Table of Contents

Privacy Policy

Last updated: July 27, 2026

This Privacy Policy ("Policy") describes how Metasign Inc, a company incorporated in Wyoming, United States ("Metasign," "Company," "we," "our," or "us"), collects, uses, discloses, transfers, and retains personal data in connection with Xpptx websites, applications, APIs, and related services (collectively, the "Services").

Unless a product notice, checkout page, enterprise agreement, or other written notice identifies a different controller for a specific service, Metasign Inc is the operator of the Services and the controller of personal data described in this Policy.

1. Scope

This Policy applies to personal data processed in connection with:

  • website operations, including registration, account, pricing, and legal pages;
  • account creation, authentication, and account management;
  • product workflows, including content generation, editing, and export;
  • subscription, payment, billing, and credit-ledger operations;
  • analytics, advertising measurement, session and performance analytics, and service improvement;
  • customer support, security monitoring, fraud prevention, and legal compliance.

For contact details and request channels, see Section 13 (Contact).

2. Categories of Personal Data

2.1 Data You Provide Directly

  • account data, such as email, username, and profile details;
  • authentication and identity-linkage data, including verification login data and third-party sign-in linkage data;
  • content data, including prompts, uploaded files, generated or edited presentation content, and associated metadata;
  • transaction and ledger data, including order IDs, plan type, subscription status, renewal and cancellation status, credit balances, credit usage records, and billing documents;
  • support communications and attachments you submit to us.

2.2 Data Collected Automatically

  • device and network data, such as IP address, browser, operating system, device type, locale/language, referring URL, and timestamps;
  • usage and telemetry data, such as page views, feature interactions, request/response logs, diagnostics, performance data, and conversion events;
  • interaction and session analytics, such as clicks, scrolling, navigation patterns, and technical session-replay data where enabled;
  • advertising and attribution identifiers, such as campaign parameters and conversion identifiers where enabled;
  • security and risk signals, including authentication outcomes, anti-abuse signals, anti-fraud indicators, and API/token risk events;
  • cookie and local storage data, including session state, authentication state, consent choices, and operational preferences.

2.3 Data from Third Parties

  • identity providers, including Google Identity Services, when you choose or enable Google sign-in;
  • payment processors and anti-fraud providers, including Stripe and its partners;
  • analytics, advertising, and measurement providers, including Google Analytics and Google Ads;
  • session, performance, and product-experience analytics providers, including Microsoft Clarity.

We process personal data to:

  • provide, operate, maintain, support, and improve the Services;
  • authenticate users and secure accounts;
  • process generation, editing, and export workflows;
  • process subscriptions, payments, taxes, accounting, and credit-ledger operations;
  • measure traffic, product performance, campaign attribution, and conversions;
  • understand aggregated or de-identified usage patterns and diagnose technical problems;
  • detect, investigate, and prevent abuse, fraud, unauthorized access, and security incidents;
  • provide support and service communications;
  • comply with legal obligations and enforce contractual or legal rights.

We process Input and Output to fulfill user requests and to operate, secure, support, and improve the Services. We do not publicly disclose or sell private Input or Output. Any materially different use of private Input or Output, including use to train a general-purpose AI model, will be governed by an additional product notice, setting, or agreement where required by applicable law.

Where required by applicable law, we rely on one or more of the following legal bases:

  • performance of a contract;
  • legitimate interests, such as platform security, fraud prevention, service operations, product improvement, and measurement that does not require consent;
  • consent, where legally required for specific cookies, analytics, advertising measurement, or marketing activities;
  • compliance with legal obligations;
  • establishment, exercise, or defense of legal claims.

4. Cookies and Similar Technologies

We use cookies and similar technologies, including local storage, tags, pixels, and software development tools, for session continuity, authentication, service functionality, security controls, analytics, performance measurement, advertising attribution, and conversion measurement.

