Your data
Privacy Policy
XLEVATED is designed to keep your inner world private. This policy is honest about what we collect, where your content must go to power a feature, and the rights you have.
Last updated: July 27, 2026
1. How XLEVATED is built
Your reflective content lives in an isolated per-account “cosmos,” membership checks prevent one cosmos from being read as another, and the most sensitive psyche fields are encrypted at rest. We design for minimum necessary data sharing. This policy is honest about the places where your content must leave our systems to deliver a feature — chiefly NobuAI and the sub-processors that power it (see §7) — and what we do to limit that.
A plain-language companion to this policy lives at /knowledge/privacy. It is a summary written for readability; where anything there conflicts with this Policy or with the Terms of Service, this Policy and the Terms control.
2. Information we collect
Account & authentication. Your name, email address, password or single-sign-on identifiers, session cookies, and security logs.
Your “Sun” — birth seed & psyche data. Your birth date; optional birth time; a birthplace label and coordinates when you select a real place; optional current location (including device geolocation if you grant it). This seeds your charts and readings; the sensitive fields around it are encrypted at rest.
Connection-based location estimate (onboarding). When you first set up your account, we estimate your approximate current city or region from your connection (your IP address, or coarse location signals our network edge attaches to your request) so we can suggest it as your “current place.” The estimate is shown to you on screen with the option to confirm, correct, or decline it — we store a current place only if you confirm or enter one, and you can change or remove it at any time in your profile. To turn a location estimate or a place you type into a standardized place name and coordinates, our servers query a place-lookup service (see the Sub-processor Annex); your name, account identity, and IP address are not sent with that query.
Approximate country from your connection (while you are signed in). Our servers derive an approximate country from the IP address your requests arrive from, or from coarse location signals our network edge attaches to them, and store it on your profile as a two-letter country code. We use it to show emergency and crisis resources for the right country and to keep region-dependent details accurate — an IP address indicates a country, not a street, a building, or a person's whereabouts, and we do not treat it as more precise than that. As part of this estimate the IP address itself is neither stored on your profile nor written to our logs: only the country code is kept, together with a note that it came from your connection. When no country can be determined, we show international resources rather than guessing one.
Self-content you create. Your story, answers, North Star and goals, journey moments, journal entries, wishes, your chats with Kronos and Solis, coach work-products (plans, notes, optional audio), and preferences (theme, reading balance, quiet hours, notification channels).
Optional connected sources. If you enable an integration, we process only what that feature requires, subject to your consent; some paths keep raw data on your device and share only aggregated patterns.
Billing. If you subscribe, our third-party payment processor handles your payment method and transaction data. We store subscription status and related metadata; we do not store full card numbers.
Usage, device & diagnostics. IP address, approximate region, device and browser type, app version, the routes you use, and performance, error, rate-limit, and abuse signals — used for security, reliability, and product improvement.
Safety signals (only if the safety feature is enabled). XLEVATED includes an optional crisis-safety layer that, when active for your region and release, screens messages so it can surface help if it detects acute distress. When that layer is on:
• The text of a screened message may be sent to a model provider to classify whether it signals a crisis. To reduce cross-border risk for this sensitive step, crisis-flagged classification is routed to a U.S.-based model provider.
• If a message is flagged, we may record a codes-only duty-of-care entry — a category, severity, surface, and action code and a timestamp. We do not store the raw text of the message in that safety record. This layer never contacts anyone on your behalf and never calls emergency services for you (see Safety & Disclaimers).
Some safety, content, voice, and localization features described here are governed by internal controls and may be off, limited, or unavailable in a given release. Where a feature is off, the related processing does not occur.
3. How we use information
We use information to: provide, operate, maintain, and secure the Service and your isolated cosmos; compute charts, readings, and coaching from the data you provide; personalize guidance under the NobuAI brand; process payments, prevent fraud, and enforce plan limits; communicate about the Service, security, and material changes; comply with law and protect rights, safety, and property; and analyze aggregated, de-identified trends to improve the product.
We do not sell your personal information, and we do not use the content of your sittings to train third-party foundation models.
4. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: contract (to provide the Service you request); legitimate interests (security, fraud prevention, product improvement, balanced against your rights); consent (for optional integrations, optional device permissions, and — if and when offered — voice features); and legal obligation. Your birth/psyche content and any safety signals may be special-category data; where so, we rely on your explicit consent and, for acute-distress situations, potentially vital interests, with heightened safeguards. The precise basis for safety processing is being finalized with counsel before that feature is enabled.
5. First-party sponsorship on Echo
On the Echo entry plan, some Solis replies or deliverables may carry a short first-party line (for example, “Sponsored by …”) set by us. This is not a third-party ad exchange and not behavioral ad tracking. Plans above Echo do not receive these markers, and we may change or remove the feature at any time.
6. Cookies & similar technologies
We use essential cookies and local storage for authentication, session continuity, security, and core preferences (such as theme). We do not use third-party advertising cookies for cross-site retargeting. You can control cookies in your browser; disabling essential cookies may break sign-in.
