Privacy Policy
Last updated: February 16, 2026
1. Introduction
Xylo4AI ("we", "our", or "us") operates the Nex-Gen BI analytics platform at analytics.xylo4ai.com. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
We collect information that you provide directly to us:
- Account Information: When you sign in via Google OAuth, we receive your name, email address, and profile picture.
- Uploaded Data: Files (CSV, Excel) you upload for analysis. Your data is stored securely and used solely for providing analytics services to you.
- Usage Data: Queries you submit, charts generated, and interaction logs to improve our service.
- Device Information: Browser type, IP address, and device identifiers collected automatically.
3. How We Use Your Information
- To provide, maintain, and improve the Nex-Gen BI analytics platform.
- To authenticate your identity and manage your account.
- To process and analyze data you upload, using AI models to generate insights, charts, and reports.
- To communicate with you about service updates, security alerts, and support.
- To detect, prevent, and address technical issues and security threats.
4. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest.
- Secure cloud storage with Cloudflare R2.
- JWT-based authentication with secure token handling.
- Data isolation — your files are only accessible to your authenticated account.
5. AI Processing
When you submit a query, we use third-party AI models (OpenAI) to generate SQL queries and analytical insights. Only the minimum necessary data — table schemas and small data previews — is sent to the AI model. Your full dataset is never sent to any AI provider. All SQL execution happens locally on our servers using DuckDB.
6. Data Sharing
We do not sell, trade, or rent your personal information. We may share information only in the following circumstances:
- Service Providers: Third-party services that help us operate (cloud hosting, AI models) under strict data processing agreements.
- Legal Requirements: When required by law, regulation, or legal process.
- Safety: To protect the rights, property, or safety of our users and the public.
7. Data Retention
We retain your data for as long as your account is active. You may delete your uploaded files at any time through the dashboard. Upon account deletion, all associated data is permanently removed within 30 days.
8. Your Rights
You have the right to:
- Access the personal information we hold about you.
- Request correction or deletion of your personal data.
- Withdraw consent for data processing at any time.
- Export your data in a portable format.
9. Cookies
We use essential cookies and local storage for authentication (JWT tokens) and session management. We do not use third-party tracking cookies or advertising trackers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Xylo4AI
Email: support@xylo4ai.com
Website: analytics.xylo4ai.com
© 2026 Xylo4AI. All rights reserved.
Terms of Service →