Privacy Policy
Last Updated: August 10, 2025
This Privacy Policy explains how VIXAI TECHNOLOGIES LTD (“Vixai”, “we”, “us”) collects, uses, shares, and safeguards personal data in connection with Vixai STUDY — including our WhatsApp-based assistant and web app. It applies globally, with particular focus on users in the United States, the European Economic Area/United Kingdom, and Brazil.
1) Who We Are & How to Contact Us
Controller: VIXAI TECHNOLOGIES LTD
Email: vixai@vixai.app
If you are in the EEA/UK or Brazil, you can use this email to exercise your local privacy rights.
2) What We Collect
- Account Data: name, email, phone number, password (hashed), country/region.
- WhatsApp Data (when you message our assistant):
- Your phone number and WhatsApp profile name (if available).
- Message content you send to us, including text, links, images, PDFs, videos, voice notes.
- Technical metadata provided by WhatsApp Business Platform (e.g., timestamps, message IDs, delivery events).
- User Content uploaded via the web app (e.g., PDFs, slides, videos, images, audio, notes).
- Payment Data: handled by Stripe; we receive limited billing metadata (e.g., last 4 digits, brand, status) but do not store full card details.
- Usage & Device Data: IP address, device/browser type, pages/events, crash logs, and cookies or similar technologies for essential operations and (where required by law and consented) analytics.
- Support & Communications: messages and attachments you send us via email, WhatsApp, or in-app forms.
3) How We Use Data (Purposes & Legal Bases)
- Provide and operate the service (process your prompts/files; deliver study guides, summaries, quizzes, translations, chat responses; enable WhatsApp interactions). Legal basis: contract necessity; legitimate interests.
- Transcription & voice (if you send audio or request audio replies): we may use trusted speech-to-text and text-to-speech providers to process audio. Legal basis: contract necessity; legitimate interests; consent where required.
- Billing and fraud prevention via Stripe. Legal basis: contract necessity; legal obligation; legitimate interests.
- Security, abuse prevention, and diagnostics. Legal basis: legitimate interests; legal obligation.
- Improvements and analytics (e.g., de-identified or aggregated usage to improve quality, latency, and safety). Legal basis: legitimate interests; consent where required.
- Customer support & communications (emails/WhatsApp messages about your account, receipts, service updates). Legal basis: contract necessity; legitimate interests; consent for optional marketing.
4) WhatsApp-Specific Information
We operate an automated assistant on WhatsApp using the WhatsApp Business Platform (Cloud API). When you message us on WhatsApp:
- Your messages and media are delivered to us via Meta’s WhatsApp infrastructure and forwarded to our servers.
- We process that content to generate responses (e.g., summaries, quizzes, explanations) and may store it in your account history so you can revisit it.
- You can stop interactions at any time by no longer messaging us, blocking our number in WhatsApp, or contacting us at vixai@vixai.app to request deletion of your history.
- WhatsApp/Meta independently processes your data under their own policies. Please review: WhatsApp Privacy Policy and Meta Privacy Policy.
Note: End-to-end encryption in WhatsApp protects delivery to the WhatsApp platform. When you message a business, the business (us) receives your content through the Business Platform to provide the service you requested.
5) Third-Party Processors & Infrastructure
We rely on reputable providers to deliver the service:
- AI processing: OpenAI and Google (to interpret prompts and generate responses). Where available, we configure settings to not allow your content to be used for provider training.
- Speech services (if used): speech-to-text (e.g., transcription) and text-to-speech providers to process audio you send or request.
- Payments: Stripe for secure subscription and token purchases.
- Hosting & storage: Amazon Web Services (e.g., compute and object storage) in regions appropriate for performance and availability.
6) International Data Transfers
We may transfer personal data to countries outside your own (e.g., to the US). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful mechanisms. We take steps to ensure your data remains protected according to applicable law.
7) Data Retention
- Account data: kept while your account is active and for a reasonable period thereafter (e.g., for compliance, fraud prevention, accounting), unless you request deletion earlier where applicable.
- WhatsApp and chat history: retained so you can review past interactions; you may request deletion at any time.
- Processing caches & logs: kept only as long as necessary for security, reliability, troubleshooting, and legal obligations.
8) Security
- Encryption in transit (HTTPS/TLS) and at rest for stored content where applicable.
- Access controls, audit trails, and least-privilege principles for our internal systems.
- Vendor due diligence and contractual data protection commitments with processors.
9) Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, port, or object/restrict processing of your data, and to withdraw consent at any time (this won’t affect prior lawful processing). To exercise rights, contact vixai@vixai.app.
- EEA/UK (GDPR): additional rights to lodge a complaint with your supervisory authority.
- Brazil (LGPD): contact us to exercise rights of confirmation, access, correction, anonymization, portability, information about sharing, and deletion; you may petition the ANPD.
- California (CCPA/CPRA): rights to know, delete, correct, and to opt-out of “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined. We do not use sensitive personal information for purposes requiring a “Limit” link.
10) Children’s Privacy
Vixai STUDY is not directed to children under 13 (or higher age where local law requires, e.g., 16 in parts of the EEA). We do not knowingly collect personal information from children below the applicable age threshold. If you believe a child has provided personal data, contact us to remove it.
11) Cookies & Similar Technologies
We use essential cookies for authentication and security. Where required by law, we seek consent for optional analytics or marketing cookies. You can control cookies via browser settings and (where implemented) our cookie banner.
12) Automated Processing & AI
We use AI to generate explanations, summaries, quizzes, and replies. We do not engage in automated decision-making that produces legal or similarly significant effects about you. You can always contact us for help or to request deletion of content.
13) Marketing & Opt-Outs
We may send service messages (e.g., receipts, critical updates). For optional marketing, we will obtain consent where required. You can opt out via unsubscribe links (email), by asking us on WhatsApp, or by emailing vixai@vixai.app. On WhatsApp, you may also block our number.
14) Changes to This Policy
We may update this policy from time to time. Material changes will be notified via email or in-app/WhatsApp notice. Continued use of the service after an update means you accept the revised policy.
15) How to Reach Us
Email: vixai@vixai.app