Privacy Policy
This policy explains what personal information xRLive collects, what we use it for, who we share it with and how, and the measures we take to keep it safe. It covers the xRLive desktop application, the websites at xrlive.tv and xrlive.app, the account dashboard and the API behind them (together, the Services).
1. Who we are
xRLive builds a real-time generative visuals engine for live events. In this policy xRLive, we and us mean the xRLive team, which is the data controller for the personal information described here.
For any privacy question, request or complaint, write to admin@xrlive.tv, or by post:
xRLive100 S Eola Dr, Suite 200
Orlando, Florida 32801
United States
We answer privacy requests within 30 days.
Your use of the Services is also governed by our Terms and Conditions.
2. The short version
- Your creative work stays on your computer. Projects, visuals, presets, timelines and rendered video files are saved locally on your machine. We do not upload, host or store them.
- Camera and microphone are processed on your device. Audio-reactive and camera-driven visuals run entirely on your computer. No camera or microphone stream is ever sent to us.
- We never see your card. Payments run through Stripe's hosted checkout. Card numbers never reach our servers.
- AI features are the exception to local-only. When you use the in-app AI assistant or AI Render, the prompt and the specific content you ask them to work with are sent to our servers and on to the AI provider that fulfils the request.
- Analytics are metadata-only and optional. We never send the content of your prompts or visuals to analytics, and you can switch analytics off entirely.
- We do not sell personal information and we do not run advertising.
3. Information we collect
3.1 Account information
When you create an xRLive account we collect your name and email address. If you sign up with a password, we store it only as a one-way bcrypt hash — we cannot read it. If you use Google Sign-In, Google returns your email address, name and Google account identifier to us; we never receive your Google password. We also store the sign-in method, the account creation date, your role/permissions, and short-lived password-reset tokens when you request a reset.
3.2 Purchase, subscription and credit information
If you buy a subscription, a Show Pass or a credit pack, we store your Stripe customer identifier, your subscription and entitlement status and expiry, a record of each purchase and invoice event, and your credit balance and consumption history.
Card details are entered on Stripe's hosted checkout page, not ours. Card numbers, expiry dates and security codes are never transmitted to, processed by or stored on xRLive systems. Stripe may share limited billing information back to us — such as your name, billing country, the last four digits of the card and the payment status — so that we can issue the right entitlement and support the purchase.
3.3 AI feature content
The AI features are opt-in: they only run when you invoke them. When you do, we process the content needed to answer the request.
- AI assistant (in-app agent): your prompt text, any images or assets you attach to the conversation, and the visual code, controls or composition you ask it to create or edit.
- AI Render: your text prompt plus the still frame or frames from your composition that you submit as the reference for the render.
- Usage metadata for every AI call: the model used, token counts, duration, cost and outcome. We keep this to meter credits accurately, bill correctly, support you when a job fails, and detect abuse.
Because AI Render works from a frame of your composition, a frame that happens to include camera imagery will be included in what is sent. If you do not want camera imagery leaving your machine, do not submit frames containing it to AI Render.
3.4 Product analytics and diagnostics (optional)
The desktop app can send us metadata about how the app is used — never the content of your work. That means: app version and platform, feature events (for example: app started, which sign-in method you used, that an AI turn ran with a given model, how long it took, its prompt length, whether it succeeded, that a checkout was opened, that a project or visual was created), and error reports containing the technical details of a crash or failure.
These events are tied to a random identifier stored on your own machine. Once you sign in, that identifier is linked to your account so we can see a coherent picture of one user's experience. You can turn this off at any time — see Your choices and controls.
3.5 Website information
When you visit xrlive.tv or xrlive.app we collect standard analytics — pages viewed, referring site, approximate location derived from your IP address, device and browser type — using a cookie or local-storage identifier. Our hosting provider also keeps standard server logs (IP address, user agent, request time) for delivery, security and abuse prevention.
