Privacy Policy
x-motion.io and x-motion.io Recorder. Last updated: September 20, 2026.
This Privacy Policy explains how x-motion.io collects, uses, shares, stores, and protects information when you use our website, web application, Chrome extension, interactive demos, demo hubs, Find Leads, opportunity workspaces, integrations, AI-assisted video tools, paid plans and AI credit packs sold through Paddle, support channels, and related services. If you do not agree with this policy, do not use x-motion.io.
Quick summary
- We collect account information, product content, recordings, uploaded assets, prompts, generated media, usage logs, and demo analytics needed to provide x-motion.io.
- The Chrome extension records only the tab you explicitly choose after pressing Start recording. It does not collect browsing history, cookies, passwords, form field contents, or tabs you did not choose to record.
- Public demo and hub analytics may use a browser-local viewer ID, event data, IP address, user agent, and optional lead form data so demo owners can understand engagement.
- Find Leads research is run by x-motion.io's own research agent, which uses public web search and AI-assisted source reading to research people and companies at your request. Search queries and source content are processed by Anthropic, our AI and web search provider. Results and source references are saved in x-motion.io's own database for your workspace. X-Motion does not connect mailboxes, send outreach emails, or run message sequences.
- Customer content is normally protected by account, workspace, access-control, or signed-link safeguards. If you publish a demo or hub, enable anonymous access, use a public embed, or otherwise make content public, that content may be accessible to anyone with the link or embed access and may no longer be protected as private content.
- We do not sell personal information, Customer Content, or Lead Data. Lead Data returned through Find Leads is licensed for the customer's authorized internal business-to-business research use and must not be sold, resold, sublicensed, or redistributed as a data product.
- We do not intentionally use Customer Content to train our own foundation models. AI, voice, media, and rendering providers process inputs only as needed for the features you request, subject to their applicable terms and configurations.
- You can ask to access, correct, export, delete, or restrict personal information by contacting [email protected].
Our role
For account holders, workspace members, website visitors, and people who contact us directly, x-motion.io generally acts as the controller of the account, support, security, billing, and service administration data we collect.
When a customer uploads content, records a workflow, configures a lead form, requests lead research or enrichment, embeds a demo, connects a CRM or collaboration tool, or reviews viewer analytics, the customer controls the purpose and means of that processing. For Customer Content, prospect data, and end-viewer data, x-motion.io generally acts as a processor or service provider on the customer's instructions. AI, search, infrastructure, and connected services may act as subprocessors or independent recipients depending on the feature and their terms. Customers are responsible for giving their users, viewers, employees, prospects, and website visitors any notices or consents required by law.
Information you provide
- Account and workspace data: name, email address, authentication identifiers, organization membership, roles, settings, theme preferences, and account status.
- Project and demo content: video projects, source files, prompts, chat messages, assistant responses, tool calls and tool results, uploaded images, PDFs, audio, video, brand assets, saved prompts, prompt attachments, theme presets, demo sessions, scenes, screenshots, click labels, notes, interstitial text, CTA text, and generated outputs.
- Chrome extension recordings: cursor-free video of the user-selected tab during an active recording, click coordinates, click timing, clicked element labels, source URL, viewport metadata, and session metadata needed to attach the recording to your account.
- Viewer and lead data: demo and hub view events, step navigation, CTA clicks, form submissions, names, email addresses, language selection, time spent, and viewer identifiers when a public demo or hub owner enables or uses those features.
- Find Leads and research workspace data: research prompts, company profiles, account knowledge, uploaded documents or CSV files, table values, person and company names, job titles, employers, business contact details, domains, public profile links, source references and source-confidence information. We also store saved targets, opportunity and content-planning records, transcripts, tool results, approvals, and usage or credit records. We do not collect mailbox access tokens or outbound email delivery records.
- Integrations: Salesforce instance and user details; HubSpot portal, domain, user, contact, company, deal, form, meeting, workflow, and sync details; encrypted CRM refresh tokens; Slack workspace, channel, scope, and encrypted bot-token details; and Microsoft Teams tenant, team, channel, service URL, pairing state, alert rules, and delivery logs when you connect those services.
