← Back to XOAI.cloud
Privacy Policy
Last Updated: January 17, 2026
Your privacy matters. XOAI LTD is committed to protecting your personal information and being transparent about how we use it across all our products.
1. Who We Are
XOAI LTD ("we", "us", or "our") operates three AI-powered platforms:
- XOCOACH.AI - AI sports coaching assistant
- XOTUTOR.AI - AI education platform in 62+ languages
- XOFIT.AI - AI wellness and fitness platform
This Privacy Policy applies to all three products and the xoai.cloud website.
We are registered in the United Kingdom (Company No. 16872288) and comply with:
- UK GDPR: General Data Protection Regulation as incorporated into UK law
- UK Data Protection Act 2018
2. Information We Collect
2.1 Account Information
When you create an account using Google, Microsoft, or Apple authentication:
- Email address: For account identification and communication
- Name: From your authentication provider
- Profile photo: If provided by your authentication provider (optional)
- User ID: A unique identifier from your authentication provider
2.2 Usage Data
We collect information about how you use our services:
- Generated content: Lessons, coaching activities, or wellness goals you create
- Feature usage: Which features you use (PDF download, audio playback, etc.)
- Login history: When you log in and device type
- Subscription status: Your current plan and usage limits
2.3 Payment Information
When you upgrade to a paid plan:
- Payment processing is handled securely by Stripe
- We NEVER see or store your full credit card number
- We retain transaction records for legal/tax purposes
2.4 Technical Data
- Browser type and version
- Device type and operating system
- IP address (for security purposes)
- Session duration
3. How We Use Your Information
- Provide and improve our services
- Generate AI-powered content for you
- Process payments and manage subscriptions
- Provide customer support
- Comply with legal obligations
4. Data Storage and Security
4.1 Where We Store Data
| Service |
Purpose |
Location |
| Google Cloud / Firebase |
Account data, generated content |
UK/EU data centers |
| Stripe |
Payment processing |
PCI-compliant infrastructure |
| Google Gemini AI |
Content generation |
No personal data sent |
4.2 Data Retention
| Data Type |
Retention Period |
| Account information |
Until account deletion |
| Generated content |
Until deleted or account closure |
| Payment records |
7 years (legal requirement) |
| Usage analytics |
2 years (anonymized) |
5. We Do NOT Sell Your Data
We do not and will never sell your personal information to third parties. Your data is used solely to provide and improve our services.
6. Your Rights Under UK GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Restrict Processing: Limit how we use your data
- Data Portability: Receive your data in a machine-readable format
- Object: Object to certain processing
- Withdraw Consent: At any time by deleting your account
How to Exercise Your Rights
7. Cookies
We use minimal cookies:
- Essential cookies: Required for login and functionality
- Authentication tokens: To keep you logged in securely
We do NOT use marketing or advertising cookies.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email.
9. Complaints
If you believe we have not handled your data properly, you can contact the UK Information Commissioner's Office:
10. Contact Us