3.6 Messages you send us
If you email us, request a demo or contact support, we keep your name, email address, any company or role you provide, and the content of your message so we can respond and keep a record of the conversation.
3.7 Software update checks
The desktop app periodically asks our update service whether a newer version exists and downloads installers. Those requests carry your IP address, platform and current app version.
4. What we do not collect
To be explicit about the boundaries of the Services:
- Your projects and visuals. Everything you author is stored in local files on your computer. There is no cloud sync, and we cannot see your work.
- Your camera and microphone feeds. Vision and audio analysis run locally in the app. Nothing is streamed, recorded or uploaded to us. (The single exception is the AI Render case described in §3.3, where you deliberately submit a frame.)
- Share links are local. When you share a visual to a phone or laptop, the app serves it from your own machine over your local network. The content does not pass through xRLive servers.
- Card and bank details. Handled exclusively by Stripe.
- Special-category data. We do not knowingly collect health, biometric identification, political, religious or similar sensitive data, and we ask that you do not send it to us.
We do not use your prompts or creative content to train our own AI models, and we do not sell or rent personal information to anyone.
5. How we use information
| Purpose | Information used | Legal basis (EEA/UK) |
|---|---|---|
| Create and run your account, authenticate you, keep you signed in | Account information (§3.1) | Performance of a contract |
| Take payment, grant and renew entitlements, meter credits, issue receipts | Purchase and credit information (§3.2), AI usage metadata (§3.3) | Performance of a contract; legal obligation (tax and accounting records) |
| Run the AI assistant and AI Render and return the result to you | AI feature content (§3.3) | Performance of a contract |
| Keep the Services secure, prevent fraud and abuse of AI credits | Usage metadata, server logs, purchase records | Legitimate interests (protecting the Services and our users) |
| Fix crashes and improve the product | Analytics and diagnostics (§3.4) | Consent (the desktop toggle); legitimate interests for website analytics |
| Send service email — verification, password reset, purchase receipts, important notices | Account and purchase information | Performance of a contract |
| Respond to your emails, demo requests and support tickets | Messages you send us (§3.6) | Legitimate interests; steps prior to entering a contract |
| Deliver software updates | Update check information (§3.7) | Performance of a contract; legitimate interests (security patching) |
We do not make decisions with legal or similarly significant effects about you by automated means, and we do not build advertising profiles.
6. Who we disclose information to, and how
We disclose personal information only to the service providers listed below, each for a defined purpose, and only the data that purpose requires. Every disclosure happens over an encrypted connection. We do not sell personal information, we do not share it with data brokers, and we do not disclose it to advertising networks.
| Recipient | What is disclosed | Why | Method of disclosure |
|---|---|---|---|
| Stripe (payments, US/IE) | Name, email, the billing and card details you enter directly on Stripe's page, purchase amounts, customer and subscription identifiers | Process payments and subscriptions, calculate tax, prevent payment fraud, keep invoice records | Your browser is redirected to Stripe's own hosted checkout page, so card data goes to Stripe directly and never through us. Everything else is exchanged as server-to-server HTTPS API calls and cryptographically signed webhooks |
| Anthropic, Moonshot AI, OpenAI (AI models) | Your AI assistant prompts, attached images or assets, and the visual code being created or edited | Generate the assistant's response — this is the request you asked for | Server-to-server HTTPS from our gateway using xRLive's own API keys. Your name, email and account identity are not passed to the model provider |
| Google (Gemini image model) | Your AI Render prompt and the reference frame you submit | Generate the AI-rendered still you requested | Server-to-server HTTPS from our backend using xRLive's own API key |
| Atlas Cloud (Seedance video model) | Your AI Render prompt and the reference frame or clip you submit | Generate the AI-rendered video you requested | Server-to-server HTTPS from our backend using xRLive's own API key |
| Google Cloud Platform and Firebase Hosting (US) | All data we store — account records, purchase and credit records, logs, installers, website files | Hosting, database, file storage, secret management and content delivery | Data is stored within our own Google Cloud project; Google acts as our processor under its data processing terms and does not use the data for its own purposes |