- Support and feedback: messages, ratings, survey responses, bug reports, screenshots, and related contact details you send to us.
- Billing data: when a workspace buys a paid plan or an AI credit pack, Paddle, our merchant of record, collects your name, billing email, billing address or country, tax or VAT number, and payment details directly in its checkout. x-motion.io receives and stores the Paddle customer, subscription, transaction, price, and adjustment identifiers, the plan and billing period, payment status, refund or dispute holds, credit-pack grants, the identity of the admin who authorized each purchase, and an audit trail of billing operations. Full payment card numbers never reach x-motion.io servers.
Chat messages, uploads, and stored assets
Chat conversations are stored so the service can maintain project context, show chat history, replay assistant state, count usage, debug failures, and continue work across sessions. Stored chat records may include your messages, assistant messages, compacted conversation summaries, referenced files, images, PDFs, tool inputs and outputs, project changes, token counts, error details, and feedback signals.
Uploaded and generated assets are stored in object storage and indexed in our database with metadata such as filename, object key, MIME type, file size, owner, workspace, resource type, dimensions, duration, creation time, update time, deletion state, and storage class. This includes project assets, chat attachments, saved prompt attachments, recordings, screenshots, demo media, voiceovers, generated videos, render outputs, hub media, and organization brand assets.
Personal saved prompts and personal assets are intended for the owner. Organization-level prompts, brand assets, projects, demos, hubs, usage records, and activity may be visible to workspace members depending on roles, product settings, and access controls.
Find Leads and public web research
Find Leads research is performed by x-motion.io's own research agent. At your request, the agent searches public web sources and reads publicly accessible pages to organize professional and company information in your workspace. The agent runs on Anthropic's AI models and Anthropic's web search service; Anthropic is the AI provider listed under "How we share information". Find Leads does not use a separate lead-research or data-enrichment vendor. Anthropic processes the research instructions, search queries, relevant workspace context such as the tables and files you include, and the source page content needed for the research you request. Research results can include names, roles, employers, business contact details, public profile links, company facts, source references and source-confidence information.
Research tables, rows, research runs, and the review history of each row are stored in x-motion.io's own database, hosted by the database and infrastructure providers listed under "How we share information". Tables are shared with members of your workspace according to their roles. Retention is described under "Retention".
- Published contact details: research may record a business email explicitly published in a referenced public source. We do not infer email addresses or classify people by sales suitability. Public availability is not consent to contact someone.
- Research boundaries: X-Motion does not connect mailboxes, send outreach emails or messages, or operate outbound message sequences. Saving a record or exporting a table does not contact the people listed.
- Your responsibilities: establish a lawful basis for personal information you request or use, provide required notices, and honor objections and deletion requests. Public availability does not remove a person's privacy rights or grant permission to contact them.
- Restricted use: research output is for authorized internal business research. Do not sell or redistribute it as a dataset, use it for unsolicited mass marketing, harassment, surveillance, discrimination, or unlawful profiling, or use it to determine eligibility for credit, employment, housing, or insurance.
- Accuracy: public sources and AI-assisted results may be incomplete, inaccurate, or outdated. Review sources and verify results before relying on or exporting them.
Information collected automatically
- Device and log data: IP address, request headers, browser type, operating system, referring page, timestamps, route paths, error logs, performance data, and security events.
- Usage data: feature usage, render jobs, generation jobs, token and credit usage, project activity, edit-lock activity, and analytics needed to operate and improve the service.
- Cookies and local storage: authentication cookies, theme preferences, OAuth state cookies, demo unlock cookies, rate-limit and security data, and a browser-local viewer ID used to deduplicate public demo and hub analytics. When you open a Paddle checkout or the Paddle customer portal from the workspace billing page, Paddle sets its own cookies and similar technologies for payment session integrity, fraud prevention, and tax calculation under its Privacy Notice. The public marketing site also stores a signed consent receipt for 180 days. See the Cookie Policy.
