Who can access your data?

The short answer: During AI processing, nobody — not even XAP.ai’s own team — can read your data, because it’s protected by hardware-level isolation (see our article on Trusted Execution Environments). Outside of that processing moment, access is deliberately restricted and tested, not just promised.

1. During processing — nobody

While your message is actively being processed by XAP’s AI systems, it exists inside a Trusted Execution Environment — a hardware-sealed region that infrastructure operators, including XAP.ai’s own team, cannot read into. This isn’t a permissions setting someone could quietly change; it’s enforced by the physical processor.

2. Can XAP.ai’s own team read my data?

Not during processing, for the reason above. Outside of that window, access is deliberately limited and enforced in code, not left to individual discretion.

As one concrete, tested example: our systems are built so that infrastructure-level information and internal commands are restricted from general users by default, with access genuinely limited to specific, verified accounts. This has been directly verified through real security testing — including testing performed by outside, unprivileged accounts specifically to confirm the restriction actually holds in practice, not just on paper.

3. What can a member of the public see?

If you talk to XAP.bot — our free, publicly available agent — your conversation is private to you. Other users of XAP.bot cannot see your conversation, your data, or even that you’ve used the service, in the same way that messaging any private bot on Telegram works.

Worth knowing: like any Telegram bot, ordinary conversation is a private 1:1 channel by design — this is a property of the platform itself, not a special claim unique to XAP.

4. Does paying for XAP Advisor grant more system access?

No. Why we think this distinction matters: being a paying XAP Advisor client changes what product features you have access to. It does not, and will not, grant access to infrastructure-level commands or internal systems that are otherwise restricted.”

Why this matters: we treat ‘what you’re subscribed to’ and ‘what system-level access you have’ as two permanently separate questions. A paying customer gets a better product experience — not a backstage pass to how XAP.ai’s systems work internally. We think that’s the right way to build trust, not just a technical implementation detail.

5. How long is data kept, and who can act on it?

Free-tier conversation data (via XAP.bot) follows an automated lifecycle, not indefinite storage:

StageWhat happens
Active useData remains available to continue your conversation naturally
After a period of inactivityData is automatically archived
After a further periodData is permanently deleted

This lifecycle runs automatically — it doesn’t depend on someone remembering to clean up old data manually. For XAP Advisor (paid) clients, we’re finalising a policy that reflects the nature of an ongoing advisory relationship, and will publish it here once confirmed rather than commit to specifics prematurely.


Related articles:

  • What is a Trusted Execution Environment (TEE)?

  • Why your business data is more secure on XAP.ai

Try it for yourself
Start a free conversation with XAP.bot on Telegram — no signup required!

XAP Advisor — our premium tier — launching soon.

Or join our private Telegram group.

Last updated: 11 August, 2026 | XAP.ai