Privacy Policy
This Privacy Policy explains how Coexist Group LLC, a United States limited liability company that provides the Service under the CXProAI brand ("CXProAI," "we," "us," or "our"), collects, uses, discloses, and retains information when you use cxproai.com and its subdomains, CXProAI Studio, the CXProAI API, and any related websites, applications, account services, APIs, storage or media-delivery services, tools, features, and services made available by or on behalf of CXProAI (collectively, the "Service").
By using the Service, you acknowledge the practices described in this Privacy Policy. Our Terms of Service govern your use of the Service.
1. Scope
This Privacy Policy applies to information processed by CXProAI through the Service, including account information, billing records, support communications, usage information, and content submitted to or generated through the Service.
It does not govern websites, applications, or services operated independently by third parties. Those third parties maintain their own privacy practices.
When a business customer submits personal information about its customers, employees, contractors, or other individuals, that business is responsible for determining whether it has a lawful basis to provide the information and for giving any required notices or obtaining any required consents. CXProAI processes that information to provide the Service and as otherwise described in this Policy and our Terms.
2. Information we collect
Information you provide
We may collect:
- Account and authentication information, such as your name, email address, profile information, account identifiers, authentication methods, session information, and records of your acceptance of our legal terms. CXProAI uses Clerk to provide authentication, account management, session management, and related identity services. Clerk may process this information through its systems under its applicable customer agreements, data-processing terms, privacy notices, and legal obligations.
- Billing and transaction information, such as billing contact details, purchases, Credit transactions, subscription status, payment status, invoices, refunds, chargebacks, and the Stripe identifiers for your customer, subscription, checkout session, and payment. Payments are processed by Stripe. Card details are entered on Stripe's own hosted checkout and billing pages and do not pass through the CXProAI website or application. CXProAI receives transaction records and limited payment information needed to administer purchases, subscriptions, refunds, payment disputes, fraud prevention, accounting, and customer support. CXProAI does not store card numbers, card security codes, card brand, expiration information, or other card details in its own systems.
- User Content, including prompts, instructions, text, images, audio, video, documents, data, project files, Solution inputs, generated outputs, exports, and associated metadata. User Content may contain personal, sensitive, confidential, proprietary, or regulated information that you choose to submit.
- API information, including API-key identifiers, requests, usage, timestamps, response status, Solution usage, Credit consumption, and technical information needed to operate, secure, and troubleshoot the API.
- Communications, including support requests, feedback, survey responses, dispute notices, and other messages you send to us.
- Communication preferences, including subscription, unsubscribe, and product-communication preferences.
Information collected automatically
When you use the Service, we and our service providers may automatically collect:
- IP address and approximate location derived from it;
- browser, device, operating-system, and language information;
- pages, features, Solutions, and actions used;
- referring pages and interaction timestamps;
- session, authentication, error, performance, and security logs;
- cookie, local-storage, and similar technical identifiers; and
- information used to detect fraud, abuse, automated activity, unauthorized access, and violations of our Terms.
Information from service providers
We may receive information from providers that help operate the Service, including:
- Clerk, which provides authentication, session, identity, and account-management services;
- Stripe, which processes payments, subscriptions, refunds, disputes, fraud signals, and related transactions;
- hosting, database, storage, content-delivery, email, monitoring, analytics, and security providers;
- AI, media-processing, and compute providers used to perform Solution runs; and
- business or technical partners you direct us to interact with.
The information we receive depends on the provider, feature, transaction, integration, and your settings. Providers may also process information directly through their systems under their own applicable agreements, privacy notices, policies, and legal obligations.
3. How we use information
We may use information to:
- create, authenticate, administer, secure, and support accounts;
- provide CXProAI Studio, Solutions, API access, storage, exports, and other Service features;
- transmit Input to infrastructure, AI, media-processing, and compute providers and return generated results;
- process purchases, subscriptions, Credit usage, refunds, payment disputes, taxes, and accounting records;
- communicate about accounts, purchases, security, support, maintenance, policy changes, and Service operation;
- send occasional product news, feature announcements, educational content, surveys, promotions, and offers where permitted by law, and manage your communication preferences;
- respond to questions, complaints, legal requests, and privacy requests;
- monitor performance, diagnose failures, troubleshoot problems, and improve usability;
- evaluate, develop, test, maintain, train, and improve the Service, including creating, populating, updating, and using internal historical databases, datasets, benchmarks, models, scoring systems, rankings, classifications, and other service-improvement and derived information;
- prevent, detect, investigate, and address fraud, abuse, security threats, prohibited activity, and Terms violations;
- protect CXProAI, users, service providers, and others;
- establish, exercise, or defend legal claims and enforce agreements;
- comply with law, legal process, tax, accounting, sanctions, and regulatory obligations; and
- create aggregated or de-identified analytics, statistics, and operational insights.
