Data We Collect
- User-provided content, including prompts, inputs, files, and workflow data
- Account and contact information, if provided
- Usage, diagnostic, and interaction data
- Device, browser, network, and IP metadata
Last updated: 2026
Xorventa.ai ("Company", "we", "our") provides AI automation services. We take data protection seriously and operate under principles aligned with GDPR, CCPA, and recognized industry best practices.
Your inputs may be processed by third-party AI and infrastructure providers to generate responses, operate automations, and deliver services. By using the service, you acknowledge and consent to this processing.
We share data only with service providers necessary to operate the platform, such as cloud infrastructure and AI providers. We do not sell personal data.
You can also connect your own website so Xorventa can work on it directly. Supported platforms are Wix, Shopify, Webflow and WordPress. With your permission, Xorventa can install your Assist chat window and propose changes to the SEO information on your live pages — the page title, the description shown in search results, the canonical address and whether a page should be indexed. Xorventa does not rewrite the body content of your pages. Nothing is written to your website until you approve that specific change, you can undo an applied change, and you can disconnect at any time. You can connect one website at a time.
Connecting your website uses that platform’s own authorization, and for WordPress an application password you create and can revoke yourself — we never see or store your website password. We store the connection and a credential scoped to that one site, encrypted at rest. Data exchanged with your website platform goes to the platform you already use for your site; Xorventa does not move your website or its content anywhere else. Disconnecting stops all future access; it does not remove anything already installed on your site, which you remove separately.
Xorventa Social lets you connect third-party accounts — TikTok, Facebook, Instagram, LinkedIn, X, Pinterest, Bluesky, Google Business Profile and YouTube — so Xorventa can publish content on your behalf and, where the network supports it, read and reply to inbound comments and messages. You choose which accounts to connect, and you can disconnect any of them at any time.
Connecting an account uses that network’s own authorization screen (OAuth). We never see or store your password. The network issues us an access token, which we store encrypted at rest and use only for the actions you have authorized.
For TikTok specifically, Xorventa Social requests three permissions: basic profile information, permission to publish videos and photos, and permission to upload content to your TikTok drafts. Before you post, we read your TikTok account’s current settings — display name, profile image, which audience options are available to you, whether comments, Duet and Stitch are enabled, and the maximum video length your account allows — so the posting form reflects your real settings rather than guessing. We publish only the content you submit, with the audience and interaction settings you select on that form. We do not read your existing TikTok videos, followers or analytics.
You can revoke Xorventa’s access from the network itself at any time — for TikTok: Profile → Menu → Settings and privacy → Security & permissions → Manage app permissions → Xorventa Social → Remove — or by disconnecting the account in your Xorventa account. See our Data Deletion page for what disconnecting removes on our side.
Google user data (Search Console, Analytics, and YouTube). When you connect a Google account to Xorventa — for Xorventa SEO (Google Search Console and Google Analytics) or Xorventa Social (YouTube) — you do so through Google’s own OAuth consent screen and grant only the permissions shown there. Xorventa’s use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements.
What we access depends on the products you use: your Google Search Console performance data for your verified sites (clicks, impressions, positions, and queries) and your Google Analytics (GA4) reporting metrics — both read-only — to produce your SEO reports; and, for Xorventa Social, your YouTube channel, to publish videos you approve and to read and reply to comments on your own videos on your behalf. We use this data only to provide the features you enable. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized AI or ML models.
Google access and refresh tokens are stored encrypted at rest and used only for the actions you authorized. Search Console and Analytics metrics are stored only as part of the SEO reports we generate for you — we keep a limited number of your most recent reports — and are used solely to provide those reports to you. YouTube data (such as comments on your videos that you choose to review and reply to) is retained no longer than needed to provide the feature and is deleted within 30 days if not acted on. We do not share Google user data with third parties except with providers acting on our behalf to deliver the service, to comply with law, or with your consent. You choose which Google account and permissions to grant, and you can disconnect at any time — from your Xorventa portal or your Google Account security settings — which revokes our access.
Xorventa’s transfer and use of information received from YouTube APIs also complies with the YouTube API Services Terms of Service (https://developers.google.com/youtube/terms/api-services-terms-of-service) and the Google Privacy Policy (https://policies.google.com/privacy).
We retain data only as long as reasonably necessary to provide services, meet legal obligations, enforce agreements, and improve system performance. You may request deletion where applicable.
When you delete your account, we deactivate it immediately and cancel any active subscription. Residual account records — including your tenant configuration, knowledge-base content, and the customer record held by our payment processor — are retained for no longer than six (6) months after deletion, after which they are permanently and irreversibly purged from our active systems, except where a longer period is required by law, needed to resolve disputes, or necessary to enforce our agreements. Routine backups and audit logs may persist for their normal rotation period before being overwritten.
You agree not to submit sensitive personal, financial, healthcare, regulated, or confidential data unless explicitly permitted by contract and supported by the service.
We implement administrative, technical, and organizational safeguards, including encryption, access controls, and monitoring. No system can be guaranteed 100% secure.
To protect sign-in, sign-up, and account-recovery pages from automated abuse, we use Cloudflare Turnstile, a bot-detection challenge that may run invisibly and processes limited client-side signals (such as IP address, user-agent, and browser characteristics) solely for that purpose. Your interaction with Turnstile is also governed by Cloudflare’s Turnstile Privacy Addendum, available at https://www.cloudflare.com/turnstile-privacy-policy/.
We are not responsible for outputs generated by AI systems or for downstream decisions, actions, or business outcomes based on those outputs.
support@xorventa.ai
Contact Xorventa for details, plan terms, and implementation guidance.