These technologies may be provided by Metasign or third parties, including Google Analytics, Google Ads, Microsoft Clarity, Google Identity Services, and Stripe. Depending on configuration, they may process online identifiers, device and network data, page and interaction data, campaign parameters, and conversion events.

You may manage cookies through browser settings and, where available, consent management tools. Blocking some technologies may affect authentication, checkout, security, or other service functions.

Where required by applicable law, we obtain consent before using non-essential cookies (such as certain analytics or advertising cookies).

5. Disclosure of Personal Data

We may disclose personal data to:

  • payment and billing processors, including Stripe, to process payments, subscriptions, fraud signals, and related billing events;
  • identity providers, including Google Identity Services, when you use supported sign-in methods;
  • cloud hosting, storage, CDN, AI/content-processing, and infrastructure providers used to deliver requested features;
  • analytics, advertising-measurement, monitoring, and observability providers, including Google Analytics, Google Ads, and Microsoft Clarity;
  • customer support and communication service providers;
  • legal, compliance, audit, and professional advisors;
  • regulators, courts, law enforcement, and public authorities where required by law;
  • counterparties and advisors involved in merger, acquisition, financing, restructuring, or asset transfer transactions;
  • other parties at your direction or with your authorization.

We do not sell personal data for money. Some privacy laws define "sale," "sharing," or "targeted advertising" more broadly and may treat certain advertising-measurement disclosures as covered activities. Where those laws apply, we provide the notices and choices required by law. We do not disclose private Input or Output to third parties for their own independent advertising purposes.

6. Payment Processing (Stripe)

When you purchase a subscription or paid feature, payment processing is performed by Stripe, Inc. and its affiliates ("Stripe"), acting as our payment processor.

For card payments, your full card number, CVC/CVV, and full payment credentials are collected and processed directly by Stripe under Stripe's own technical and compliance controls. We do not store or receive full card numbers or CVC/CVV in our systems.

We may receive and process limited payment and billing data from Stripe, such as:

  • customer and payment method identifiers (for example, Stripe customer/payment method IDs);
  • card metadata (for example, brand, funding type, and last four digits);
  • billing contact details and billing country/region;
  • subscription status, invoice status, payment outcomes, and refund/chargeback events;
  • risk, fraud, and dispute-related signals provided by Stripe.

We use this data to:

  • create and manage subscriptions and invoices;
  • provide receipts, billing support, and account-level payment history;
  • detect and prevent fraud, payment abuse, and unauthorized transactions;
  • meet tax, accounting, audit, and legal obligations.

Stripe may process personal data as an independent controller for certain activities under its own privacy notice and legal obligations.

7. International Transfers, Retention, and Security

Because we use global infrastructure and vendors, personal data may be transferred to and processed in countries other than your country of residence. Where required, we implement recognized safeguards for cross-border transfers.

Retention depends on the data and why it is processed:

  • account and profile data is generally retained while the account remains active and for a reasonable period afterward for account recovery, security, dispute resolution, and legal compliance;
  • Input, uploaded files, Output, and editing data is generally retained while needed to provide the requested workflow, preserve projects or account history, or until deletion through available controls or a verified request, subject to backups and legal obligations;
  • security, diagnostic, analytics, and request logs are retained for periods reasonably necessary for security, abuse prevention, troubleshooting, measurement, and service integrity;
  • transaction, tax, accounting, subscription, and billing records are retained for periods required by financial, tax, audit, chargeback, and other applicable laws;
  • support and legal records are retained while needed to address the request, establish or defend claims, and satisfy legal duties.

When retention is no longer required, we delete, anonymize, or de-identify data in accordance with applicable law. Data removed from active systems may remain in restricted backups until those backups are overwritten under normal retention cycles.

We implement reasonable administrative, technical, and organizational safeguards, including access controls, encryption in transit where appropriate, and security monitoring. No transmission or storage method is completely secure, and you are responsible for safeguarding your credentials and API tokens/keys.

