Privacy Policy

Last updated: April 1, 2026


1. Introduction

XRToken.ai (the "Platform," "we," "us," or "our"), operated by a company incorporated in Singapore, is committed to protecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, store, share, transfer, and protect your personal information when you access or use our Platform and Services.

This Policy applies to all personal data processing activities that occur when you interact with the XRToken.ai website and its associated online services. By creating an account, accessing, or using any part of the Platform, you acknowledge that you have read and understood this Policy and consent to the data practices described herein. If you do not agree with this Policy, please do not use the Platform.

We designed this Policy to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the Personal Data Protection Act 2012 of Singapore (PDPA), and other relevant regulations. Where specific jurisdictions impose additional requirements, we will comply with those requirements for users in those jurisdictions.


2. Information We Collect

We collect information in three categories: information you provide to us, information collected automatically, and information from third-party sources.

Information You Provide: When you register an account, we collect your email address and password (stored as a cryptographic hash, never in plaintext). If you contact our support team, we collect the content of your communications. When you make a purchase, your payment details are collected directly by our payment processor (Stripe); we receive only transaction confirmation data, including the amount, timestamp, payment status, and the last four digits of your card number.

Information Collected Automatically: When you use the Platform, we automatically collect the following data: API call records (including timestamp, model invoked, input/output token counts); request frequency and usage patterns; credit consumption records; login records (including timestamps and IP addresses); device information (browser type and version, operating system, device model, screen resolution); and unique device identifiers. This data is necessary for billing, platform operations, performance optimization, and security monitoring.

Information from Third Parties: We may receive limited information from third-party services we integrate with, such as payment confirmation from Stripe or authentication data if you use third-party sign-in providers. We do not purchase personal data from data brokers or other commercial sources.


2a. Facial Information Processing

When you use services on the Platform that require real-person video synthesis (such as video generation), we may ask you to provide facial images or video clips ("Facial Information"). Facial Information constitutes sensitive personal data under applicable law and is subject to the strictest protections we apply.

We process Facial Information only after obtaining your separate, explicit consent, and solely for the purpose of generating the video content you have requested. Facial Information is deleted from our systems upon completion of the generation task and is not used for any other purpose — including AI model training, third-party sale, or sharing (except for data transmitted to the AI model provider as strictly necessary to fulfill your request). You may withdraw your consent to the processing of Facial Information at any time, after which we will cease processing and delete all related data.

The Platform uses Volcengine (a ByteDance service) to process Facial Information for video generation. That service is subject to its own privacy rules. For details, see the Volcengine Personal Information Processing Rules ↗


3. How We Use Information

We use the information we collect for the following specific purposes, each with a corresponding legal basis:

We do not use your personal information for purposes beyond those listed above. If we need to process your data for a new purpose, we will seek your consent beforehand (unless otherwise permitted by applicable law). We do not use the content of your API requests or the outputs you receive to train AI models. Your API request content is processed transiently for routing purposes only and is not persistently stored for any purpose unrelated to service delivery.


4. Information Sharing

We do not sell your personal information. We share your data with third parties only in the following circumstances and only to the extent necessary:

We do not share your personal information with any third party for their own marketing purposes. Any third-party service provider that processes personal data on our behalf is contractually required to use the data solely for the purposes we specify and to maintain appropriate security measures.


5. Cookies & Tracking

We use cookies and similar technologies to provide, secure, and improve the Platform. Cookies are small data files stored on your device by your web browser. We use the following categories of cookies:

Most browsers accept cookies by default, but you can manage or delete cookies through your browser settings. Please note that disabling essential cookies may prevent you from using certain features of the Platform. We do not use advertising or tracking cookies, and we do not participate in cross-site tracking networks.


6. Data Security

We implement multi-layered technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or loss. These measures include but are not limited to:

We maintain an incident response plan for personal data breaches. In the event of a breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay through Platform notifications, email, or other reasonable means, informing you of the nature of the breach, the likely consequences, and the measures we have taken or propose to take. We will also notify the relevant supervisory authority as required by applicable law.

Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security but are committed to continuously improving our security practices.


7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are as follows:

After the applicable retention period expires, we will delete or anonymize your personal data. Where immediate deletion is not technically feasible, we will isolate the data from further processing and apply appropriate security measures until deletion is possible.


8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise any of these rights, please contact us at [email protected]. We will verify your identity and respond to your request within thirty (30) days (or the shorter period required by applicable law). In some cases, we may not be able to fully comply with your request due to legal obligations or other legitimate reasons, in which case we will explain our reasoning.


9. International Data Transfers

As an AI API gateway, the Platform routes requests to model providers that may operate in different jurisdictions. When you invoke a model hosted outside your country of residence, your API request content (which does not include your personal identity information) may be transmitted internationally for processing. Your account data and personal information are stored on servers located in Singapore.

For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers from other jurisdictions, we comply with the applicable legal requirements for cross-border data transfers. You may request information about the specific safeguards we apply to international transfers by contacting us.


10. Children's Privacy

The Platform is not intended for use by individuals under the age of sixteen (16). We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will take steps to delete that information promptly.

If you are a parent or guardian and believe that your child has provided personal information to us without your consent, please contact us at [email protected], and we will take prompt action to remove the information and, if applicable, close the child's account.


11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make material changes (such as changes to the purposes or methods of processing, the categories of third-party recipients, or your rights), we will provide prominent notice through Platform announcements, in-app notifications, or email to your registered address at least thirty (30) days before the changes take effect.

Your continued use of the Platform after the effective date of any revised Policy constitutes your acceptance of the changes. If you do not agree with the revised Policy, you should discontinue use of the Platform. We encourage you to review this Policy periodically. Previous versions of this Policy are archived on the Platform for your reference.


12. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: [email protected]

We will acknowledge receipt of your inquiry and provide a substantive response within thirty (30) days. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your jurisdiction.