| PostHog (product analytics, US) | Analytics events and error reports as described in §3.4 and §3.5, with an anonymous or account identifier | Understand how the product is used and diagnose failures | HTTPS from your browser (website) or from the desktop app (in-app analytics, if enabled) |
| SendGrid (Twilio) (email delivery, US) | Your email address, name and the content of the service email being sent | Deliver verification, password-reset, receipt and service notices | Server-to-server HTTPS API call at the moment an email is sent |
| Google Sign-In and Google Fonts | Sign-in: the OAuth exchange that returns your email, name and Google account id. Fonts: your IP address and browser, visible to Google when a page loads its webfont | Let you sign in with Google; render the site's typeface | OAuth redirect in your browser plus a server-to-server token exchange; standard HTTPS asset request for fonts |
6.1 Other disclosures
- Legal and safety. We may disclose information if we are legally required to — a valid court order, subpoena or regulatory demand — or where we reasonably believe it is necessary to investigate fraud, enforce our terms, or protect the rights, safety or property of xRLive, our users or the public. Where we are permitted to notify you of such a demand, we will.
- Business transfer. If xRLive is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
- With your direction. Anything you explicitly ask us to share, for example when you send us a project file to help debug a support issue.
We require every provider above to protect personal information under a written contract, to process it only on our instructions and for the stated purpose, and to apply appropriate security measures.
7. International transfers
xRLive is operated with infrastructure in the United States, and the providers listed in §6 process data in the United States and other countries. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal information will be transferred outside your country. Where that happens we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), or on an adequacy decision such as the EU–US Data Privacy Framework where the recipient is certified. You can ask us for details of the safeguards that apply to a specific transfer.
8. How long we keep information
- Account information — for as long as your account is open, then deleted or anonymised within 90 days of account closure.
- Purchase, invoice and credit records — up to 7 years after the transaction, because tax and accounting law requires us to keep them.
- AI feature content — prompts and reference frames are processed to produce your result and are not retained as a browsable archive; the associated usage metadata (model, tokens, cost, outcome) is kept with the billing records above. Our AI providers apply their own retention windows, typically short and limited to abuse monitoring.
- Analytics and error reports — retained by our analytics provider for up to 12 months, then aggregated or deleted.
- Server logs — up to 90 days.
- Support and demo correspondence — up to 24 months after the last message, unless it relates to an ongoing contract or dispute.
9. Your choices and controls
- Turn off in-app analytics. Open the account dialog in the desktop app and clear Share anonymous usage data. It takes effect immediately, no restart needed. The app also respects the standard
DO_NOT_TRACK=1environment variable, and settingXRLIVE_ANALYTICS=0disables it outright. - Don't use the AI features. The editor, presets, sequences, timelines, audio-reactivity and outputs all work without them. If you never invoke the AI assistant or AI Render, no creative content leaves your machine.
- Camera and microphone. Access is granted through your operating system's privacy settings and can be revoked there at any time.
- Website analytics. Blocking cookies or using a tracker-blocking extension stops website analytics; the site works normally either way.
- Marketing email. We only send service email by default. Any marketing email we send carries a one-click unsubscribe link. Unsubscribing does not stop essential service notices such as receipts or security alerts.
- Close your account. Email admin@xrlive.tv and we will delete your account and associated personal information, apart from records we are legally required to keep (see §8).
10. Your rights (EEA, UK and Switzerland)
If the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal information we hold about you, and get a copy.
- Rectify information that is inaccurate or incomplete.
- Erase your information ("right to be forgotten").
- Restrict or object to processing based on legitimate interests.
- Portability — receive the information you gave us in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent, without affecting processing that already happened.
- Complain to your local supervisory authority. We would appreciate the chance to address your concern first.
To exercise any of these, email admin@xrlive.tv from the address on your account. We respond within 30 days and will not charge you or treat you differently for asking.
