Last updated: July 27, 2026
This Privacy Policy ("Policy") describes how Metasign Inc, a company incorporated in Wyoming, United States ("Metasign," "Company," "we," "our," or "us"), collects, uses, discloses, transfers, and retains personal data in connection with Xpptx websites, applications, APIs, and related services (collectively, the "Services").
Unless a product notice, checkout page, enterprise agreement, or other written notice identifies a different controller for a specific service, Metasign Inc is the operator of the Services and the controller of personal data described in this Policy.
This Policy applies to personal data processed in connection with:
For contact details and request channels, see Section 13 (Contact).
We process personal data to:
We process Input and Output to fulfill user requests and to operate, secure, support, and improve the Services. We do not publicly disclose or sell private Input or Output. Any materially different use of private Input or Output, including use to train a general-purpose AI model, will be governed by an additional product notice, setting, or agreement where required by applicable law.
Where required by applicable law, we rely on one or more of the following legal bases:
We use cookies and similar technologies, including local storage, tags, pixels, and software development tools, for session continuity, authentication, service functionality, security controls, analytics, performance measurement, advertising attribution, and conversion measurement.
These technologies may be provided by Metasign or third parties, including Google Analytics, Google Ads, Microsoft Clarity, Google Identity Services, and Stripe. Depending on configuration, they may process online identifiers, device and network data, page and interaction data, campaign parameters, and conversion events.
You may manage cookies through browser settings and, where available, consent management tools. Blocking some technologies may affect authentication, checkout, security, or other service functions.
Where required by applicable law, we obtain consent before using non-essential cookies (such as certain analytics or advertising cookies).
We may disclose personal data to:
We do not sell personal data for money. Some privacy laws define "sale," "sharing," or "targeted advertising" more broadly and may treat certain advertising-measurement disclosures as covered activities. Where those laws apply, we provide the notices and choices required by law. We do not disclose private Input or Output to third parties for their own independent advertising purposes.
When you purchase a subscription or paid feature, payment processing is performed by Stripe, Inc. and its affiliates ("Stripe"), acting as our payment processor.
For card payments, your full card number, CVC/CVV, and full payment credentials are collected and processed directly by Stripe under Stripe's own technical and compliance controls. We do not store or receive full card numbers or CVC/CVV in our systems.
We may receive and process limited payment and billing data from Stripe, such as:
We use this data to:
Stripe may process personal data as an independent controller for certain activities under its own privacy notice and legal obligations.
Because we use global infrastructure and vendors, personal data may be transferred to and processed in countries other than your country of residence. Where required, we implement recognized safeguards for cross-border transfers.
Retention depends on the data and why it is processed:
When retention is no longer required, we delete, anonymize, or de-identify data in accordance with applicable law. Data removed from active systems may remain in restricted backups until those backups are overwritten under normal retention cycles.
We implement reasonable administrative, technical, and organizational safeguards, including access controls, encryption in transit where appropriate, and security monitoring. No transmission or storage method is completely secure, and you are responsible for safeguarding your credentials and API tokens/keys.
Subject to applicable law and permitted exceptions, you may have rights to:
To submit a request, contact us using the channel listed in Section 13 (Contact) with sufficient information for us to locate your records. We may verify your identity, including verification of account ownership or control of the relevant email address, before fulfilling your request.
Where permitted by law, you may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and may separately verify your identity.
We respond to privacy requests within timeframes required by applicable law. Where legally required, if we deny all or part of a request, we will provide the basis for that decision and applicable appeal instructions.
Where applicable U.S. state privacy laws apply, you may have specific rights to know/access, correct, delete, and obtain portability of personal data, and to opt out of certain processing activities where required by law.
We do not sell personal data for money. Depending on how applicable law defines sale, sharing, or targeted advertising, certain advertising-measurement technologies may fall within those definitions. Where required, you may opt out using an available consent or privacy control or by contacting us under Section 13. We do not process sensitive personal data for purposes requiring a separate opt-out right under applicable state law except as otherwise disclosed and legally permitted.
If your state law grants an appeal right, you may appeal by replying to our privacy request response or contacting us using the channel listed in Section 13 (Contact) with the subject line "Privacy Appeal." We will review and respond according to applicable legal timelines.
For users in jurisdictions with additional privacy requirements (including, where applicable, the EEA, UK, and Switzerland), the following also applies:
The Services are not directed to individuals under 18 years of age, or a higher age threshold where required by local law. We do not knowingly collect personal data from individuals under the applicable minimum age in violation of applicable law.
If you believe an individual under the applicable minimum age has submitted personal data improperly, contact us using the channel listed in Section 13 (Contact). Where required, we will take reasonable steps to delete relevant data.
The Services may include links to third-party websites, products, or services that are not controlled by Metasign. This Policy does not apply to those third-party services. Your use of third-party services is subject to their own terms and privacy policies.
We may update this Policy periodically to reflect operational, legal, or regulatory changes. When we make material changes, we will post the revised Policy with an updated "Last Updated" date and, where required by law, provide additional notice or obtain consent.
Continued use of the Services after a revised Policy becomes effective means the revised Policy applies prospectively to your continued use, to the extent permitted by law.
If you have questions about this Policy or want to submit a privacy request, contact:
Metasign Inc (Wyoming, United States)
Email: support@metasigncloud.com
For privacy requests, please include:
We may request additional information necessary to verify your identity and authority before fulfilling privacy requests involving personal data.
This Policy is intended to work together with applicable product notices, consent notices, and region-specific disclosures.
Where applicable law provides rights or protections that are stronger than this Policy, applicable law controls to that extent.
If any provision of this Policy is held invalid or unenforceable, the remaining provisions remain in full force and effect.
Any capitalized terms not defined in this Policy have the meanings given in the Terms of Use, where applicable.