We may use aggregated or de-identified information for any lawful purpose and may retain it where it cannot reasonably be linked back to an identifiable person.
4. How User Content is processed
When you run a Solution, CXProAI may transmit your Input and related technical information to one or more third-party AI, storage, hosting, media-processing, or compute providers so the requested operation can be performed.
CXProAI may consider factors it believes relevant when selecting or continuing to use a provider, which may include capabilities, reputation, availability, published terms, privacy and security information, commercial suitability, and performance. Any such review is limited, may rely on information supplied or published by the provider, and is not an audit, certification, endorsement, warranty, or guarantee of that provider or its practices.
Third-party providers operate systems that CXProAI does not own or fully control. Their processing may be governed by their own applicable customer agreements, data-processing terms, privacy notices, product policies, account settings, subprocessors, and legal obligations. These documents and practices may differ from CXProAI's and may change from time to time, potentially without advance notice to CXProAI or you.
Provider retention periods, security controls, data locations, subprocessors, model-improvement practices, and permitted uses may vary by provider, product, account configuration, and Solution. Providers may retain Input, Output, or related logs for security, abuse prevention, debugging, service operation, legal compliance, or other purposes permitted by their applicable terms and settings.
To the maximum extent permitted by applicable law, CXProAI does not guarantee how a provider will collect, process, store, secure, retain, transfer, disclose, use, or delete information, or how a provider will respond to an outage, security incident, legal request, policy change, acquisition, or service discontinuation.
CXProAI may change, substitute, add, or discontinue providers and subprocessors as the Service evolves. Where required by applicable law, we will provide notice or obtain consent for material changes.
CXProAI may process User Content to provide, operate, secure, maintain, troubleshoot, evaluate, develop, and improve the Service; enforce our Terms; comply with law; and protect CXProAI, users, providers, and others. We do not sell or rent private User Content to third parties for their unrelated advertising.
The Service is general-purpose and is not designed or approved for highly sensitive, regulated, privileged, or mission-critical information unless CXProAI expressly agrees otherwise in a separate written agreement.
You should not submit information such as complete payment-card data, passwords, authentication secrets, government identification numbers, protected health information, biometric templates, children's information, legally privileged materials, trade secrets, confidential source code, or information subject to special legal, contractual, or professional restrictions unless the applicable use is expressly supported.
Unless separately agreed in writing, CXProAI does not enter into business-associate agreements and does not undertake HIPAA, PCI DSS, GLBA, FERPA, fiduciary, professional-secrecy, escrow, custodial, or special confidentiality obligations on your behalf.
You are responsible for deciding what to submit; determining whether the Service, each Solution, and the involvement of third-party providers are suitable; minimizing, redacting, anonymizing, encrypting, and backing up information where appropriate; obtaining all required rights, notices, authorizations, and consents; and complying with applicable privacy, confidentiality, security, records-management, and sector-specific requirements.
Submission of information does not create a confidential, fiduciary, professional, or privileged relationship. Any confidentiality obligation of CXProAI is limited to obligations expressly stated in this Policy or a separate written agreement signed by an authorized representative of Coexist Group LLC.
5. Service improvement and derived information
To operate, evaluate, develop, and improve the Service, CXProAI may use and retain information from Solution runs, including Input, Output, run metadata, publicly available or lawfully obtained information, research results, analyses, scores, classifications, feedback, and information derived from them.
This information may be maintained as individual records or combined and analyzed across runs, users, sources, and time periods. Where appropriate, we may remove or avoid including identifiers that associate an internal record with the user or account that initiated the run. A record may still identify the topic or public or third-party subject being researched.
We may use this information to maintain historical records, evaluate and improve results, identify trends, refresh research, improve prompts, models, rankings, scoring systems, and other existing or future Solutions.
