Legal
Xapitol Protocol: Privacy Policy
Last Updated: 04/06/2026
This Privacy Policy explains how Xapitol collects, uses, and shares information when you use our web and mobile applications.
1. Information We Collect
Identity Information (XloudID): To comply with global AML/KYC regulations, we collect verifiable personal and corporate information, including legal name, government-issued ID, date of birth, biometric verification data, and corporate incorporation documents.
Vault & Account Data: We collect profile vault identifiers and account activity linked to your XloudID session.
Usage & Device Data: We collect standard web and mobile analytics, including IP addresses, device types, interaction with the Pulse feed, and preferences for platform intelligence alerts.
2. How We Use Your Information
Compliance & Security: To verify identities, prevent fraud, and comply with Anti-Money Laundering (AML) laws.
Platform Operation: To facilitate access to the Creator Studio, the Market Terminal, and the Xapitol Connect API.
Communication: To deliver requested ecosystem notifications, Pulse updates, and security alerts.
3. Transaction Records (Important Disclaimer)
Durable Transaction Ledger: Users must understand that Key trades and balance updates are permanently recorded in Xapitol's transaction ledger for compliance, tax, and dispute resolution.
Separation of Data: While your XloudID (PII) is stored securely by us and our verification partners, trade history tied to your account may be retained as required by law.
4. How We Share Your Information
Identity Partners: We share necessary data with our accredited third-party KYC/KYB providers solely for the purpose of identity verification.
Legal & Regulatory Requests: We will disclose information if required by a valid subpoena, court order, or regulatory inquiry to protect the integrity of the platform.
No Selling of Data: Xapitol does not sell user data or XloudID profiles to third-party marketers.
5. Data Security
We implement institutional-grade security measures, including encryption and strict access controls, to protect off-chain personal data. However, no digital transmission is 100% secure.
6. User Rights & Data Retention
Users may request access to, correction of, or deletion of their off-chain personal data, subject to regulatory retention requirements (e.g., AML laws often require keeping KYC records for several years even after an account is closed).
Users acknowledge that completed payment and ledger records may be retained even after an account is closed when required by law.