8. Your Privacy Rights and Request Handling

Subject to applicable law and permitted exceptions, you may have rights to:

  • confirm whether we process your personal data and request access;
  • request correction of inaccurate data;
  • request deletion of personal data;
  • request restriction of certain processing;
  • object to processing based on legitimate interests;
  • request data portability in a structured, commonly used format;
  • withdraw consent where processing relies on consent;
  • opt out of sale, sharing, targeted advertising, or certain profiling where applicable law grants that right;
  • appeal a denial of a privacy request, where appeal rights are required by law.

To submit a request, contact us using the channel listed in Section 13 (Contact) with sufficient information for us to locate your records. We may verify your identity, including verification of account ownership or control of the relevant email address, before fulfilling your request.

Where permitted by law, you may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and may separately verify your identity.

We respond to privacy requests within timeframes required by applicable law. Where legally required, if we deny all or part of a request, we will provide the basis for that decision and applicable appeal instructions.

9. U.S. State Privacy Disclosures

Where applicable U.S. state privacy laws apply, you may have specific rights to know/access, correct, delete, and obtain portability of personal data, and to opt out of certain processing activities where required by law.

We do not sell personal data for money. Depending on how applicable law defines sale, sharing, or targeted advertising, certain advertising-measurement technologies may fall within those definitions. Where required, you may opt out using an available consent or privacy control or by contacting us under Section 13. We do not process sensitive personal data for purposes requiring a separate opt-out right under applicable state law except as otherwise disclosed and legally permitted.

If your state law grants an appeal right, you may appeal by replying to our privacy request response or contacting us using the channel listed in Section 13 (Contact) with the subject line "Privacy Appeal." We will review and respond according to applicable legal timelines.

10. Additional Regional Privacy Disclosures

For users in jurisdictions with additional privacy requirements (including, where applicable, the EEA, UK, and Switzerland), the following also applies:

  • you may have additional rights under local law, such as the right to lodge a complaint with a competent supervisory authority;
  • where required, we process personal data under recognized legal bases and apply appropriate transfer safeguards for cross-border data transfers;
  • where consent is required under local law for specific processing activities, you may withdraw consent at any time for future processing;
  • where local law provides stronger mandatory protections than this Policy, those mandatory protections control to that extent.

11. Children's Privacy

The Services are not directed to individuals under 18 years of age, or a higher age threshold where required by local law. We do not knowingly collect personal data from individuals under the applicable minimum age in violation of applicable law.

If you believe an individual under the applicable minimum age has submitted personal data improperly, contact us using the channel listed in Section 13 (Contact). Where required, we will take reasonable steps to delete relevant data.

12. Third-Party Services and Policy Updates

The Services may include links to third-party websites, products, or services that are not controlled by Metasign. This Policy does not apply to those third-party services. Your use of third-party services is subject to their own terms and privacy policies.

We may update this Policy periodically to reflect operational, legal, or regulatory changes. When we make material changes, we will post the revised Policy with an updated "Last Updated" date and, where required by law, provide additional notice or obtain consent.

Continued use of the Services after a revised Policy becomes effective means the revised Policy applies prospectively to your continued use, to the extent permitted by law.

13. Contact

If you have questions about this Policy or want to submit a privacy request, contact:

Metasign Inc (Wyoming, United States)
Email: support@metasigncloud.com

For privacy requests, please include:

  • the email address associated with your account;
  • the type of request (for example: access, correction, deletion, restriction, objection, portability, opt-out, or appeal);
  • enough detail for us to locate relevant records;
  • if using an authorized agent, proof of authorization as required by applicable law.

We may request additional information necessary to verify your identity and authority before fulfilling privacy requests involving personal data.

14. General Provisions

This Policy is intended to work together with applicable product notices, consent notices, and region-specific disclosures.

Where applicable law provides rights or protections that are stronger than this Policy, applicable law controls to that extent.

If any provision of this Policy is held invalid or unenforceable, the remaining provisions remain in full force and effect.

Any capitalized terms not defined in this Policy have the meanings given in the Terms of Use, where applicable.