmail, SES message identifier, send timestampsLegitimate interests — Art. 6(1)(f); operating a service that works
Marketing unrelated to your Early Access request, such as a newsletterEmail, nameConsent — Art. 6(1)(a), collected separately and never bundled

Joining Early Access is not consent to unrelated marketing. The emails you receive by joining are limited to your Early Access request — confirmation, invitation, and setup information. If we ever send anything else, we will ask for your consent separately, with an unticked opt-in, and you can withdraw it at any time.

What we do not collect through this site

Website processors

ProviderRoleWhere
Amazon Web Services (AWS)Hosting, encrypted PostgreSQL database, application logsEU (Ireland), eu-west-1
Amazon SES (AWS)Sending Early Access emailsEU (Ireland), eu-west-1
CookieYesCookie consent preference management on this websiteSee CookieYes' own privacy information

Nothing you type into the Early Access form is sent to an AI provider.

How long we keep website data

Security

At a high but truthful level: databases are encrypted at rest, sit in private network subnets with no route to the internet, and are not publicly reachable. Traffic is HTTPS only. Development and production data live in separate databases with separate credentials that cannot reach each other. Application credentials are held in AWS Secrets Manager, never in code. Access to records requires our own authenticated cloud identity. No system is perfectly secure, and we do not claim otherwise.

Children

Xaviour is intended for people aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, contact privacy@xaviour.ai and we will delete it.

Your rights

Under the GDPR you have the right to access your data; to have it corrected; to have it erased; to restrict processing; to object to processing based on legitimate interests; to data portability where applicable; and, where we rely on consent, to withdraw that consent at any time without affecting processing already carried out.

Email privacy@xaviour.ai and we will handle your request manually. We aim to respond within one month.

You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie), or with the supervisory authority where you live or work.

Changes

If this notice changes materially we will update the date above and, where the change affects you, tell you by email.