We may retain and use user-unlinked, de-identified, statistical, system-generated, and derived information independently of the original run, User Content, or account, including after the original content or account is deleted, where permitted by applicable law. We may use this information to improve the quality, relevance, and performance of current and future Solutions without associating those improvements with the user or account that initiated the original run.
This internal use is separate from processing performed by third-party providers, which is described elsewhere in this Policy.
6. How we disclose information
We may disclose information in the following circumstances:
Service providers
We disclose information to providers that perform services for or with CXProAI, including Clerk for authentication and account management; Stripe for payment processing, subscriptions, refunds, disputes, and fraud prevention; and providers for hosting, databases, cloud storage, content delivery, communications, monitoring, analytics, customer support, security, AI processing, media generation, and computing.
Providers receive or process information reasonably related to their functions. Depending on the provider and activity, a provider may act as a processor or service provider for CXProAI, as an independent controller or business, or in another role recognized by applicable law.
Their processing may also be subject to their own applicable terms, privacy notices, product policies, settings, and legal obligations. CXProAI does not control or guarantee every aspect of a provider's independent processing.
At your direction
We may disclose information when you instruct us to do so, connect a third-party service, publish or share content, use an integration, or otherwise direct information to another party.
Legal, safety, and enforcement reasons
We may preserve, use, or disclose information when we reasonably believe it is necessary to:
- comply with law, regulation, subpoena, court order, or legal process;
- respond to lawful requests from government authorities;
- investigate or enforce our Terms or other agreements;
- detect, prevent, or address fraud, abuse, security issues, or illegal activity;
- protect the rights, safety, property, systems, or integrity of CXProAI, users, providers, or others; or
- establish, exercise, or defend legal claims.
Corporate transactions
Information may be disclosed or transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, change of control, due diligence process, or similar transaction. A successor may continue to process information subject to this Policy or a replacement policy provided as required by law.
Professional advisers
We may disclose information to attorneys, accountants, insurers, auditors, and other professional advisers where reasonably necessary.
7. No sale of personal information
CXProAI does not sell personal information or share personal information for cross-context behavioral advertising, as those terms are defined under applicable United States state privacy laws.
We do not rent customer lists or permit third parties to use private User Content for their own unrelated advertising.
If these practices change, we will update this Policy and provide any notices or choices required by applicable law.
8. Cookies and similar technologies
The CXProAI marketing website is currently designed without third-party advertising cookies or cross-site behavioral advertising trackers.
The application uses cookies, local storage, and similar technologies that are necessary or useful for:
- authentication and session management;
- account and security features;
- fraud and abuse prevention;
- remembering preferences;
- payment and checkout functionality;
- performance, error detection, and Service operation; and
- measuring use of the Service in a privacy-conscious manner.
Authentication and payment providers may set their own cookies when you use their features or visit their hosted pages. Their cookies are governed by their own privacy policies.
Browser controls may allow you to block or delete cookies, but disabling necessary technologies may prevent sign-in, checkout, account management, or other Service features from working correctly.
If we later introduce non-essential analytics, advertising, or tracking technologies, we will update this Policy and provide consent or opt-out controls where required.
9. Email and communications
We send transactional and service communications necessary to operate the Service, including account verification, receipts, billing notices, security alerts, support replies, operational updates, and changes to legal terms. You generally cannot opt out of these communications while maintaining an active account.
Where permitted by applicable law, we may also send occasional product news, feature announcements, educational content, surveys, promotions, or offers. We use your contact information and communication preferences for this purpose and obtain consent where required.
You may unsubscribe from product or marketing communications at any time through the link included in the message or through available account settings. Unsubscribing does not affect transactional or service communications.
10. Data retention and deletion
We retain information for different periods depending on its type, purpose, account status, and legal requirements.
In general:
- Account information is retained while the account is active and for a reasonable period afterward for administration, security, fraud prevention, dispute resolution, and legal compliance.
- Studio User Content is generally retained while it remains in your account, subject to storage limits, account status, deletion requests, our Terms, security needs, and operation or discontinuation of the Service.
- API results are generally accessible for the period shown in the Service, currently seven days, and may then be deleted or made unavailable.
- Billing and transaction records may be retained as necessary for accounting, tax, fraud prevention, chargebacks, audits, and legal obligations.
