XXSIGNALMARKET INTELLIGENCE
ProductEnginesAI DeskUsageTrust
Private test ↗
Legal / 01

Privacy Policy

A precise account of the information used by XSignal and the controls available to every user.

Effective July 18, 2026

XSignal does not request brokerage credentials, exchange API keys, private keys, seed phrases or full payment-card numbers. The Android app requests internet access only; it does not request access to location, contacts, SMS, call logs, camera, microphone or device files.

1. Who is responsible

XSignal, the developer identified as XSignal in the Google Play listing, is responsible for the XSignal Android application, the API used by that application, xsignal.website and related support. Privacy and data-deletion questions can be sent to support@xsignal.website.

2. Information XSignal processes

Google account information

When you choose Sign in with Google, Google provides a stable Google account identifier, your verified email address and your display name. XSignal uses those fields to create or locate your XSignal account. XSignal validates the Google identity token but does not receive or store your Google password.

Google Play purchase and credit records

If you choose to buy or restore digital credits, XSignal processes the Google Play product ID, purchase token, order identifier and state, credited and bonus amounts, refund or chargeback state, restoration result, and the resulting XSignal balance and usage ledger. The purchase token is sent to Google for server-side verification. Google processes the payment method; XSignal does not receive the full card number or bank credentials.

App activity and user-provided content

XSignal processes the market symbol, signal engine, report type, AI role and template you select; the feature request and its time; the server market context used for a result; and the resulting usage charge. If you use an AI feature, XSignal also processes the question you submit and the generated response. Entering an AI question is optional.

Network and security records

When a device connects to XSignal, hosting and security systems necessarily process the IP address, a limited HTTP user-agent string, request time, requested endpoint, response status and security events. These records are used to deliver the service, prevent abuse and investigate failures. The Android app does not use an advertising ID and does not read Android ID, IMEI, IMSI or the list of installed apps.

Support communications

If you email support, XSignal receives the sender address and the content and attachments you choose to provide. Do not send passwords, private keys, seed phrases, payment-card details, identity documents or purchase tokens unless XSignal provides a secure and necessary process.

3. Why the information is used

  • Google account identifier, email and display name: account creation, authentication, session protection and account support.
  • Purchase and ledger records: entitlement verification, credit delivery, purchase restoration, accounting, fraud prevention, refunds, chargebacks and dispute handling.
  • Selections, feature requests and results: provide signals and reports, maintain an accurate usage ledger, and operate the requested research workflow.
  • AI questions and responses: provide the AI analysis specifically requested by the user and investigate abuse or a support issue.
  • Network and security records: service delivery, rate limiting, security, reliability and legal compliance.
  • Support communications: answer the request and maintain a record of its resolution.

4. When information is sent to another service

XSignal does not sell personal data and does not use personal data for third-party advertising. Information is disclosed only as described below, to service providers acting for XSignal, or when required by law:

  • Google: Google Sign-In authenticates the account. Google Play Billing processes purchases, and the Google Play Developer API verifies purchase tokens and entitlement state.
  • AI model provider: when the AI feature is enabled and you submit an AI request, the question, selected role and relevant server market context are sent to the configured AI provider solely to generate the requested response. Account email, Google account identifier, purchase token and balance are not included in that AI request.
  • Hosting, content-delivery and security providers: infrastructure providers process encrypted traffic and limited network or security records as needed to host and protect the website and API.
  • Market-data providers: XSignal requests market information by asset symbol. XSignal does not send the user's Google identity or purchase information with those requests.
  • Authorities or professional advisers: limited information may be disclosed when legally required or reasonably necessary to protect users, enforce rights, investigate fraud or resolve a dispute.

5. User choice and necessity

Google account identifier, verified email and display name are required for an XSignal account. A user may avoid purchase processing by not buying or restoring credits. A user may avoid AI-content processing by not submitting an AI question. Core market browsing does not require location, contacts, camera, microphone or file permissions.

6. Retention

  • Account profile data is kept while the account is active and is removed when a verified account-deletion request is completed.
  • AI questions and other user-provided research content are removed or irreversibly de-identified when the associated account is deleted, unless a specific legal or security obligation requires limited retention.
  • Purchase, refund, chargeback and balance-ledger records may be retained after account deletion only for accounting, tax, fraud prevention, purchase restoration, platform disputes or legal obligations. The account address is replaced with a non-reversible internal tombstone and retained metadata is restricted to what is necessary for that purpose.
  • Operational access and security logs are retained only for a limited period appropriate to reliability, abuse prevention and incident investigation, then deleted or aggregated unless a specific incident or legal duty requires longer retention.
  • Support records are kept only as long as needed to resolve the request and satisfy security or legal recordkeeping obligations.

7. Account and data deletion

You can permanently delete your account in XSignal by opening Me → Account → Account Deletion and confirming the request. You can also follow the public instructions at xsignal.website/account-deletion. XSignal aims to complete a verified web request within 30 days. Deletion removes the account profile, active session access and app-specific user content, and de-identifies only those financial or security records that must be retained for the limited purposes listed above.

8. Security

XSignal uses HTTPS in production, validates Google identity tokens on the server, verifies Google Play purchases before crediting an account, restricts production credentials, and does not embed server verification keys in the Android app. No service can guarantee absolute security. Users should keep their Google account and device secure.

9. International processing

The service and its providers may process information outside the country or region where you live. XSignal limits processing to the purposes described in this policy and uses provider agreements and technical safeguards appropriate to the information and service involved.

10. Children

XSignal is a financial-market research service for adults and is not directed to children. XSignal does not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@xsignal.website so it can be investigated and deleted where required.

11. Google Play Data safety

The Google Play Data safety declaration for XSignal describes the same current Android data flow: account name, email and user ID; purchase history; app interactions; user-provided AI content; encrypted transmission; OAuth account creation; and account deletion. XSignal reviews that declaration before release and updates it before introducing a new permission, SDK or data use.

12. Changes and contact

If XSignal materially changes the data it collects or the way it is used, this policy, the in-app notice and the Google Play Data safety declaration will be updated before the changed production feature is released. Questions, access or correction requests, and complaints can be sent to support@xsignal.website.

XXSIGNALMARKET INTELLIGENCE

Research infrastructure for clearer decisions under market stress.

ProductSystemSignal stackAI deskUsage
LegalPrivacyTermsRisk disclosureAccount deletion
Contactsupport@xsignal.websiteHong Kong time base
© 2026 XSignal. All rights reserved.Market research only · Not investment advice