11. California privacy rights
Under the CCPA as amended by the CPRA, California residents have the right to know what personal information we collect and why, to request a copy of it, to request correction or deletion, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights.
In the twelve months before the date at the top of this page we collected the following statutory categories: identifiers (name, email, account and device identifiers, IP address); commercial information (purchases, subscription and credit history); internet or network activity (app and website usage events, error reports); geolocation (approximate, city-level, derived from IP); and audio, electronic or visual information (only the prompts, attachments and reference frames you deliberately submit to the AI features). We do not draw inferences to build a profile about you, and we do not collect sensitive personal information as the CCPA defines it. Each category above is collected from you or from your use of the Services, used for the purposes in §5, and disclosed for a business purpose to the providers in §6.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the past twelve months. We do not knowingly sell or share the personal information of anyone under 16. We offer no financial incentives in exchange for personal information. To make a request — including through an authorised agent — email admin@xrlive.tv. We will verify your identity against the email on your account before acting.
12. How we protect information
We apply administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold:
- Encryption in transit. All traffic between the app, the website and our API runs over HTTPS/TLS. Every disclosure to a provider in §6 uses an encrypted connection.
- Encryption at rest. Our databases and file storage are encrypted at rest by our cloud provider.
- Passwords are hashed, never stored. Passwords are protected with bcrypt, a deliberately slow one-way hash with a per-password salt. We cannot recover or read your password, and neither could an attacker who obtained the database.
- Card data never touches our systems. Payment card details are collected on Stripe's PCI-DSS Level 1 certified hosted checkout. This removes card data from our environment entirely — the strongest control available for that class of data.
- Authenticated, expiring sessions. API access uses cryptographically signed JSON Web Tokens with a limited lifetime, checked on every request, with role-based authorisation so an account can only reach its own data.
- Verified webhooks. Payment notifications from Stripe are rejected unless their cryptographic signature validates, and each event is recorded once so a replayed message cannot duplicate a charge or an entitlement.
- Secrets are managed, not committed. API keys, database credentials and signing secrets live in a managed secret store, are injected at runtime, and are never shipped inside the desktop application. The keys for our AI providers stay server-side, which is why AI calls proxy through our gateway rather than going out from your machine.
- Least privilege and separation. Production access is limited to the people who need it; development and production environments are separated so test activity cannot reach live customer data.
- Local-first architecture. The most effective protection is not holding the data at all. Your projects, media, camera and microphone stay on your computer by design.
No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and the relevant supervisory authority without undue delay and within the timeframes the law requires. If you believe you have found a security issue in xRLive, please report it to admin@xrlive.tv.
13. Cookies and similar technologies
We use a small number of cookies and browser storage entries:
- Analytics. Our analytics provider sets an identifier so that repeat visits are counted as one visitor. It is shared across our own subdomains so that a visit to the site and a later sign-up are understood as one journey.
- Authentication. The account dashboard stores your session token in your browser so you stay signed in.
- No advertising cookies. We run no ad networks, no retargeting pixels and no third-party advertising trackers.
You can clear or block cookies in your browser settings. Blocking analytics cookies does not affect the Services; blocking authentication storage will prevent you from staying signed in.
14. Children
The Services are intended for professional and adult use. They are not directed at children, and we do not knowingly collect personal information from anyone under 16 (or under 13 in the United States). If you believe a child has provided us with personal information, contact admin@xrlive.tv and we will delete it.
15. Changes to this policy
We may update this policy as the Services evolve. When we do we will change the Last updated date at the top of this page. If the change materially affects how we handle your personal information we will give you clear notice in advance — by email to your account address or a notice in the app — before it takes effect.
16. Contact us
Questions, requests or complaints about privacy go to admin@xrlive.tv. Please tell us which right you want to exercise and write from the email address associated with your account so we can verify the request.
This policy is provided in good faith as a plain description of our practices. It is not legal advice.