7. How your content powers NobuAI
XLEVATED’s readings, chats, and coaching deliverables are powered by NobuAI — and, where you enable it, NobuAI also synthesizes spoken voice. To produce these, your prompts and their outputs are processed by NobuAI together with a small set of vetted infrastructure sub-processors engaged under a data-processing agreement (DPA). We share only the minimum content a feature needs; each sub-processor is contractually barred from using your content for its own purposes; and, where the provider supports it, processing runs under zero-data-retention / no-training terms. As stated in §3, we do not use the content of your sittings to train third-party foundation models.
For full transparency — and to meet the disclosure GDPR Article 28 requires — every sub-processor NobuAI and XLEVATED rely on, including the specific companies behind AI language processing and voice synthesis, is named in the Sub-processor Annex at the foot of this policy.
We also share personal information, as needed, with professional advisors under confidentiality; with authorities when required by law or to protect rights, safety, or the Service; and with a buyer or successor in a merger, acquisition, financing, or sale of assets (subject to this policy or equivalent protections). We do not sell personal information to data brokers. We maintain the annex below and update it as our sub-processors change.
Optional identity providers. If you choose to sign in through a single-sign-on provider, that provider learns that you signed in and returns the identifiers we need to authenticate you. Minimum necessary is a design goal, not a guarantee: we build each feature to send the least context it needs, but we do not promise that every part of your history is excluded from every request.
8. International transfers & data residency
We operate primarily in the United States and may process and store information in the U.S. and other countries where we or our providers operate — some outside your home country or the EEA. Because some of NobuAI’s sub-processors (see the Sub-processor Annex) may operate outside the EEA (and, for some models, outside the U.S.), using NobuAI features may involve international transfers of the content you submit. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses). As noted in §2, when the safety layer is enabled, crisis-flagged classification is deliberately routed to a U.S.-based model provider.
9. Security
We apply industry-standard measures including TLS in transit, encryption at rest for primary data stores (and additional at-rest encryption for the most sensitive psyche fields), access controls, and membership checks. No method of transmission or storage is 100% secure. You are responsible for safeguarding your credentials and devices. Report a suspected incident to privacy@nobukaizen.com promptly.
10. Retention
We retain information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal, tax, and security requirements. After account deletion or an erasure request, we remove your stored files (audio, documents, images) from our object storage immediately, and delete or de-identify primary cosmos content within approximately thirty (30) days. Encrypted database backups are a separate, unavoidable copy: they cycle out on a fixed schedule — hourly within 7 days, daily within 30 days, weekly within 90 days, and monthly and long-term archives within up to seven (7) years — so a copy of deleted information can persist in those archives until they expire. We keep them for disaster recovery and do not restore a backup to revive deleted data; if one is ever restored, erasure requests are re-applied. Certain media (such as spoken audio) may be purged on a shorter schedule. Any coded safety records are subject to a defined retention limit that counsel is finalizing before that feature is enabled.
11. Voice, and future features (planned; not active by default)
We are developing an optional, opt-in voice feature. If and when it launches, it will use a separate, explicit consent (not bundled into these terms), a published retention-and-destruction policy, and a “we never sell your voice” commitment, consistent with biometric-privacy laws. A voiceprint is sensitive biometric data, and we will not collect it without your specific, informed, up-front consent. Any future cultural/slang localization would be developed with sensitivity review. These features are described so you know our direction; where a feature is not active, the related processing does not occur.
12. Your choices & rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent. You can:
- Use the in-product export and erase tools (Your data);
- Update your profile and birth seed in Account settings;
- Disconnect optional sources and notification channels;
- Email privacy@nobukaizen.com to make a GDPR/UK GDPR/CCPA-style request (we may verify your identity first).
Our goal is that these rights reach all of your data, including your Sun/psyche content and any voice profile or coded safety record. We may decline a request that is unlawful, abusive, compromises another person’s privacy, or falls within a legal exemption, and we do not discriminate against you for exercising your rights.
An authorized agent may submit a request on your behalf where applicable law allows it; we may ask for proof of the agent’s authority and verify your identity directly.
13. Children — 18 and older only
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact privacy@nobukaizen.com and we will take appropriate steps to delete it.
14. U.S. state privacy notices
We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. California and other states with comprehensive privacy laws may grant additional rights (access, deletion, correction, portability, and to limit the use of sensitive personal information). To exercise them, contact privacy@nobukaizen.com. We do not currently respond to browser “Do Not Track” signals in a differentiated way beyond this policy.
15. Changes
We may revise this policy at our discretion; the “Last updated” date reflects the latest revision. For material changes we may provide additional notice (in-product or by email). Continued use after the effective date means you accept the updated policy.
16. Contact
Privacy: privacy@nobukaizen.com
Support: support@nobukaizen.com
Nobu Kaizen · Dallas, Texas, USA
This page is provided for transparency and may be updated from time to time; the version shown here is the one that currently applies. Questions? Email support@nobukaizen.com.
