Privacy Policy
1. Who we are and what this policy covers
XALLER AI, a trade name of ZPEACHY LLC ("Xaller.ai", "we", "us"), operates xaller.ai. Our business mailing address is 5900 Balcones Drive STE 100, Austin, TX 78731 US. You can contact us about privacy at [email protected].
This policy explains how we handle personal information when you visit our website, join the early-access waitlist, contact us, or communicate with our team about early access. It also covers the limited staff accounts used to administer these requests. It applies to personal information about people, including people acting on behalf of a business.
The current website collects business interest in a future service. Joining the waitlist does not create a customer account, start a subscription or activate call handling. We are not processing customer calls, recordings, transcripts or patient information through this launch. Before offering those services, we will provide an updated notice and any required agreements. This policy does not turn a waitlist registration into a business associate agreement.
2. Our privacy commitments
We do not sell personal information or share it for targeted advertising. We do not rent contact lists. We do not give other companies permission to market to you using your waitlist or contact-form information. We do not use these submissions to train AI models or send them to a generative AI service for analysis.
We collect information for the purposes explained below, restrict access to people who need it, and use service providers to process information needed to operate Xaller.ai and deliver communications. We do not treat your decision to contact us as unlimited permission to contact you for unrelated purposes.
3. Information you provide
Waitlist information. The form asks for your name, business name, email address, business phone number and address, whether your intended business use might involve healthcare data, and your affirmative contact permission. You can optionally tell us which business software you use or would like us to integrate with. These optional software details are not required to join.
Permission records. We record the permission wording, the applicable agreement version and document hash, the date and time you gave permission, and subsequent withdrawal and confirmation status. We also keep a keyed, one-way representation of the email address to detect duplicate registrations and honor an opt-out. This representation is a restricted identifier, not a claim that all consent records are anonymous.
Contact inquiries and correspondence. We receive the name, email address, business name, optional phone number and message you submit through the contact form, together with emails or other correspondence you send us. Contact inquiries are delivered to our team's inbox rather than stored as a separate contact-form record in the website database. Copies can remain in that inbox and in the email provider's delivery records.
Staff administration. Staff access involves an email address, account/profile details, protected password-verification data, two-step-verification information, session records and audit records of administrative access. We do not store staff passwords in readable form. These records help protect the information entrusted to us.
Please provide business contact information you are authorized to share. Do not include patient information, medical records, diagnoses, payment-card details, government identification numbers, passwords or information about someone else's private circumstances. The healthcare question asks about a business's prospective use; it is not a request for anyone's health information. If we receive information outside this scope, we will restrict it and assess appropriate deletion.
4. Information used to deliver and protect the website
When your browser connects to the website, our infrastructure providers necessarily receive technical information such as your IP address, browser/device characteristics, requested pages, request time and connection/security signals. We and our providers use relevant technical records to serve pages, prevent abuse, diagnose failures and protect the service.
The application uses hashed identifiers for short-lived rate limits. It does not add a raw IP address to the waitlist registration record. This does not mean our network or security providers never process IP addresses. Staff access is audited, and operational records can include request identifiers, timestamps, error categories and access/security events. We aim to keep submitted message contents, contact details and credentials out of routine application logs.
We use a website security and abuse-prevention service to verify submissions and reduce automated abuse. The service processes relevant browser, network and challenge-related signals for that purpose. An unsuccessful security check can prevent a form submission; you can contact our team by email if you need another way to reach us.
Invisible form verification. We use Cloudflare Turnstile to protect the waitlist and contact forms without displaying a challenge widget. Cloudflare processes technical signals such as IP address, browser headers and connection characteristics to detect and block bots, and also uses those signals to improve its bot detection. See the Cloudflare Turnstile Privacy Addendum for details about that processing. You can contact us by email if verification prevents a submission.
5. How we use information
We use the information described above to:
- register your interest, send a requested confirmation and prevent duplicate registrations;
- communicate about early access and your business needs within the permission you provided;
- understand requested integrations and prioritize product work without activating those integrations;
- respond to inquiries and manage the correspondence you initiate;
- verify and honor privacy requests and withdrawals;
- administer authorized staff access, audit administrative activity and protect the website;
- maintain backups, diagnose problems and recover from failures; and
- meet applicable legal obligations and establish or defend legitimate legal claims when necessary.