- Account Reveal: if a workspace enables IP-based company enrichment for demo or hub viewers, we may use the viewer IP address to identify company-level information such as company name, domain, industry, employee range, city, state, or country.
Sensitive information
We do not intentionally request sensitive personal information such as government identifiers, financial account numbers, health data, biometric identifiers, precise geolocation, children's data, or special-category data. Because x-motion.io can record a tab chosen by a user and can store customer-uploaded content, you must avoid recording or uploading sensitive information unless you have the legal right and required permissions to do so.
How we use information
- Create, authenticate, secure, and administer accounts.
- Record workflows, store scenes, render videos, generate voiceovers, create images or clips, export assets, and deliver interactive demos and hubs.
- Provide public sharing, embeds, access controls, password unlocks, domain restrictions, viewer analytics, lead capture, account reveal, and alert delivery.
- Process prompts, files, recordings, and generated outputs through AI, media, rendering, storage, and infrastructure providers needed to provide requested features.
- Research professional and company information from public web sources, maintain research tables and account knowledge, organize opportunity content, and perform authorized table exports or CRM synchronization. These features do not send outreach messages.
- Sync or send information through integrations you connect, including Salesforce, HubSpot, Slack, and Microsoft Teams.
- Monitor abuse, enforce rate limits, detect fraud, troubleshoot errors, maintain service reliability, and protect x-motion.io, customers, viewers, and third parties.
- Communicate about product updates, service messages, security notices, billing, support, and marketing where permitted.
- Comply with law, enforce our Terms, resolve disputes, and defend legal claims.
Legal bases
Where GDPR, UK GDPR, or similar laws apply, we process personal information based on one or more legal bases: performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights or safety. For example, we use contract necessity to provide your account and requested features, legitimate interests to secure and improve the service, consent where required for optional marketing or certain tracking, and legal obligations for tax, accounting, compliance, and lawful requests.
How we share information
- Service providers: hosting, database, object storage, CDN, authentication, observability, security, analytics, AI, public web research, search, media generation, voice generation, rendering, rate limiting, email, billing, support, and operations providers.
- Connected integrations: Salesforce, HubSpot, Slack, Microsoft Teams, or other services you authorize. Their own terms and privacy policies govern how they handle information after it is sent to them.
- Workspace members: users in the same organization may see shared projects, demos, hubs, analytics, brand assets, prompts, usage, editor identity, and activity depending on their role and workspace configuration.
- Public viewers: demos or hubs you publish publicly can be viewed by people with the link or on websites where you embed them. Public access settings are controlled by the owner. If anonymous access is enabled, viewers may not need an x-motion.io account, password, approved domain, or other access restriction to view the published content.
- Legal and safety: regulators, courts, law enforcement, advisors, or affected parties when we believe disclosure is required by law or needed to protect rights, safety, security, or the integrity of the service.
- Business transfers: information may be disclosed or transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
Current infrastructure and product providers may include Clerk for authentication, Paddle as merchant of record for checkout, payments, tax, invoices, subscriptions, and refunds, Neon or compatible Postgres hosting for database storage, Cloudflare R2 or CDN services for media storage and delivery, Sentry for error monitoring, Anthropic Claude for AI assistant processing, ElevenLabs for voice or music generation, Remotion and AWS infrastructure for rendering, Upstash Redis for rate limiting, Clearbit or successor company-enrichment services for optional account reveal, Anthropic's models and web search for x-motion.io's own Find Leads research agent, and HubSpot, Slack, Microsoft Teams, and Salesforce when you connect those integrations. Find Leads does not use a separate lead-research vendor. Not every provider receives every category of information; information is shared based on the feature, integration, configuration, and request involved.
