AXO← Back to home
Legal

Privacy Policy

How we collect, use, and protect your data.

Version 1.0Effective July 16, 2026Updated July 16, 2026
This draft reflects AXO’s actual current infrastructure and AI processing, verified against the codebase. Two operational details couldn’t be confirmed from source code alone — a self-hosted server’s physical region, and a public sub-processor list URL — so they’ve been rephrased below to avoid stating something unverified, rather than left as guessed values.

1. Introduction

AXO Technologies Pte. Ltd. (“AXO,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you use the AXO platform (“Service”).

This Privacy Policy applies to all users of the Service, including account holders, invited collaborators, and recipients of shared documentation links.

AXO is incorporated in Singapore and is subject to the Personal Data Protection Act 2012 (“PDPA”). Where our users are located in the European Economic Area (“EEA”), United Kingdom (“UK”), or other jurisdictions with data protection legislation, we also comply with the applicable requirements of the General Data Protection Regulation (“GDPR”), the UK GDPR, and other applicable laws.

Data Protection Officer: [email protected]

2. Data We Collect

2.1 Account Data

When you register for an account, we collect:

DataPurposeLegal Basis
Email addressAccount creation, login, communicationsContractual necessity
Full nameDisplay in editor, audit trail, collaborationContractual necessity
Authentication credentialsSign-in (email/password or SSO via Google, Apple, Facebook, GitHub), managed by our authentication provider (Clerk)Contractual necessity
Organization nameMulti-tenancy, brandingContractual necessity

2.2 User Content Data

When you use the Service, we process:

DataPurposeLegal Basis
Screen recordings (video files)AI processing to generate documentationContractual necessity; Consent
Extracted video frames (screenshots)Step-by-step documentationContractual necessity
AI-generated documentation (text, steps)Core service deliveryContractual necessity
Screenshot annotations (crop, blur, arrows, boxes, text)User-directed editingContractual necessity
Brand assets (logo, colors, fonts)PDF/DOCX export customizationContractual necessity

Audio: where a recording contains an audio track, it is extracted from the video during processing as part of preparing the file for AI analysis. We do not currently transcribe, analyze, or otherwise use this audio track to generate documentation content, and it is not retained separately from the source recording.

2.3 Usage and Technical Data

We automatically collect:

DataPurposeLegal Basis
IP addressSecurity, rate limiting, abuse preventionLegitimate interest
Browser type and versionCompatibility, debuggingLegitimate interest
Pages visited and features usedService improvement, analyticsLegitimate interest
Timestamps of actionsAudit trail, debuggingLegitimate interest; Contractual necessity
Device informationCompatibility, supportLegitimate interest
Error logsDebugging, reliabilityLegitimate interest

2.4 Collaboration Data

DataPurposeLegal Basis
Invitee email addressesSending collaboration invitationsLegitimate interest; Contractual necessity
Role assignments (Admin, Editor, Viewer)Access controlContractual necessity
Edit history (who changed what, when)Audit trail for complianceContractual necessity; Legitimate interest

2.5 Data We Do NOT Collect

We do not intentionally collect sensitive personal data (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data) unless such data incidentally appears in your screen recordings, which you are responsible for redacting using the built-in blur/redact tool.

AXO does not currently process payments through the Service. If paid subscriptions are introduced in the future, this policy will be updated to describe the payment processor used and what payment-related data is collected.

3. How We Use Your Data

We use your personal data for the following purposes:

3.1 Service Delivery

  • Processing your screen recordings through the AI pipeline to generate documentation
  • Transmitting video frames and interaction data to our AI provider (Google Gemini) for analysis and text generation
  • Storing and serving your documentation, screenshots, and annotations
  • Generating PDF and DOCX exports with your branding
  • Enabling collaboration through shared projects and read-only links

3.2 AI Processing

Your video content is processed through the following AI pipeline stages, all of which run on Google Gemini models:

  1. Preprocessing: frame and audio extraction and video chunking, performed on AXO’s own infrastructure (audio is extracted but not analyzed — see 2.2).
  2. Model routing: a confidence score is computed to guide downstream processing.
  3. Analysis & documentation: sampled video frames and interaction timing data are sent to the Google Gemini API to detect actions and generate step-by-step documentation text.
  4. Screenshot extraction: a representative frame is selected or extracted for each step; Gemini may rewrite a step’s text to match what the screenshot actually shows.
  5. Highlight detection: step screenshots are sent to the Google Gemini API to detect and box the specific UI element you interacted with.

Ask AI Rewrite: when you use the “Ask AI” feature, the selected step’s text is sent to the Google Gemini API for rewriting.

Important: AXO does not use your User Content to train, fine-tune, or improve any AI models. Your content is processed for real-time documentation generation only. We contractually require Google not to use your data for model training.

3.3 Security and Compliance

  • Detecting and preventing unauthorized access, fraud, and abuse
  • Maintaining audit logs for enterprise compliance requirements
  • Enforcing our Terms of Service and Acceptable Use Policy

3.4 Service Improvement

  • Analyzing aggregate, anonymized usage patterns to improve Service features and performance
  • Monitoring system performance and reliability
  • Debugging and resolving technical issues

3.5 Communications

  • Sending account-related notifications (verification emails, password resets, collaboration invitations)
  • Providing customer support
  • Sending service updates and announcements (you may opt out of non-essential communications)

4. Data Storage and Residency

4.1 Primary Data Location

AXO’s application data is stored on infrastructure operated by AXO. This includes:

  • Convex (self-hosted application database)
  • Object storage for videos, screenshots, and exports (pCloud)
  • Redis (background job queue and caching)

4.2 Cross-Border Data Transfers

When your content is processed by our AI provider, data may be temporarily transferred to servers outside the primary data center region:

ProviderData TransferredTransfer DestinationSafeguards
Google (Gemini API)Video frames, interaction data, step textGoogle Cloud infrastructure (varies)Google Cloud DPA; Standard Contractual Clauses

Data transmitted to our AI provider is:

  • Encrypted in transit (TLS 1.2+)
  • Processed in real time and not retained by the provider beyond the API request lifecycle (subject to provider policies)
  • Not used for model training per our contractual agreement with the provider

4.3 Backup and Redundancy

Backups are stored within the same data center region as our primary infrastructure. We do not replicate your data to other geographic regions unless explicitly agreed in writing.

