# Foxora — Privacy Policy

> What data Foxora collects, why, how it is protected, and your rights. Data is not used to train models.

Source: https://foxora.ai/privacy
Knowledgebase: https://foxora.ai/llms-full.txt

---

We take your privacy seriously. This policy explains exactly what data Foxora collects, why we collect it, how we protect it, and the choices you have.

## 1. Overview

xBesh Labs, LLC ("xBesh Labs", "we", "us", or "our") is the legal entity behind Foxora AI. We operate the website at foxora.ai and the Foxora AI platform, including its API, agent runtime, dashboard, and all related services (collectively, the "Service").

xBesh Labs, LLC is incorporated in Delaware, United States. Our registered address is 8 The Green, Dover, Delaware, United States 19901.

This Privacy Policy describes how we collect, process, store, share, and protect personal information when you use the Service, and explains the choices available to you regarding your personal data.

Plain language summary: We only collect what we need to run the product. We do not sell your data. We give you full control to access, update, or delete your information at any time.

## 2. Data we collect

Account & identity — name, email, and password hash when you register; profile settings and preferences; billing name, address, and payment metadata (card last four, expiry — full card numbers are never stored by us, handled exclusively by Stripe); company name and role if provided.

Product usage — API requests, model calls, token counts, latency, and cost records; feature flags; agent configurations you create; support tickets and communications.

Technical & device — IP address, browser, OS, and device type; log data including error traces, request IDs, and timestamps; session tokens and authentication events; referral source and UTM parameters.

Content you provide — prompts, inputs, and outputs processed through the Foxora API (used solely to deliver the service; not used for model training); files or data you upload for analysis features.

## 3. How we use data

We use the information we collect to:

- Provision, operate, and maintain the Service and its features
- Process billing, manage subscriptions, and prevent fraud
- Enforce plan limits, rate limits, and acceptable-use policies
- Send transactional emails (confirmation, invoices, password reset, usage alerts)
- Provide customer support and resolve technical issues
- Monitor and improve reliability, performance, and security
- Generate aggregated, anonymized analytics about service usage
- Comply with legal obligations and respond to lawful requests

We do not use your prompts, agent outputs, or API request content to train any machine learning model — ours or any third party’s.

## 4. Data sharing

We do not sell, rent, or trade your personal information. We may share data with third parties only in these limited circumstances:

Service providers — vendors who help us operate the Service, including Supabase (database & auth), Stripe (payments), Postmark (email), Sentry (error monitoring), Upstash (caching), and Railway (infrastructure), under data processing agreements.

AI model providers — when you make API requests, your inputs are routed through our gateway to third-party model providers (e.g. Google, OpenAI) to generate responses. We route through our gateway so providers never receive your Foxora credentials or account identity.

Legal requirements — we may disclose information if required by law, court order, or to protect the rights, property, or safety of xBesh Labs, LLC, our users, or the public.

Business transfers — in a merger, acquisition, or sale of assets, user data may be transferred. We will notify users via email and a prominent notice before any such transfer.

## 5. Retention & security

We retain personal data for as long as your account is active and as necessary to provide the Service, meet legal obligations, resolve disputes, and enforce agreements.

- Account data — retained while active and for up to 90 days after deletion, then permanently purged
- API usage logs — up to 13 months for billing reconciliation and abuse detection
- Payment records — 7 years, as required by financial regulations
- Support communications — 3 years

Security protections include TLS/HTTPS for data in transit, AES-256 encryption for sensitive values at rest, row-level security and role-based database access, multi-factor authentication for infrastructure access, and regular security reviews and dependency audits.

## 6. Cookies & tracking

We use essential cookies and browser storage to operate the Service — session and authentication state (Supabase Auth), dashboard theme preference (localStorage), affiliate tracking cookies (30-day window), and CSRF protection tokens.

We do not run third-party advertising networks or cross-site behavioral tracking. You can manage cookies in your browser settings, though disabling essential cookies will prevent login.

## 7. Your rights

Depending on your jurisdiction, you may have the following rights:

- Access — request a copy of the personal data we hold about you
- Correction — update inaccurate profile information via dashboard settings
- Deletion — request permanent deletion of your account and data
- Portability — export your usage data and account information
- Restriction — object to certain processing activities
- Opt-out of marketing — unsubscribe from non-transactional emails at any time

To exercise these rights, contact us at privacy@foxora.ai or use your dashboard settings. We respond to all requests within 30 days.

## 8. Children

The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If we learn that a child has provided us with personal data, we will delete it promptly. If you believe a child has provided us with data, contact privacy@foxora.ai.

## 9. Policy changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date. Continued use of the Service after notification constitutes acceptance of the updated policy.

## 10. Contact us

For privacy-related questions, data requests, or to report a concern, contact us at privacy@foxora.ai.
