Privacy Policy

Last updated: May 20, 2026

1. Data Collection

XG FinePrint collects only the data necessary to provide our contract analysis service:

  • Account information (email, name) via email/password authentication
  • Uploaded documents (temporarily, for analysis only)
  • Usage analytics (anonymous, for service improvement)

2. Data Processing

Documents uploaded to XG FinePrint are processed by AI models hosted on secure infrastructure in Romania/EU. Uploaded PDF files are processed in memory and discarded after extraction. By default, the original extracted document text is not stored with a scan; the report and operational metadata are retained for your account. If you separately opt in to model-training data use, that copy is encrypted and retained for up to 30 days unless you delete your account sooner. Free-scan result files expire after 24 hours. You can delete individual scans from your dashboard or request full account deletion.

3. Data Security

We implement industry-standard security measures including encryption in transit (TLS). Access to user data is restricted to authorized personnel only. Data is stored on servers located in Romania, EU.

4. Third-Party Services

We use the following third-party services:

  • Custom JWT Authentication — Self-hosted, no third-party auth provider
  • Local AI Engine (Aether) — Self-hosted, no data sent to external AI providers
  • Stripe — Payment processing (stripe.com/privacy)

5. GDPR / DPA Compliance

XG FinePrint complies with the General Data Protection Regulation (GDPR) and Romanian Data Protection Authority (ANSPDCP) requirements. We process data as a Data Controller for account information and as a Data Processor for uploaded documents. Data is stored on servers located in Romania.

Users have the right to:

  • Access their personal data
  • Rectify inaccurate data
  • Delete their account and all associated data
  • Export their data in a portable format
  • Object to or restrict processing

To exercise these rights, contact us at [email protected]. We respond within 30 days as required by GDPR.

6. Cookies

XG FinePrint uses only essential cookies:

  • Authentication token — HttpOnly JWT cookie for session management (7-day expiry)
  • Theme preference — localStorage for dark/light mode (no cookie)

We do not use tracking, analytics, or advertising cookies. No third-party cookies are set.

7. Contact

For privacy-related inquiries, contact us at [email protected]

© 2026 XG FinePrint. A product of XG Tech Studio.