We do not use the waitlist to make consequential automated decisions about you. The current site does not profile visitors for advertising. We will explain a materially different use and obtain any required permission before starting it.
6. Emails, contact permission and opt-outs
We send a transactional confirmation after a new waitlist registration. Confirmation attempts can be retried if delivery temporarily fails. A confirmation does not guarantee early access or a launch date. Email delivery necessarily shares the recipient address, message and related delivery information with our email provider and the recipient's email service.
Any subsequent early-access contact from our team follows the permission described in the Waitlist Agreement. You can withdraw by replying to a team email, asking a team member during a call, or emailing [email protected] with a request to leave the waitlist. We will stop active outreach, remove the active contact details and retain only records reasonably needed to honor the request or meet the purposes disclosed in this policy. A duplicate submission does not automatically undo an earlier withdrawal.
Waitlist permission does not authorize marketing text messages, automated or prerecorded marketing calls, AI-generated marketing calls, or marketing by another company. Contacting us through the contact form permits us to respond to that inquiry; it does not silently enroll you in a marketing campaign. We may still respond to a privacy request you initiate after you withdraw from outreach.
7. When information is disclosed
Service providers. Service providers process information needed to operate Xaller.ai. We use these categories of providers for this launch:
| Provider category | Purpose and relevant information |
|---|---|
| Hosting and storage | Operate the backend, database and encrypted backups; process stored information and infrastructure/security records needed to provide those services. |
| Website delivery, connectivity and security | Host and deliver pages, route website requests, connect securely to the backend and prevent automated abuse; process website traffic and relevant browser/network/security signals. |
| Email delivery and mailbox services | Deliver confirmation, inquiry and staff-account emails; process recipient addresses, message contents/headers and delivery information. Mailbox services receive and store contact inquiries, privacy requests and related correspondence in our monitored team inbox. |
We select providers for specific operational purposes, limit the information sent to what the service needs, and use applicable service terms/data-processing arrangements. Providers can use subprocessors and can process limited information for their own security or legal obligations. Mailbox retention is described in section 9; provider operational records remain subject to the applicable service terms and account settings.
Other necessary disclosures. We can disclose limited information when required by law, a valid legal process or a regulator, or when reasonably necessary to protect people, investigate abuse, enforce our agreements or establish/defend legal claims. We assess the request and limit disclosure where appropriate and permitted.
If the business undergoes a reorganization or ownership change affecting this information, we will require continued protection consistent with this policy and give notice of any material change. Such an event does not authorize sale of your contact list for unrelated marketing. We will obtain permission where required before materially changing the purpose of processing.
8. Cookies, local storage and online tracking
The initial waitlist website does not use optional audience analytics, advertising pixels, cross-site advertising trackers or session-replay tools. We do not embed third-party advertising or social-media widgets in the forms. Security services can use necessary challenge mechanisms, and staff sign-in uses necessary session/anti-forgery cookies and browser state. These mechanisms support operation and security rather than advertising.
You can manage cookies and browser storage through your browser settings. Blocking necessary storage or security scripts can prevent sign-in or form verification. Ordinary browsing does not require a staff account.
Do Not Track and Global Privacy Control. We do not change essential security processing in response to a Do Not Track signal. This site does not sell personal information or share it for targeted advertising, regardless of a browser preference signal. If we introduce processing that requires an opt-out preference mechanism, we will update our notice and controls before starting it. We do not permit advertising partners to track visitors across other sites.
9. How long we retain information
We remove active waitlist contact information, including optional software preferences, after 12 calendar months without a recorded interaction initiated by you, unless you withdraw or request deletion sooner. Registration starts the period. A later reply or conversation you initiate about early access can restart it when our team records that interaction. Automated confirmations, repeated form submissions, staff views/exports and unanswered outreach do not restart it. After the deadline, the record is excluded from active outreach, staff contact views and exports; scheduled daily cleanup clears its contact details and cancels pending confirmations. Expiration does not silently renew your contact permission.
On withdrawal, active waitlist contact details and optional software information are removed from the application record, and pending confirmations are cancelled. Limited consent evidence, dates and a suppression identifier can remain to document the permission previously given, honor your request and address legal claims. We restrict access and do not use those retained records for renewed outreach. We retain this limited evidence only as reasonably needed to honor an opt-out or privacy request, protect security, or establish/defend a legal claim. We review the need for retained evidence at least annually and delete records when those purposes no longer justify keeping them. An applicable legal preservation duty can require limited records to remain longer; they are not used for renewed outreach.
