Legal

Privacy Policy

XM Services is a creative generation platform. This policy explains what we collect, why we collect it, who processes it on our behalf and how you can control or delete it.

Last updated: 20 August 2026

1. Information we collect

Account data: your name, email address and password hash (passwords are handled by our authentication provider and never stored in plain text). If you sign in with Google, we receive your name, email and profile image.

Billing data you submit when requesting a plan: full name, email, phone, company, country, tax or VAT ID and billing address. We use this only to verify your request and issue an invoice.

Usage data: prompts, negative prompts, model and aspect-ratio choices, uploaded reference files, generated images and videos, credit transactions and generation logs (status, provider, latency and errors).

Technical data: IP address, browser and device information and error reports, used to keep the service secure and reliable.

2. How we use your information

To create and secure your account, run your generations, charge and refund credits correctly, issue invoices, provide support and investigate abuse.

To operate and improve reliability — for example, routing a request to a healthy model provider when another one is rate-limiting or failing.

To send transactional email such as email confirmation, password resets, invoices and activation confirmations. We do not sell your data or send marketing email you did not ask for.

3. Prompts, uploads and generated assets

Your prompts and any reference files you upload are sent to the AI model provider that fulfils the request, because that is technically required to generate the output.

Finished assets are copied off the provider into private storage. Only your account can read them, and downloads use short-lived signed links rather than public URLs.

We do not use your prompts, uploads or outputs to train our own models, and we do not publish your work without your permission.

4. Processors we rely on

We use third-party infrastructure and model providers to deliver the service: a managed database, authentication and storage platform, and AI model providers that carry out generation requests. Each provider receives only the data needed for its task.

These providers process data under their own terms and security controls. If you need the current list of providers for a compliance review, contact us and we will share it.

5. Retention

Account data is kept while your account is open. Generations and credit transactions are kept so your library and billing history stay accurate.

You can delete individual generations from your library at any time; deletion removes the stored asset. When you ask us to close your account, we delete your account data and assets except records we must keep for accounting and fraud-prevention purposes.

6. Security

Access to your data is enforced at the database level: every table with user data has row-level policies so one account cannot read another account's rows. Privileged operations run only on the server, never in your browser.

No system is perfectly secure. If you believe you have found a vulnerability, report it through the contact page rather than testing against other users' data.

7. Your choices

You can view and update your profile from your account page, export or delete individual generations, and request full account deletion.

Depending on where you live, you may have additional rights over your data such as access, correction, portability and erasure. Contact us and we will action valid requests.

8. Children

XM Services is not intended for anyone under 16. We do not knowingly create accounts for children, and we will delete such an account if we learn of one.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced in-app or by email, and the “last updated” date above will always reflect the current version.

Questions?

Our team answers billing, credit and policy questions directly. Reach us through the contact page or read the FAQ.