| Category | Providers may include | Example data |
|---|---|---|
| Authentication and accounts | Clerk | Account identifiers, sessions, organization membership, roles, and authentication state. |
| Billing and payment processing | Paddle (merchant of record: Paddle.com Market Limited, Paddle.com Inc., or Paddle.com (Canada) Ltd) | Buyer name, billing email, billing address, tax or VAT number, payment method, and IP address collected by Paddle at checkout; plan, subscription, transaction, invoice, tax, payment status, dispute, and refund records exchanged with x-motion.io. Full card numbers stay with Paddle and its payment processors. |
| Hosting, storage, database, and delivery | Cloudflare, Neon or Postgres hosting, AWS, and Remotion | Product content, uploaded assets, generated media, render jobs, object metadata, logs, and delivery data. |
| AI, voice, image, and video processing | Anthropic, ElevenLabs, and rendering providers | Prompts, chat context, files, scripts, source images, audio inputs, generation parameters, and returned outputs when you request those features. |
| Security, observability, and rate limiting | Sentry, Upstash Redis, and infrastructure providers | Error reports, route paths, timestamps, request metadata, usage counters, security events, and abuse-prevention signals. |
| Public web research | Anthropic and its web search services | Research instructions, public-topic search queries, source URLs and page content, relevant workspace context such as tables and attached files, professional and company facts, citations, and results needed for requested research. Saved tables, research runs, and review history are stored in x-motion.io's own database. |
| Customer-connected integrations | Salesforce, HubSpot, Slack, Microsoft Teams, and similar services | Encrypted integration tokens, CRM records and identifiers, workspace, tenant, team, and channel metadata, viewer signals, alerts, and content you choose to import, sync, export, or deliver. |
Payments and billing through Paddle
Paid plans and AI credit packs are sold through Paddle, our merchant of record. Paddle runs the checkout and customer portal, decides how it processes buyer data, and acts as an independent controller of the personal data it collects for payment, tax, fraud prevention, receipts, and legal compliance. Paddle's processing is described in its Privacy Notice.
- Sent to Paddle: the workspace identifier, the selected plan or credit pack, the checkout transaction created by our servers, and the billing email you use at checkout. You enter your name, address, tax number, and payment details directly into Paddle's checkout; those fields are not typed into x-motion.io forms.
- Received from Paddle: signed webhook events and API records describing the customer, subscription, transaction, price, billing period, payment status, refunds, chargebacks, and adjustments. We use them to verify entitlements, grant credits, place or lift payment holds, reconcile balances, detect duplicate or ambiguous charges, and keep a billing audit trail.
- Stored by x-motion.io: Paddle identifiers, the plan, billing interval and period end, price identifier, payment and review status, credit-pack purchase records, the identity of the admin who authorized each purchase, the persisted intent to delete a paying account, and minimal billing tombstones that survive workspace deletion so a late refund, dispute, or tax obligation can still be resolved. Raw payment details and card numbers are never stored on our servers.
- Emails and portal: Paddle sends receipts, invoices, renewal reminders, payment-failure notices, and refund confirmations to your billing email. The Paddle customer portal verifies that email before showing invoices or payment methods, so one workspace admin cannot view another buyer's payment details.
- Retention: finished billing events and closed operations are retained for 90 days; ownership records, unresolved operations, and billing tombstones are retained as long as needed for accounting, tax, refund, dispute, and fraud-prevention purposes, including after account or workspace deletion.
CRM and collaboration integrations
- Salesforce: when connected, x-motion.io can read or write authorized Lead, Contact, Account, Opportunity, and Campaign records; import CRM context into opportunity workspaces; and sync demo or hub engagement. We store encrypted refresh tokens, instance and user identifiers, scopes, mappings, sync status, and error or usage metadata needed to operate the connection.
- HubSpot: when connected, x-motion.io can import or export authorized contacts, companies, and deals; synchronize demo and hub engagement; use forms, meetings, app cards, personalized share links, workflow actions, and webhooks; and store encrypted refresh tokens, portal and user identifiers, scopes, mappings, sync snapshots, and delivery status.
- Slack: when installed, x-motion.io stores the authorized workspace, bot, scopes, selected channels, encrypted bot token, alert rules, and delivery results needed to send configured demo, hub, CTA, form, and engagement alerts.
