Privacy Policy
Last updated: August 13, 2026
xBound.ai ("xBound", "we", "us") builds AI-powered GTM engines and internal ops agents for businesses. This policy explains what information we collect, why we collect it, and what you can do about it. Plain English, no legalese.
It covers two different things, and they are worth keeping apart as you read:
- This website, xbound.ai, which is marketing. Anyone can visit it.
- The application, which you sign into at app.xbound.ai and connect your own accounts to. It reads real work out of your mail, calendar, chat, and task tools. That section is the one that matters most, and it starts further down.
Your use of the application is also governed by our terms of service.
Who we are
xBound.ai is operated from Chicago, Illinois, United States. For questions, requests, or complaints, contact hello@xbound.ai.
Part one: this website
Information you give us directly. When you fill out a form on this site, for example to download the free playbook or to get in touch, we collect what you enter. That is typically your name, email address, company, and anything you write in a message field.
Information collected automatically. Like most websites, we collect standard technical data when you visit: IP address, browser and device type, referring source, pages viewed, and time on site. We use this for analytics and security.
Website visitor identification. We use a third-party tool called RB2B that attempts to identify individual visitors to this site, including name, company, professional profile, and in some cases a business email address, even if you never fill out a form. It works by matching your device against the vendor's existing data. RB2B performs person-level identification on United States visitors only. We do not load it until you accept it in the banner shown on your first visit.
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout
If you are located outside the United States, you may opt out of the collection of your personal data at https://www.rb2b.com/rb2b-gdpr-opt-out
You can also write to hello@xbound.ai and we will honor your request directly.
If we contacted you first. If you received an email from us that you did not ask for, we obtained your business contact information from public sources and third-party business data providers, such as company websites, public directories, and B2B enrichment tools. Every email we send includes a way to opt out. You can also reply with "remove", or write to hello@xbound.ai, and we will delete your information and stop contacting you.
How we use website information
- To respond to you and deliver anything you requested
- To understand who is interested in our work so we can follow up
- To improve this site and our content
- To send you relevant information about what we do, if you asked for it or if you are a business contact who may find it relevant
Cookies and tracking
This site uses cookies and similar technologies for analytics and for the visitor identification described above. We ask before loading the identification tool, and if you decline we do not load it. You can also block or delete cookies in your browser settings. Doing so may affect how parts of the site work.
Part two: the xBound application
The application shows you one board built from work that already exists in your own tools. To do that, it has to read those tools. This section says exactly what it reads, where that information goes, and what we will never do with it.
Your account
To use the application you create an account with an email address. We store that, when you signed up, and which plan you are on. If you subscribe to a paid plan, Stripe processes the payment and we store the identifiers Stripe gives us so we know your subscription is active. We never see or store your full card number.
What you connect, and exactly what we ask for
Nothing is connected by default. You choose each provider, and you can disconnect any of them at any time. These are the permissions we request, copied from the live configuration:
gmail.readonlygmail.composecalendar.readonlycalendar.events
Read your mail and calendar so the board can show what is waiting on you, write a reply into your drafts, and place a hold on your calendar. Two of those four are write permissions and you should know exactly what they let us do, so read the paragraph under this table before you decide.
Microsoft
Mail.ReadMail.ReadWriteCalendars.ReadCalendars.ReadWriteoffline_accessopenidemail
The same reading and the same two writes, for Outlook and Microsoft 365. Mail.ReadWrite creates the draft, and Microsoft states in its own permissions reference that it does not include permission to send mail. Sending is a separate permission called Mail.Send, and we do not ask for it. The last three identify your account and let the connection stay alive without asking you to sign in every hour.
Slack
channels:readchannels:historychannels:joinusers:readgroups:readgroups:history
List the channels you could pick, read the ones you actually map, and turn a user id into a name. We read nothing until you map a channel yourself. A private channel additionally requires a human to invite the app, which Slack enforces and we cannot bypass.
ClickUp
chosen by you, per workspace, at the consent screen
Read your tasks so they can appear on the board, and write back the changes you make there, such as a status, a due date, or an assignee. ClickUp does not take a list of permissions from us; it asks you which workspaces to grant at the moment you connect.
