Our Core Executive Privacy Commitments
- Zero AI Model Training: We will never sell your audio recordings or use your private conversations, deals, or proprietary company insights to train public artificial intelligence models.
- Fail-Closed Privacy Gates: You have absolute authority over each piece of captured knowledge. Any item marked “Private / Never Publish” is mathematically quarantined and blocked from public distribution.
- Enterprise Encryption: All audio streams, transcripts, and account data are encrypted in transit via TLS 1.3 and stored in secure, access-controlled infrastructure.
- Full Data Portability: You can export your entire Expertise Brain (JSON/Markdown) or request permanent deletion at any time.
1. Overview
At xpScribe (“we”, “our”, or “xpScribe”), we take your privacy and proprietary executive knowledge with the utmost seriousness. Domain experts and business leaders trust us with their rawest thinking, real battle scars, and customer feedback.
This Privacy Policy explains how we collect, process, store, and safeguard your personal data and audio recordings when you use https://xpscribe.com and our associated services.
2. Information We Collect
We collect only the information strictly necessary to provide and operate the Service:
- Account & Profile Information: When you request early access or register an account, we collect your name, professional email address, job title, company name, LinkedIn profile URL, and self-described knowledge bottlenecks.
- Voice & Audio Submissions: When you record voice check-ins or upload audio files, we capture the audio recording to transcribe and extract tacit insights.
- Derived Knowledge Assets: Our processing pipeline generates text transcripts, extracted belief atoms, resonance tags, and draft distribution content tailored to your configured voice profile.
- Technical & Usage Telemetry: Log files, browser user-agent, IP address (for security authentication and rate-limiting), and anonymous feature usage data to ensure platform stability.
3. How We Use Your Information
We process your data exclusively for the following purposes:
- Transcribing your spoken thoughts into high-accuracy text.
- Extracting high-resonance “Content Atoms” and maintaining your persistent Expertise Brain.
- Drafting platform-native distribution formats (LinkedIn posts, Reddit operator contributions, 60-second video scripts, and carousel outlines).
- Enforcing your strict privacy boundary rules (Public, Anonymous, or Never Publish).
- Communicating early-access approvals, account notices, and system alerts.
4. Zero AI Training Guarantee & Enterprise Inference
The most critical differentiator of xpScribe is our commitment to IP protection:
We do not use customer data to train foundation models. When xpScribe synthesizes transcripts or generates native channel formats using frontier language models (e.g., Google Gemini or Groq Whisper transcription), we utilize commercial API endpoints bound by enterprise terms that guarantee:
- Customer prompts and audio inputs are not used for model training or tuning.
- Ephemeral processing memory is cleared following API execution.
- Zero data leakage across customer tenants.
5. Our Three-Tier Privacy Clearance Architecture
Every captured insight inside xpScribe is governed by our programmatic privacy engine:
Cleared for public thought leadership and external social sharing without redaction.
Automatically scrubs all client names, proprietary numbers, and enterprise identifiers before drafting.
Hard fail-closed gate. Strictly kept in your internal vault. Distribution engines throw a 403 error if triggered.
6. Data Sharing and Third-Party Sub-Processors
We do not sell, rent, or trade your personal information. We share data only with verified technical infrastructure providers required to operate xpScribe:
- Hosting & Serverless Compute: Vercel Inc. (San Francisco, CA)
- AI Inference & Processing: Google Cloud / Gemini API (Mountain View, CA) under enterprise commercial data protection agreements.
- Speech-to-Text Transcription: Groq Cloud (Mountain View, CA) for low-latency Whisper model inference.
- Administrative Communication: Telegram Bot API (used exclusively to send 1-tap approval alerts for waitlist reviews).
7. Security Safeguards
We employ industry-standard administrative, physical, and technical controls to safeguard your data, including TLS 1.3 cryptographic protocols for data in transit, salted cryptographic password hashing, stateless HMAC-SHA256 tokens for access verification, and restricted administrative database access.
8. Your Rights Under GDPR and CCPA
Regardless of your geographic location, xpScribe extends comprehensive data sovereignty rights:
- Right of Access: You can request a copy of all personal data and knowledge items stored about you.
- Right to Rectification: You can modify or edit any transcript, voice profile rule, or account detail at any time.
- Right to Erasure (“Right to be Forgotten”): You can request the permanent purge of your account, raw audio recordings, and extracted knowledge.
- Right to Data Portability: You can export your data in standard JSON or Markdown formats.
9. Contact the Privacy Team
To exercise your data protection rights, report a security concern, or inquire about our AI data boundaries, please reach out to:
Email: privacy@xpscribe.com
Security Response: security@xpscribe.com
Website: https://xpscribe.com