- Microsoft Teams: when installed and paired, x-motion.io stores tenant, team, selected channel, service URL, pairing status, alert rules, and delivery results needed to receive bot commands and send configured engagement alerts.
- Disconnecting an integration stops future access after the disconnect is processed, but it does not automatically delete records already written to the third-party service. Customers must manage those downstream records under their own retention and privacy obligations.
Chrome extension details
x-motion.io Recorder is designed to record only after explicit user action. The extension injects a click tracker and starts tab capture only for the active tab selected by the user. Recording stops when you stop it from the popup or the recording flow ends.
- We do not collect full browsing history or scan unrelated tabs in the background.
- We do not collect cookies, passwords, hidden form values, or typed form contents as separate data fields.
- The extension stores a bearer token or pairing state needed to connect to your x-motion.io account or demo session. You can disconnect from the popup, and pairings can be revoked in the web app.
- If you configure a self-hosted or custom API URL, recordings and metadata are sent to that configured endpoint.
Public access and customer-published content
x-motion.io is designed to keep ordinary account content, project files, chat attachments, saved prompts, recordings, generated media, and private demos behind authentication, workspace authorization, configured access controls, or short-lived signed links. These safeguards apply while content remains private or protected inside the service.
If you choose to publish a demo or hub, enable anonymous access, enable a public share link, embed content on a website, connect a public object-storage or CDN endpoint, or otherwise configure content to be publicly reachable, the selected content is public or may become public. People with access to the link, embed, website, public endpoint, or downstream copy may view, copy, download, record, index, scrape, share, or redistribute that content outside x-motion.io's control.
You are responsible for choosing public access settings and for confirming that publicly shared content does not contain confidential, sensitive, regulated, third-party, or personal information that you are not authorized to disclose. To keep content protected, do not enable anonymous access and use available controls such as sign-in requirements, passwords, domain restrictions, expiration settings, workspace permissions, and disabling public object-storage or CDN access where applicable.
AI and generated media
When you use AI-assisted features, prompts, chat messages, uploaded assets, recordings, screenshots, project files, and relevant metadata may be sent to AI, voice, media, or rendering providers so they can return the requested output. You should not submit confidential, regulated, or sensitive data to these features unless you have authority to do so and your use complies with the applicable provider terms.
- Claude / Anthropic: chat messages, project context, uploaded chat images or PDFs, file excerpts, tool results, prompts, Find Leads research instructions, search queries, public source page content, assistant outputs, and usage metadata may be sent to Anthropic's Claude API to answer requests, edit projects, translate content, reason over attachments, run Find Leads research and public web search, or generate assistant responses. Where supported, we use commercial/API configurations rather than consumer chat accounts, and we do not intentionally use customer content to train our own foundation models.
- ElevenLabs: scripts, text, selected voice IDs, voice settings, audio inputs, music prompts, and returned audio may be processed when you use voice, music, or speech-related features.
- Remotion and AWS rendering: project files, authored code, referenced assets, templates, render settings, temporary bundles, and output files may be processed through Remotion tooling and AWS infrastructure. Completed renders may be copied into x-motion.io storage for download, sharing, or hub import.
- Third-party providers may process data under their own terms, data processing addenda, security measures, moderation systems, abuse-prevention rules, retention periods, and legal obligations. Provider terms and capabilities may change over time.
Retention
- Account, workspace, project, demo, hub, prompt, integration, and media records are generally retained while your account or workspace remains active, until you delete them, or until they are no longer needed to provide the service.
- Deleted sessions, scenes, hubs, projects, exports, and assets are removed from active systems where deletion is supported, but copies may remain temporarily in backups, logs, caches, or provider systems until normal retention cycles expire.
- Chat messages, agent events, saved prompts, prompt attachments, and chat attachments are generally retained with the project, prompt, session, or workspace they belong to, unless you delete them where deletion controls are available or we delete them under an account, workspace, legal, security, or operational process.
