xamedia vaultBack to home

Legal

Privacy Policy

Last updated July 11, 2026

x|a media vault is private music infrastructure. This policy explains the information used to operate the platform and the controls intended to keep accounts and catalogs protected.

01Information we collect

We collect the account information you provide when you request access or sign in, including your name, email address, profile details, and the workspaces you belong to. When you authenticate with Google, we receive the basic profile and email information authorized through Google's identity service.

Within a workspace, the platform may store catalog data, audio and artwork, rights records, delivery settings, recipient details, and operational metadata created by you or your team.

02How we use information

We use information to authenticate users, enforce workspace roles, operate catalog and delivery workflows, provide requested platform features, maintain security records, communicate about the service, and improve reliability. We do not sell personal information. Uploaded media or rights documents are not used to train general-purpose artificial-intelligence models.

03Service providers

We use infrastructure and identity providers to host the application, store data, deliver files, and process authentication. These providers receive only the information needed to perform those services and are subject to their own security and privacy obligations. We may also disclose information when required by law or to protect the platform, its users, or the rights of others.

04Tenancy and access controls

x|a media vault is designed as a multi-tenant service. Workspace records are scoped to the organization that owns them, and database access policies are used to restrict one tenant from reading another tenant's catalog, recipients, or documents. Authorized platform personnel may access limited information when needed for security, support, compliance, or operations, and such access may be logged.

05Storage and security

Media and documents are stored in private storage locations rather than publicly listable folders. We use authentication, tenant-scoped authorization, encrypted transport, and other administrative and technical safeguards intended to protect information. No system can guarantee absolute security, and users are responsible for protecting their credentials and choosing appropriate sharing settings.

06Cookies and sessions

The platform uses essential cookies or similar browser storage to maintain authenticated sessions, protect account access, and preserve necessary application state. We do not use these essential technologies to sell personal information.

07Retention and your choices

We retain information while an account or workspace is active and for as long as reasonably necessary to provide the service, maintain security and audit records, resolve disputes, and meet legal or contractual obligations. Depending on your jurisdiction, you may request access, correction, export, or deletion of your personal information. Requests are evaluated subject to applicable law, security requirements, and legitimate retention obligations.

Questions about this policy? Contact darion@ipxs.digital.