Privacy Policy

Last updated: July 22, 2026

1. Introduction

XEELAA ("we," "our," or "us") is an enterprise AI conversation memory platform operated by Xeelaa AI, a company registered in Nigeria under registration number 9685591, with a registered address at Abuja, Nigeria. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform, website, and related services (collectively, the "Service").

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

Contact: For privacy-related inquiries, contact us at hello@xeelaa.com or at the registered address above.

2. Scope: Account Holders and End-Users

This Privacy Policy applies differently depending on your relationship with the Service:

  • Account Holders: If you register for a XEELAA account, this Policy governs our direct relationship with you as described throughout this document.
  • End-Users of Deployed Chatbots: If you are interacting with an AI chatbot or WhatsApp integration deployed by one of our business customers, your messages and related data are processed by XEELAA on behalf of that business, which acts as the data controller for your interaction. XEELAA acts as a data processor in this context, handling data under the instructions of, and agreement with, our business customer. If you are an end-user with questions about how your data is used, please contact the business you are messaging directly. If you are unable to reach them, contact us at hello@xeelaa.com and we will direct your inquiry appropriately.

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email address, password (hashed), and avatar when you register or sign in via Google OAuth.
  • Profile Information: Display name, role, team associations, and any settings you configure.
  • Communications: Messages, conversations, and chat history with AI chatbots, including content you submit, files you upload, and voice recordings you make.
  • Training Data: Documents, URLs, and files you upload to train your chatbots.
  • API Keys: API keys you generate for programmatic access, along with usage metadata.
  • Video & Audio Content: Scripts, scenes, renders, and audio recordings you create through the Studio features.
  • Connected Account Credentials: OAuth tokens and API keys for third-party services you choose to connect (Google, Microsoft, LinkedIn, and others). These are stored encrypted.

3.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, actions performed, timestamps, and session duration.
  • Device & Connection Data: IP address, browser type and version, operating system, referring URLs, and device identifiers.
  • Cookies & Tracking: Session cookies for authentication, preference cookies, and, where configured by an administrator, a Facebook Pixel for analytics and advertising.
  • Performance Data: API response times, error logs, and queue processing metrics.

3.3 Information from Third Parties

  • Google OAuth: When you sign in with Google, we receive your name, email address, and Google profile ID.
  • Connected Services: When you connect third-party services (Google Drive, Gmail, LinkedIn, and others), we access data as permitted by the OAuth scopes you authorize.
  • Web Search: When you use web search features, queries are processed through DuckDuckGo or Google Custom Search.

4. How We Use Your Information

  • To provide and maintain the Service: Including AI chat responses, memory retrieval, file processing, video generation, and action execution.
  • To improve AI responses: Conversation history is used to generate contextually relevant replies through semantic memory retrieval.
  • To process and store embeddings: Messages and documents are converted to vector embeddings and stored for similarity search.
  • To build and maintain your chatbot's knowledge base: From uploaded documents and URLs.
  • To manage your account: Authentication, API key management, usage tracking, and tier enforcement.
  • To execute actions: Connected service credentials are used to perform actions you request through connected third-party services.
  • To maintain security: Monitoring for abuse, enforcing rate limits, and protecting against unauthorized access.
  • To communicate with you: Service announcements, password resets, and support responses.
  • For analytics: Where Facebook Pixel is configured by an administrator.

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • With AI Providers: Messages are sent to AI model providers (such as OpenAI or DeepSeek) to generate responses. When using locally-hosted models, no data leaves your infrastructure.
  • With Third-Party Services You Connect: When you authorize connections to services like Google Drive, LinkedIn, or Slack, we transmit data as necessary to fulfill your requests.
  • With Service Infrastructure Providers: Including database, caching, and cloud hosting providers used to operate the Service.
  • With Analytics Providers: Facebook Pixel, where configured by an administrator.
  • For Legal Reasons: If required by law, regulation, or legal process, or to protect our rights and the safety of our users.
  • With Your Consent: For any other purpose you explicitly agree to.

6. Data Storage and Security

  • Encryption: OAuth tokens, API keys, and sensitive credentials are encrypted at rest. Passwords are hashed using industry standard methods.
  • Data Storage: Data is stored using industry-standard relational and cache databases, including vector storage for semantic search.
  • File Storage: Uploaded files, generated documents, and media are stored on secured local or cloud storage.
  • Security Measures: We implement security headers, rate limiting, CSRF protection, session timeout, IP whitelisting for API keys, and periodic security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Data Retention and Deletion

  • Account Data: Retained until you delete your account or request deletion.
  • Conversation History: Retained to provide context for AI responses. You may delete individual conversations or all history at any time.
  • API Usage Logs: Retained for up to 90 days for audit and billing purposes.
  • Backup Retention: Encrypted backups may be retained for up to 30 days after deletion.
  • Requesting Deletion: Contact hello@xeelaa.com to request deletion of your data. We will respond within 30 days.

8. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal obligations.
  • Portability: Request export of your data in a structured, machine-readable format.
  • Objection: Object to processing of your data for specific purposes.
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Opt-Out of Tracking: Where Facebook Pixel is configured, opt out via your Facebook ad preferences.

To exercise any of these rights, contact us at hello@xeelaa.com.

9. Cookies

We use essential, preference, and (where configured) analytics cookies. See our Cookie Policy for full details, including specific cookies, durations, and how to manage them.

10. Third-Party Services

The Service integrates with third-party providers across the following categories, each governed by its own privacy policy:

AI & Language: OpenAI, DeepSeek
Cloud & Infrastructure: Database, caching, cloud hosting
Google Services: OAuth, Gmail, Drive, Calendar, Docs, Sheets, Slides, Tasks, Meet, YouTube
Microsoft 365: Outlook, OneDrive, Teams, Excel, Word, PowerPoint
Social Media: LinkedIn, X/Twitter, Facebook, Instagram, TikTok
Communication: Slack, Discord, WhatsApp, Telegram
Business: Shopify, WooCommerce, Stripe, PayPal, HubSpot, Salesforce, Zendesk
Productivity: Notion, Jira, Trello, Asana, Confluence
Development: GitHub, GitLab
Search: DuckDuckGo, Google Custom Search
Analytics: Facebook Pixel (where configured)

We encourage you to review each provider's privacy policy before connecting a third-party account.

11. Children's Privacy

The Service is not intended for individuals under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it. Contact us if you believe a child has provided us with personal data.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including where our infrastructure providers and AI model providers operate. By using the Service, you acknowledge this transfer. We take appropriate safeguards, such as standard contractual clauses where applicable, to protect your data in accordance with this Privacy Policy and applicable law.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date, and, where appropriate, via email or through the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

For European Union users: You have the right to lodge a complaint with your local data protection authority.