5. Data Sharing and Disclosure

5.1 Sub-Processors

We share data with the following categories of service providers (“Sub-Processors”), all of whom are bound by data processing agreements:

CategoryProviderPurposeData Shared
Application databaseConvex (self-hosted)Storing account, project, and document dataAccount data, document data, audit logs
Object storagepCloudVideo and screenshot storageVideo files, screenshots, annotations
AI processingGoogle (Gemini)Video analysis, step generation, rewritingVideo frames, extracted text, step text
AuthenticationClerkAccount sign-in and session managementEmail address, name, authentication credentials
Email deliveryMicrosoft 365 (Microsoft Graph API)Transactional emails, invitationsEmail addresses, names
PaymentNot applicable — AXO does not currently process payments through the Service.

A complete, current list of Sub-Processors is available on request by contacting [email protected], and any material addition will be communicated with at least fourteen (14) days’ advance notice.

5.2 Collaboration Partners

When you invite collaborators to a project, those users will have access to User Content within that project in accordance with their assigned role. When you share a read-only link, anyone with the link (and the password, if one is set) can view the documentation.

5.3 Legal Requirements

We may disclose your personal data if required by law, regulation, legal process, or governmental request, including to comply with Singapore’s PDPA or foreign law enforcement requests processed through appropriate legal channels.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the successor entity. We will notify you of any such transfer and any changes to this Privacy Policy.

5.5 No Sale of Personal Data

AXO does not sell, rent, or trade your personal data to third parties for marketing or advertising purposes.

6. Data Retention

Data CategoryRetention PeriodBasis
Account dataDuration of account + 90 days post-deletionContractual; Legal obligation
User Content (videos, docs, screenshots)Duration of subscription + 90 days post-deletionContractual
Audit logsDuration of subscription + 1 yearLegitimate interest; Compliance
Usage and technical data12 months (rolling)Legitimate interest
Transactional email logs6 monthsLegitimate interest
Backup data90 days from source deletionBusiness continuity

Upon account deletion or subscription termination, we will delete or anonymize your personal data within ninety (90) days, except where retention is required by applicable law.

7. Data Security

We implement the following technical and organizational measures to protect your data:

7.1 Technical Measures

  • Encryption in transit: all data transmitted between your browser, our servers, and our AI provider’s API is encrypted using TLS 1.2 or higher.
  • Encryption at rest: stored data (database, object storage, backups) is encrypted at rest.
  • Multi-tenant isolation: every request is scoped to your organization’s tenant, and application-level authorization checks enforce that one tenant’s data is never accessible to another.
  • Account authentication: dashboard sign-in and session management is handled by our authentication provider, Clerk, including password storage and session token lifecycle.
  • Extension authentication: the browser extension authenticates using a separate long-lived access token, stored server-side only in hashed form, valid for 30 days.
  • Share-link passwords: optional passwords set on a public share link are stored using a salted cryptographic hash, never in plaintext.
  • API security: all third-party API calls are authenticated with per-environment credentials and transmitted over TLS.

7.2 Organizational Measures

  • Access to production systems is restricted to authorized personnel on a need-to-know basis.
  • Security incidents are investigated and reported in accordance with our Incident Response Plan.
  • Employees and contractors are required to sign confidentiality agreements.
  • Regular security reviews and vulnerability assessments are conducted.

8. Your Rights

8.1 Rights Under the PDPA (Singapore)

If you are located in Singapore, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete personal data.
  • Withdrawal of consent: withdraw your consent for data processing activities based on consent. Note that withdrawal may affect our ability to provide the Service.

8.2 Rights Under the GDPR (EEA/UK)

If you are located in the EEA or UK, you have the following additional rights:

  • Erasure (“right to be forgotten”): request deletion of your personal data, subject to legal retention obligations.
  • Restriction: request restriction of processing in certain circumstances.
  • Portability: request a copy of your personal data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Automated decision-making: the AI processing described in this policy involves automated processing of your video content. However, the output is presented for your review and editing, and no solely automated decisions with legal or similarly significant effects are made about you.

8.3 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond to your request within thirty (30) days (or the timeframe required by applicable law). We may request verification of your identity before processing your request.

8.4 Complaints

If you believe your data protection rights have been violated, you may lodge a complaint with:

  • Singapore: Personal Data Protection Commission (PDPC) — www.pdpc.gov.sg
  • EEA/UK: your local supervisory authority

9. Cookies and Tracking

AXO uses cookies and similar technologies as described in our Cookie Policy. In summary:

  • Essential cookies: required for authentication, session management, and security. Cannot be disabled.
  • Analytics cookies: used to understand usage patterns and improve the Service. Can be declined.

We do not use advertising cookies or third-party tracking pixels. For full details, please refer to our Cookie Policy.

10. Children’s Privacy

The Service is not intended for use by individuals under the age of eighteen (18). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such data promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, for material changes that adversely affect your rights, by sending an email to the address associated with your account at least thirty (30) days in advance.

12. Contact Information

AXO Technologies Pte. Ltd.
Data Protection Officer: [email protected]
General inquiries: [email protected]
Support: [email protected]
Website: axo.dev

End of Privacy Policy