Legal
Privacy notice
What xs1.ai collects, why, where it goes and how long we keep it — written to match what the site actually does. The short version: we collect what you choose to send us, plus the standard logs any website produces.
- Effective
- Effective October 2026
- Applies to
- Applies to xs1.ai
- Reading time
- 5 min read
Draft — pending legal review. This text describes how the site works today; the wording may change after review.
In short
We collect what you type into the contact and Work with XS1 forms, plus standard hosting logs.
Submissions are stored in XS1's project database and emailed to the XS1 team so a person can reply.
No analytics or advertising cookies, no tracking pixels, and we never sell personal information.
Please don't send health or genetic data about identifiable people, or other sensitive personal data, through the site.
Where information goes
Everything the site collects, in one view
- Contact and Work with XS1 formsWhat you type, when you press sendXS1 project databaseXS1 team inbox
- Operator sign-inXS1 staff onlyAccount recordsSession token in the browser
- Email from the siteTransactional only — no newsletterDelivery logUnsubscribe list
- Any page viewStandard web requestsHosting-provider logsGoogle Fonts request
No analytics or advertising cookiesNo tracking pixelsNever sold
Who we are
This notice explains how XS1 ("XS1", "we", "us") handles personal information collected through the website at xs1.ai. XS1 is a frontier AI research company.
For questions about this notice, or requests about your information, use the contact form and choose Privacy request.
What this notice covers
It covers the public website, the contact and Work with XS1 forms, operator sign-in for XS1 staff, and email sent from the site.
Contracted engagements and research partnerships are covered by the written agreement for that work, which takes precedence where it differs from this notice.
Information you send us
We only collect what you type into a form and choose to send.
| Form | What it asks for | Required |
|---|---|---|
| Contact (/contact) | Topic, name, email, organization and your message. | Topic, name, email and message |
| Work with XS1 (/request) | Area or division, name, work email, organization, a summary of the work, and optionally current systems, constraints, desired outcome, timeline, budget or funding context, and whether you would rather discuss specifics privately first. | Name, work email and summary |
- Contact (/contact)
- What it asks forTopic, name, email, organization and your message.
- RequiredTopic, name, email and message
- Work with XS1 (/request)
- What it asks forArea or division, name, work email, organization, a summary of the work, and optionally current systems, constraints, desired outcome, timeline, budget or funding context, and whether you would rather discuss specifics privately first.
- RequiredName, work email and summary
When you send a form, the submission is stored in XS1's project database and emailed to the XS1 team inbox so a person can read it and reply. Your email address is set as the reply-to address, so our answer comes straight to you.
Please don't send sensitive data
Do not include personal health or genetic data about identifiable people, or other sensitive personal data, in a form. If something like that reaches us, we delete it from the submission once we notice it and ask you to share what we need another way.
Operator accounts
Operator login is for XS1 staff only. Accounts are issued by XS1; there is no public sign-up. For each account we hold the sign-in email, a display name, an optional recovery email, the account's role, and authentication records, including two-factor settings where they are enabled.
When an operator signs in, a session token is kept in that browser's local storage so they stay signed in. Signing out removes it.
Email we send
The site sends transactional email only: notifications to XS1 about new submissions, account emails for operators such as invitations and password links, and messages XS1 staff send from the site. There is no newsletter or marketing list.
Each email is logged — recipient, message type, delivery status and time — so we can confirm it arrived. Emails include an unsubscribe link. If you use it, your address goes on a suppression list and the site stops emailing it; operators may still receive essential account emails, such as sign-in links.
Information collected automatically
Like any website, the site's hosting provider records standard request logs — IP address, browser details, the page requested and the time — to deliver the site and protect it from abuse. If a page fails to load, a technical error report (the error and the page it happened on) may be sent to the hosting platform so the problem can be fixed.
The site's fonts are loaded from Google Fonts, so your browser connects to Google's servers, which receive your IP address and browser details.
We do not use analytics or advertising cookies, tracking pixels, or third-party advertising.
Browser storage
The public site does not set cookies. It uses your browser's own storage for two small conveniences, and one more if you are an operator:
| Key | Where | Why |
|---|---|---|
xs1-motion | Local storage | Remembers your Motion setting (full or reduced animation), if you change it. |
xs1:intro-seen | Session storage | Skips the home-page intro after you have seen it once in a tab. Cleared when the tab closes. |
sb-…-auth-token | Local storage | Keeps an operator signed in. Only set when an operator signs in; removed on sign-out. |
xs1-motion- WhereLocal storage
- WhyRemembers your Motion setting (full or reduced animation), if you change it.
xs1:intro-seen- WhereSession storage
- WhySkips the home-page intro after you have seen it once in a tab. Cleared when the tab closes.
sb-…-auth-token- WhereLocal storage
- WhyKeeps an operator signed in. Only set when an operator signs in; removed on sign-out.
Inside the operator area the browser also keeps a few interface preferences. You can clear all of this at any time in your browser settings.
How we use information
- To read and reply to your message or request, and to decide with you whether and how XS1 can help.
- To scope, propose and run contracted work or a research partnership, if we go ahead together.
- To run operator accounts and keep them secure.
- To deliver, secure and fix the website.
- To meet our legal obligations.
We do not sell personal information, use it for advertising, or make automated decisions about you that have legal or similarly significant effects.
If you are in the European Economic Area or the United Kingdom, our legal bases are: our legitimate interests in answering inquiries and running a secure website; taking steps you ask for before entering a contract; your consent, where we ask for it (you can withdraw it at any time); and legal obligations.
How long we keep it
- Form submissions: kept for as long as we need them to respond and follow up, and for any longer period a resulting agreement or the law requires, then deleted.
- Operator accounts: kept while the account is active and for a limited period after access ends.
- Email logs and the suppression list: kept so we can confirm delivery and keep honoring unsubscribe requests.
- Hosting logs: kept by the hosting provider for its standard retention period.
Your choices and rights
Depending on where you live, you may have the right to access the information we hold about you, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent. You can also complain to your local data-protection authority — we would appreciate the chance to help first.
To make a request, use the contact form and choose Privacy request. Tell us what you would like us to do and which email address it concerns. We acknowledge requests within 1–2 business days and respond within one month. We may need to confirm it is you before acting.
Security
The site is served over HTTPS. Submissions and operator data are stored with access controls and are available only to XS1 staff who need them. No system is perfectly secure; if you think you have found a vulnerability, please follow our vulnerability disclosure policy.
Children
The site is not directed at children, and we do not knowingly collect information from anyone under 16.
Changes to this notice
We update this page when the way the site handles information changes, and change the effective date at the top. Significant changes are called out on this page.
Contact
Use the contact form and choose Privacy request. We reply within 1–2 business days.