01 Who we are

xDitto is an AI "digital clone" platform operated by Future of Work Limited, the company behind Notchup. xDitto learns your voice, tone, knowledge and decision-making style so that an AI agent (your "Clone") can communicate and act on your behalf across email, messaging, meetings and the tools you connect.

Because of what xDitto does, we process information that is unusually personal to you — including voice and video samples, documents from your knowledge drive, and the content of the conversations your Clone handles. This Privacy Policy explains what we collect, how and why we use it, who we share it with, how long we keep it, and the rights and choices you have.

For the purposes of this Policy, the data controller is Future of Work Limited (registered in England and Wales under company number 12752302), whose registered office is at The Retreat, 406 Roding Lane South, Woodford Green, Essex, United Kingdom, IG8 8EY. This policy applies to our websites (including www.xditto.com), our apps and online services, and to people who interact with a User's Clone.

When you use your Clone to process other people's personal data, or where we process data on your instructions in connection with services we provide to a business customer, we generally act as a data processor on your behalf; in those cases you should direct privacy requests to the User or business customer that controls that data.

02 Our Privacy Promise

We are committed to protecting your personal information, being transparent about the data we hold, and giving you control over how it is used. Your knowledge drive, voice and video samples, and the content your Clone handles are used to operate and improve your own Clone.

We do not sell your personal data. We do not use your private knowledge-drive content, biometric data or conversation content to train models for other customers or to build general-purpose foundation models, except where you give us explicit consent or where we use data that has been aggregated, de-identified or anonymized so that it no longer identifies you.

You define what your Clone can and cannot do, and you can review, restrict, export or delete your training data and your Clone at any time. We process personal data in line with applicable laws, including the UK GDPR, the EU GDPR, the UK Data Protection Act 2018, the California Consumer Privacy Act (as amended) and other U.S. state privacy laws.

We may update this policy from time to time; any revisions will be posted on this page with a new "Last updated" date, and we will notify you of material changes where appropriate.

03 What Information We Collect

We collect the following categories of personal data:

• Account and contact data: your name, email address, username, password, telephone number, job title, organization, billing details and your communication preferences.

• Voice, video, image and biometric data: voice recordings, video and photographs you provide or authorize, and data derived from them (such as a voiceprint or a scan of facial geometry) that may be considered biometric identifiers or biometric information under laws such as the Illinois Biometric Information Privacy Act ("BIPA"). We use these solely to create, operate and improve your Clone. See "Consent" below.

• Knowledge drive and training content: documents, files, notes, past projects, FAQs, proposals and other materials you upload or sync (for example from Google Drive, Dropbox or OneDrive), plus the answers, samples and instructions you give when training your Clone and defining its guardrails.

• Connected accounts and integration data: when you connect tools such as Gmail, Microsoft Outlook, Slack, HubSpot, Salesforce or cloud storage, we access the data and permissions you authorize — for example messages, contacts, calendar entries, files and records.

• Conversation and activity content: the emails, messages, meeting interactions, tasks and other communications your Clone sends, receives or handles on your behalf, including transcripts, summaries and records of the actions it executes.

• Payment data: if you buy a paid plan, our payment processor (currently Stripe, Inc.) collects your payment card and billing information. We do not store full payment card numbers.

• Device, log and usage data: IP address, device and browser type, operating system, unique identifiers, approximate (IP-based) location, and information about how you use our sites and services, collected automatically and through cookies.

• Information from other sources: limited information from your organization, from people who refer you, from social login providers (such as LinkedIn) if you choose to sign in that way, and from analytics and security vendors.

04 How we use the information we collect

We use personal data to:

• create, train, operate, personalize and improve your Clone;

• create and administer your account and authenticate you;

• provide the features you request, including connecting tools and executing the workflows and actions you authorize;

• process payments and manage your subscription;

• provide customer support and respond to your requests;

• maintain security, prevent fraud and abuse, and debug our services;

• analyze and improve our products, including testing and research;

• send service communications and, where permitted, marketing you can opt out of; and

• comply with our legal obligations and enforce our terms.