We retain inquiry correspondence, staff/security records and operational records only for their relevant purposes, with periods finalized in our operating retention rules. A specific legal preservation duty or dispute can require limited information to be retained longer; it will not be used for unrelated marketing.
Encrypted database backups are scheduled to expire after 30 days, with brief additional storage possible while the storage provider processes expiration and removes old versions. Deletion from the live application does not instantly rewrite an existing backup. Backups are restricted to recovery, and we apply relevant withdrawal/deletion records before using restored data for outreach.
Email copies held by recipients are outside our control. Provider-side email/log retention also follows the applicable email provider's service and account settings. The method used to send email does not by itself establish a provider delivery-log retention period. We delete contact inquiry correspondence and related sent copies from our team mailbox after 12 months, except while an inquiry remains active or a specific legal preservation duty applies. We will coordinate requests within our control without promising that every recipient or provider can erase all records immediately.
10. Security
We use measures appropriate to this limited scope, including encrypted website connections, application encryption of stored waitlist contact details, protected storage/backups, private database access, separate operational credentials and restricted staff access. Staff waitlist access requires two-step verification and is audited. Backup decryption keys are kept separately from the encrypted backup files.
No website or communication method can be guaranteed completely secure. If we identify a security incident affecting personal information, we will investigate, address it and provide notifications as required by applicable law. Do not email sensitive patient information to report an issue.
11. Your choices and privacy requests
You can choose not to submit a form, leave optional fields blank, withdraw outreach permission, and ask to access or correct the personal information we hold about you or request deletion. Depending on applicable law and our role, you may also have rights to a portable copy, restriction or objection to processing, an authorized-agent request, or an appeal of a denied request. We do not penalize you for exercising applicable privacy rights.
Send a request to [email protected], identifying the email address used to contact us and the request. We will use proportionate steps to confirm your authority and protect other people's information; we do not routinely ask for a government-ID copy. An authorized agent can be asked to establish their authority. We aim to respond promptly and within applicable legal time limits. If a request cannot be fulfilled completely, we will explain the reason and available next steps, subject to legal restrictions. We can retain limited information when necessary to honor an opt-out, meet a legal obligation, protect security or address a claim.
US state privacy laws can provide additional rights when their applicability conditions are met. This policy does not represent that every such law applies to Xaller.ai. Where a statutory appeal is available, email the same address with "Privacy appeal" and we will explain the appeal process. You can also contact the relevant privacy regulator or attorney general as permitted by law.
12. Location of processing and intended audience
The initial site is intended only for adult representatives of businesses in the United States. We operate the application database in the United States. Our network and service providers can process technical information or provide services from other locations; selecting an email-sending region does not necessarily control where all provider data is stored. If applicable law requires safeguards for an international transfer, we will use the applicable arrangements before relying on that transfer.
The site is not directed to children, and the business waitlist is not intended for people under 18. We do not knowingly solicit children's personal information. If you believe a child supplied information, contact [email protected] so we can investigate and remove it as appropriate. Do not send a child's sensitive information in the request.
13. Other websites
Our pages can link to another website, including a provider's privacy notice. Following a link can cause that website to receive ordinary connection information and operate under its own policy. We do not control its practices. Naming a software preference on the waitlist does not connect your accounts, give us access to that software, or authorize disclosure to its vendor.
14. Changes and contact information
We will keep this policy accessible and identify its version and effective date. When practices materially change, we will provide appropriate notice and obtain any permission required before using previously collected information in a materially different way. Earlier published versions remain available for reference. Silence or continued browsing is not a substitute for any consent required by law.
For privacy questions, corrections, deletion requests or complaints, contact:
Xaller.ai
Email: [email protected]
Business mailing address: 5900 Balcones Drive STE 100, Austin, TX 78731 US
Version history
- Version 2026-10-02.6 · effective October 2, 2026 Current - Approved invisible Turnstile verification and its required privacy-addendum disclosure; other providers remain described by category.
- Version 2026-10-02.5 · effective October 2, 2026 - Approved retention, provider-category disclosures, no-sale commitment and Xaller.ai naming.