Privacy Policy
Last updated: May 20, 2026
1. Data Collection
XG FinePrint collects only the data necessary to provide our contract analysis service:
- Account information (email, name) via email/password authentication
- Uploaded documents (temporarily, for analysis only)
- Usage analytics (anonymous, for service improvement)
2. Data Processing
Documents uploaded to XG FinePrint are processed by AI models hosted on secure infrastructure in Romania/EU. Uploaded PDF files are processed in memory and discarded after extraction. By default, the original extracted document text is not stored with a scan; the report and operational metadata are retained for your account. If you separately opt in to model-training data use, that copy is encrypted and retained for up to 30 days unless you delete your account sooner. Free-scan result files expire after 24 hours. You can delete individual scans from your dashboard or request full account deletion.
3. Data Security
We implement industry-standard security measures including encryption in transit (TLS). Access to user data is restricted to authorized personnel only. Data is stored on servers located in Romania, EU.
4. Third-Party Services
We use the following third-party services:
- Custom JWT Authentication — Self-hosted, no third-party auth provider
- Local AI Engine (Aether) — Self-hosted, no data sent to external AI providers
- Stripe — Payment processing (stripe.com/privacy)
5. GDPR / DPA Compliance
XG FinePrint complies with the General Data Protection Regulation (GDPR) and Romanian Data Protection Authority (ANSPDCP) requirements. We process data as a Data Controller for account information and as a Data Processor for uploaded documents. Data is stored on servers located in Romania.
Users have the right to:
- Access their personal data
- Rectify inaccurate data
- Delete their account and all associated data
- Export their data in a portable format
- Object to or restrict processing
To exercise these rights, contact us at [email protected]. We respond within 30 days as required by GDPR.
6. Cookies
XG FinePrint uses only essential cookies:
- Authentication token — HttpOnly JWT cookie for session management (7-day expiry)
- Theme preference — localStorage for dark/light mode (no cookie)
We do not use tracking, analytics, or advertising cookies. No third-party cookies are set.
7. Contact
For privacy-related inquiries, contact us at [email protected]