- Usage, security, and technical logs are retained for periods reasonably necessary to operate, secure, analyze, and improve the Service.
- Service-improvement and derived information may be retained independently of the original run, User Content, or account, including after deletion, where permitted by law.
- Support and legal records may be retained for as long as reasonably necessary to resolve the matter and protect legal rights.
When you delete content or close an account, deletion or de-identification from active systems generally begins within a reasonable period. Copies may remain temporarily in backups, logs, provider systems, caches, fraud-prevention records, or legal archives until they are overwritten or no longer reasonably needed.
We may retain information longer when required or permitted for legal compliance, safety, fraud prevention, dispute resolution, enforcement, financial recordkeeping, or legal claims. We may also retain aggregated or de-identified information.
The Service is not a permanent backup or archival service. You are responsible for downloading and preserving any Input or Output you need.
11. Security and risk
We use administrative, technical, and organizational measures designed to protect information and may change those measures as the Service, risks, and providers evolve. We do not promise any particular security method, certification, audit result, data location, or level of protection unless expressly stated in a separate written agreement.
No storage, transmission, AI-processing, cloud, payment, authentication, or third-party system is completely secure. We cannot guarantee that information will never be accessed, disclosed, intercepted, altered, lost, corrupted, delayed, or destroyed, including while it is processed by a provider.
You are responsible for deciding what information to submit; minimizing and protecting sensitive information; maintaining independent backups; securing your devices, passwords, account credentials, and API keys; limiting access by your personnel and users; and promptly revoking or rotating credentials if exposure is known or suspected.
To the maximum extent permitted by applicable law, you assume the risks inherent in transmitting and processing information through online and third-party services. Where required by law, we will provide notice of qualifying data-security incidents.
12. Your privacy choices and rights
Depending on where you live and subject to applicable exceptions, you may have the right to:
- request access to personal information we hold about you;
- request correction of inaccurate information;
- request deletion of personal information;
- obtain a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of marketing communications;
- opt out of certain sales, sharing, targeted advertising, or profiling, where applicable;
- appeal a decision concerning a privacy request, where required; and
- receive equal service without unlawful discrimination for exercising privacy rights.
To submit a privacy request, email support@cxproai.com with the subject "Privacy Request."
We may need to verify your identity and account before completing a request. We may deny or limit a request where permitted by law, including when information cannot reasonably be verified, must be retained, concerns another person, is protected by legal privilege, or is needed for security, fraud prevention, legal claims, or operation of the Service.
Where permitted, an authorized agent may submit a request for you, but we may require proof of authorization and verification of your identity.
You may also update certain account information or delete content through available account controls.
13. International processing
CXProAI and its service providers may process and store information in the United States and other countries. Those countries may have privacy laws that differ from the laws where you live.
Where required, we use appropriate contractual or legal safeguards for international transfers. By using the Service, you understand that information may be processed in locations where CXProAI and its providers operate, subject to applicable law.
14. Additional information for the EEA, United Kingdom, and Switzerland
Where data-protection laws in the European Economic Area, United Kingdom, or Switzerland apply, Coexist Group LLC generally acts as the controller of account, billing, support, security, and Service-usage information.
Our legal bases may include:
- performance of a contract, where processing is necessary to provide the Service you request;
- legitimate interests, including operating, securing, supporting, developing, and improving the Service; preventing fraud and abuse; and protecting legal rights;
- consent, where we specifically request it; and
- legal obligations, where processing is necessary to comply with applicable law.
Where CXProAI processes personal information submitted by a business customer solely on that customer's instructions, CXProAI may act as a processor or service provider for that customer.
You may have the right to lodge a complaint with your local data-protection authority. We encourage you to contact us first so we can try to resolve the issue.
15. Children
The Service is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children.
If you believe a child has provided personal information through the Service, contact support@cxproai.com so we can review and take appropriate action.
16. Changes to this Policy
We may update this Privacy Policy as the Service, providers, technology, or legal requirements change.
The "Last updated" date identifies the current version. If a change is material, we may provide notice by email, through the Service, at sign-in, or by another reasonable method. Where required by law, we will request consent before applying a material change to information already collected.
17. Contact
Coexist Group LLC, provider of the CXProAI Service
Email: support@cxproai.com