05 Lawful basis we use to process your information

If you are in the United Kingdom or European Economic Area, we rely on the following legal bases under the UK GDPR and EU GDPR. We may rely on more than one basis depending on the specific purpose for which we process your data:

• Contract: to provide the services you request, manage your account and process payments.

• Consent: to process biometric data, for certain marketing, and for other processing where we ask for it. You may withdraw consent at any time.

• Legitimate interests: to secure, maintain, analyze and improve our services, prevent fraud and abuse, and conduct marketing, where those interests are not overridden by your rights.

• Legal obligation: to comply with applicable laws and respond to lawful requests.

07 Disclosure of your information

We do not sell your personal data. We disclose it only as described here:

• Service providers: hosting and infrastructure, AI and model-inference providers, analytics, security and fraud-prevention, customer support, and payment processing (Stripe) vendors who process data on our behalf under confidentiality and security obligations.

• Connected third-party tools: where you enable an integration, data flows to and from that service as needed to provide the functionality you turn on; their use of your data is governed by their own privacy policies.

• People your Clone interacts with: when your Clone communicates or acts on your behalf, the recipients receive the relevant content.

• At your direction: with other parties when you ask us to share or make content available to them.

• Legal and safety: to comply with law, legal process or enforceable governmental requests, to enforce our terms, and to protect the rights, property or safety of you, us or others.

• Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, personal data may be transferred to the successor or acquirer.

• Group companies: with affiliates of Future of Work Limited that help us operate the services, under this policy.

• Aggregated or de-identified data: which cannot reasonably be used to identify you, for our lawful business purposes.

08 Third-Party Platform Data & Limited Use

When you connect third-party accounts and platforms to xDitto — for example Google Workspace, OpenAI, Microsoft 365, Zoom, and Meta / WhatsApp Business — we access and process data from those services only to provide and improve the features you enable, and we handle that data in accordance with each provider's developer and data-use requirements, including the commitments below. You can review and revoke any connected integration at any time in your account settings, which stops our further access to that platform's data.

Google Workspace APIs. xDitto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of data obtained from Google Workspace APIs (such as Gmail, Google Calendar, Google Drive and Contacts), including raw data and data aggregated, anonymized or derived from it, is limited to providing or improving user-facing features that are prominent in the xDitto interface; we do not transfer this data except to provide or improve those features with your consent, for security purposes, to comply with applicable law, or as part of a merger or acquisition with your prior consent; we do not allow humans to read this data except with your affirmative consent, for security, to comply with law, or where it is aggregated or anonymized and used for internal operations; and we never use it for advertising, to train generalized AI or machine-learning models, or to determine credit-worthiness or for lending, nor do we sell it.

Read the Google API Services User Data Policy →

OpenAI. We use OpenAI's API to power certain AI features. Content sent to OpenAI to provide those features is processed under OpenAI's API data-usage and enterprise-privacy commitments: it is not used to train or improve OpenAI's models unless you explicitly opt in, remains owned by you, is encrypted in transit and at rest, and is retained by OpenAI only for a limited period (currently up to 30 days) to provide the service and detect abuse before deletion, except where longer retention is required by law.

Read OpenAI's Enterprise privacy commitments →

Microsoft 365 (Microsoft Graph). Our use of data obtained through Microsoft 365 and the Microsoft Graph API (such as Outlook mail and calendar, Teams, and OneDrive files) complies with the Microsoft APIs Terms of Use. We request only the minimum data and permissions needed to provide the features you enable, use that data solely in connection with those features, do not use it for advertising or marketing other than in connection with the application, obtain the consents required, apply reasonable security measures, and honour applicable retention, correction and deletion requirements.

Read the Microsoft APIs Terms of Use →

Zoom. Our use of data obtained through the Zoom APIs complies with the Zoom API License and Terms of Use and the Zoom Marketplace Developer Agreement. We access Zoom data only to perform the integration activities and to provide the features you request, in accordance with Zoom's API documentation and use rules, and we describe how we collect, use, share, retain and otherwise process that data as required by Zoom.