Asana
tasks:readprojects:readusers:read
Read your tasks and the projects they live in so they can appear on the board, and turn an assignee id into a name. Read only, unlike ClickUp above: these permissions cannot create, complete, or delete a task, and we do not request one that can.
Monday
boards:readme:read
Read the boards you map, including their items and columns, so that work can appear on the board, and name the connected account in your settings. Read only. We do not request the write permission, because this connection never writes: clearing one of its cards marks it handled here and leaves your Monday board untouched.
Todoist
data:read
Read your projects and tasks so they can appear on the board. This is the read-only scope. Todoist also offers a read-write scope and a delete scope, and we request neither, because a board that marks things handled here rather than completing them there has no business holding either one.
Discord
bot
This one is an invite rather than a sign-in: Discord asks which server to add xBound to, and we read the channels you point it at. The permissions attached are exactly two, view channel and read message history, and nothing else. No sending, no managing, no reading your member list. Discord shows that list to whoever installs it, as checkboxes, so you approve it item by item at the moment you connect. We do not ask to identify who clicked the button, because nothing here needs to know.
Trello
a token you generate at Trello and paste in, scoped by you
Read the open cards in the lists you choose so they can appear on the board. Trello is the one connection that is not a one-click authorisation: its sign-in hands the token back in a part of the web address that browsers never send to a server, so instead you authorise at Trello, copy the token it shows you, and paste it here. That token arrives over HTTPS, is never stored in your browser and is never logged. Read only, like the rest of the task tools below and above it.
Notion
chosen by you, per database, when you share it
Read the databases you share so their items can appear on the board. Notion has no permission strings at all, so there is nothing here for us to list: access is granted per database, by you, and xBound sees only the databases you share with it. Read only, on the same terms as Monday above.
On Microsoft the application cannot send email as you. On Google it could, and does not. That split is not ours and we would remove it if we could. It is worth your time because the two guarantees are different in kind.
Microsoft separates the two permissions. Mail.ReadWrite writes a draft, and Microsoft states in its own permissions reference that it does not include permission to send mail. Sending is a separate permission, Mail.Send, and we do not request it. On Outlook you do not have to take our word for anything: the account simply has not granted us the ability.
Google has no equivalent. There is no scope that creates a draft without also permitting send. The scope we use, gmail.compose, does both, and Google lists that same scope as one that authorises its own send method. To put a reply into your Gmail drafts at all, we have to hold a permission that could send it.
So on Google this is a promise and not a property, and we would rather tell you that than let one confident sentence cover both providers when it is only true of one. What we actually do with it: the application writes the draft and stops. Nothing in it calls send. You open your drafts and send it, or you delete it.
The calendar permission is broader than the thing we do with it, for the same reason. Placing a hold needs the ability to create an event, and the scope that allows it also allows editing and deleting events that were already there. We create holds and we do not touch anything we did not create.
Only one connection is ever written to, and it is ClickUp. When you move a due date, change a status, or hand a task to a colleague on the board, that change is sent back to ClickUp. Asana, Monday, Notion, Todoist and Trello are read only, every one of them. Acting on one of their cards marks it handled here and leaves the task exactly as it was in its own tool. Mail, calendar, Slack and Discord are never written to at all.
The application also has a task list of its own, for people who do not connect a task tool. Anything you create there is stored by us and described under what we store, below.
What we store
- Connection tokens. The access and refresh tokens each provider issues, so the board can refresh without asking you to sign in repeatedly. These live in a table that the browser cannot read at all, under any account, including yours. Only our server-side background job can reach them.
- Your board. One record per user holding the computed board, which includes short excerpts of the messages and events behind each card, enough to recognize the item. It is overwritten on every run rather than accumulated, so it holds a current picture and not a history.
- Your action log. When you clear or silence an item, we record that you did, and the item it applied to, which is what the banked time figure counts. This one does accumulate.
- Tasks you create in xBound itself. The application has its own task list, so that not using ClickUp or Asana does not leave you with nowhere to put something. A task you make there is yours and it is stored on our systems: its name, any notes you add, which world it belongs to, its status, and its due date. Unlike your board, this is not overwritten on the next run. It stays until you delete the task or the account.
We do not keep a copy of your mailbox. The application reads a recent window of messages each run, uses them to build the board, and does not retain the raw messages afterward.