- Find Leads projects, prompts, account knowledge, opportunity records, saved targets, research tables, research runs, source references, and Lead Data are stored in x-motion.io's own database and are generally retained while the workspace remains active or until you delete them. Deleting a research table removes its rows from active systems; a record of the deletion and the table's review history, which can include a person's or company's name and corrected field values, are kept until the workspace or account is deleted. Anthropic, our AI and web search provider, may retain research requests under its own agreements and policies. Deletion can remain subject to ordinary backup, legal, and security retention periods.
- Find Leads research previously ran on a third-party lead-research service. Lead Data and related content that a workspace sent to that service before research moved in-house was not migrated to x-motion.io and may remain subject to that provider's own retention and deletion practices until it is deleted there. Contact [email protected] and we will identify that provider and help route a deletion request.
- Security, billing, audit, usage, support, legal, and abuse prevention records may be retained for longer when reasonably necessary for legitimate business, legal, tax, accounting, compliance, or dispute purposes. Completed Paddle billing events and closed billing operations are kept for 90 days; subscription ownership records, credit-purchase records, and billing tombstones are kept after workspace or account deletion so that late refunds, chargebacks, and tax reporting can be handled, and Paddle retains its own transaction records under its Privacy Notice.
- Marketing-site consent receipts are retained for 400 days and include pseudonymous identifiers, the decision timestamp, policy version, interface source, category choices, Global Privacy Control status, and an integrity value. They do not include raw IP addresses, full user-agent strings, referrers, or browser fingerprints.
- We may aggregate or de-identify information and retain it in a form that does not reasonably identify you.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, account-scoped authorization, signed tokens, rate limits, encrypted integration tokens where applicable, HTTPS, security headers, object storage controls, and logging. No internet service or storage system is perfectly secure, so we cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur. If you believe you found a vulnerability, contact [email protected] and do not exploit or test beyond what is necessary to report it.
International transfers
x-motion.io and its providers may process information in countries other than where you live or where your organization is located. Those countries may have different data protection laws. Where required, we rely on appropriate safeguards such as contractual commitments, standard contractual clauses, or other lawful transfer mechanisms.
Your choices and rights
- You may update account information through your account or by contacting support.
- You may delete demos, hubs, projects, scenes, assets, saved prompts, integrations, and extension pairings from the product where those controls are available.
- You may unsubscribe from marketing emails using the unsubscribe link or by contacting us. We may still send transactional, security, billing, and service messages.
- Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or appeal of a privacy decision.
- If x-motion.io processed your professional or contact data on behalf of a customer through Find Leads, the customer is generally responsible for your request as controller. We will assist the customer or route the request where appropriate.
- Residents of California and other U.S. states may have rights to know, access, delete, correct, opt out of certain sharing or targeted advertising, limit use of sensitive information, and not be discriminated against for exercising privacy rights. We do not sell personal information.
- EEA, UK, Swiss, and similar-region residents may also contact their local supervisory authority if they believe their rights have been violated.
To exercise rights, email [email protected]. We may need to verify your identity or authority before acting on a request. If your data is controlled by an x-motion.io customer, we may direct you to that customer or process your request on their behalf.
Browser privacy signals
Some browsers send Do Not Track or Global Privacy Control signals. There is no consistent legal standard for Do Not Track, so x-motion.io does not currently use it as a consent instruction. The marketing website treats Global Privacy Control as a valid opt-out request and keeps marketing tracking disabled while the signal is present. If the signal arrives after a broader choice was recorded, the site writes a new consent receipt so the stored record matches the signal. Our support is published in machine-readable form at /.well-known/gpc.json. You can also use the Cookie settings control in the site footer or your browser settings, but blocking all storage may break authentication, demo unlocks, viewer analytics, or other product features.
Children
x-motion.io is intended for business and professional use and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child provided personal information to x-motion.io, contact us so we can take appropriate steps.
Changes
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date above. If changes are material, we may provide additional notice through the service, by email, or by another reasonable method. Continued use of x-motion.io after an update means the updated policy applies to your use going forward.
Contact
Questions, privacy requests, and support requests: [email protected].