Read the Zoom API License and Terms of Use →

Meta / WhatsApp Business. Our use of data obtained through Meta's platforms and the WhatsApp Business Platform (Cloud API) complies with the Meta Platform Terms, the Meta Developer Policies, and the WhatsApp Business Solution Terms. We process this data only for the permitted purposes of providing and improving the messaging features you enable and as permitted by applicable law; we do not use WhatsApp Business data to create, develop, train or improve generalized AI or machine-learning models; and we adhere to applicable retention limits (for example, Cloud API message retention of up to 30 days).

Read the WhatsApp Business Solution Terms →

09 Security of your information

We use appropriate technical, organizational and administrative safeguards designed to protect personal data, including encryption of data in transit and at rest, access controls, and your private knowledge vault, which reveals specific data only when you authorize it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please help protect your account by using a strong password and keeping your credentials confidential.

Protection of sensitive data. Some of the data we process is especially sensitive — in particular your biometric data (voiceprints and facial-geometry scans), the contents of your knowledge drive, and the communications your Clone handles. We apply heightened safeguards to this data, including: encryption in transit (TLS) and at rest; strict role-based access controls and least-privilege access limited to personnel who genuinely need it; logical isolation of each User's knowledge drive in a private vault that discloses specific data only when you authorize it and within the guardrails you set; pseudonymization or de-identification where feasible; contractual confidentiality, security and processing restrictions on the service providers and sub-processors who handle this data on our behalf; monitoring, logging and access reviews; and defined retention limits after which biometric and other sensitive data is permanently deleted. We process sensitive data only with your consent or as otherwise permitted by law, and never to infer characteristics about you or for purposes incompatible with those described in this policy.

Cookies and similar technologies. We and our partners use cookies, pixels and similar technologies to operate and secure our sites, remember your preferences, understand usage and measure and improve performance and marketing. You can control cookies through your browser settings and, where offered, our cookie preferences tool. Our sites do not currently respond to "Do Not Track" signals.

International data transfers. We and our service providers may process personal data in countries other than where you live, including the United Kingdom, the European Economic Area and the United States. Where we transfer personal data across borders, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement/Addendum and the European Commission's Standard Contractual Clauses, or rely on another lawful transfer mechanism.

Children. xDitto is not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 where permitted by local law). If you believe a child has provided us personal data, contact us at dataprotection@notchup.com and we will delete it.

10 Retention period

We retain personal data for as long as needed to provide the services and for the purposes described in this policy. Account and profile data is retained while your account is active; knowledge-drive, biometric, training and conversation data is retained while your Clone is active or until you delete it; payment records are retained as required for tax, accounting and legal purposes.

We may retain information longer where necessary to comply with legal obligations, resolve disputes or enforce our agreements, and we may keep aggregated or anonymized data indefinitely. You can delete your data and your Clone at any time, subject to limited legal retention requirements.

11 Your rights as a data subject

UK and EEA residents. Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

U.S. state privacy rights. Depending on your state of residence (including under the California Consumer Privacy Act as amended by the CPRA, and the privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states), you may have the right to:

• know and access the personal information we have collected about you;

• request deletion of your personal information;

• correct inaccurate personal information;

• obtain a portable copy of your personal information;

• opt out of the "sale" or "sharing" of personal information and of targeted advertising; and

• not be discriminated against for exercising your rights.

We do not sell your personal information for money, and we do not use or disclose sensitive personal information (including biometric data) for purposes beyond those described in this policy. Where we use advertising cookies, such disclosures may be considered a "sale" or "share" under some state laws; you can opt out through your browser or our cookie controls. You may use an authorized agent and may appeal a decision by replying to our response.

To exercise any of these rights, email dataprotection@notchup.com. We may need to verify your identity before responding, and we will respond within the timeframes required by law.

12 Complaints and Contact

If you have questions, requests or complaints about this Privacy Policy or how your personal data is handled, please contact us in the first instance at dataprotection@notchup.com.

Future of Work Limited (xDitto / Notchup), The Retreat, 406 Roding Lane South, Woodford Green, Essex, United Kingdom, IG8 8EY.

You also have the right to lodge a complaint with your data protection supervisory authority. In the UK this is the Information Commissioner's Office, which can be contacted via ico.org.uk. If we update this policy, we will post the revised version on this page with a new "Last updated" date.