What leaves our systems
One outside company sees any of it, and that is Anthropic. Deciding whether a message actually needs you is a judgment, so message metadata and short excerpts are sent to Anthropic's API, which returns the sorting. That covers mail, calendar, and any Slack or Discord channel you mapped. Anthropic processes it to answer that request and does not use it to train its models.
Tasks are not sent to a model at all, whichever tool they came from and including the ones you make here. They are sorted by fixed rules on our own servers, because whether a task is overdue is arithmetic and does not need judgment.
Three things you can do on a card send more than that, and each one only happens because you asked for it:
- Asking for a draft reply sends the message you are replying to and a few earlier messages in the same thread, so the reply can pick up what was already agreed. This is the one place a fuller message body leaves rather than an excerpt.
- Asking why an item is on your board sends that one card.
- Speaking to the board sends what you said, plus a short list of the items on screen, so it can work out which one you meant.
Google user data
If you connect a Google account, this section applies to you specifically, in addition to everything above.
xBound's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and without exception:
- We use Google user data only to provide and improve the features you can see in the application, which is the board and the drafting help.
- We do not transfer it for advertising, we do not use it for personalized advertising, and we do not sell it.
- We do not use it to develop, train, or improve any generalized artificial intelligence or machine learning model, ours or anyone else's.
- No human at xBound reads your Google data, except in these narrow cases: you have given explicit permission for specific messages, for example while we help you debug something; it is necessary for security, such as investigating abuse; it is required by law; or the data has been aggregated and de-identified so it is no longer about you.
You can revoke our access at any time, either from inside the application or directly at myaccount.google.com/permissions. Revoking stops all further reading immediately.
Disconnecting and deletion
Disconnecting a provider deletes its token from our systems right away, and we stop reading from it. Your board is deliberately left as it was rather than wiped, because emptying the screen looks like data loss; the next run rebuilds it from whatever is still connected.
Deleting your data entirely is a request away. Email hello@xbound.ai and we will delete your account, your tokens, your board, and your action log. We do not make you justify the request and we do not treat you differently for making one.
Who we share it with
We use third-party services to run the business, and information passes through some of them. From the website:
- Vercel (website hosting)
- RB2B (website visitor identification)
- n8n (routing form submissions)
- ClickUp (where inbound leads are stored)
- Smartlead and Lemlist (email delivery)
- Google Workspace (email and documents)
From the application:
- Supabase (the database, authentication, and the background jobs that build your board)
- Anthropic (the model that sorts messages and events into lanes, and that answers when you ask for a draft, ask why an item is there, or speak to the board)
- Stripe (subscription payments)
- Vercel (application hosting)
Plus the providers you connect yourself, which hold your data already and are the reason the application has anything to read.
Each of these is bound by its own terms and privacy commitments. We share information with them so they can perform services for us, not so they can market to you on their own.
We do not sell your personal information.
We may also disclose information if required by law, or in connection with a sale or transfer of the business.
Your choices
Wherever you live, you can ask us to:
- Tell you what information we hold about you
- Correct it
- Delete it
- Stop contacting you
Email hello@xbound.ai and we will take care of it. We do not require you to live in a particular state or country to make one of these requests, and we will not treat you differently for making one.
Retention
- Connection tokens: until you disconnect that provider or delete your account, whichever comes first.
- Your board: it is overwritten on every run, so what we hold is the latest one, and it is removed when you delete your account.
- Your action log: kept while your account exists, because it is what the banked time total counts, and removed when you delete the account.
- Tasks you created in xBound itself: kept until you delete the task, and removed with the account.
- Website and marketing information: kept for as long as it is useful for the purposes described above, and deleted when it is not, or sooner if you ask.
Security
Tokens are stored in a table with row level security enabled and no read policy for signed-in users, which means no browser session can retrieve them, including your own. Only the server-side job can, and it runs with credentials that never reach the client. Every tenant can read only their own board, enforced by the database rather than by the application.
We use reputable vendors and standard safeguards. No system is perfectly secure, and we cannot guarantee absolute security. If we ever have a breach that affects you, we will tell you.
Children
This site and the application are intended for business audiences and are not directed at anyone under 18. We do not knowingly collect information from children.
Changes
If we change this policy, we will update the date at the top of this page. Material changes will be noted here, and account holders will be told directly.