Xfigura
xfigura.aiXfigura presents moderate risks for professional use. While the terms explicitly grant users ownership of their AI outputs from Enterprise Models, the platform retains broad rights to use all AI content for service improvement. Key concerns include vague data retention policies, limited opt-out mechanisms, and extensive indemnification requirements. The service distinguishes between Enterprise Models and Third-Party Models, with different ownership and usage rights applying to each.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of their AI inputs. Xfigura explicitly states that users keep ownership of their AI Input and must have necessary rights to provide it.
Output Data Ownership
Users own AI outputs from Enterprise Models, but ownership of outputs from Third-Party Models depends on third-party agreements. AI outputs may not be unique, and other users could receive identical results.
Training Data Usage
Xfigura may use AI content from Enterprise Models to improve services but explicitly states they won't train on content from Third-Party Models. Users cannot opt out of this use for Enterprise Models.
Data Retention & Deletion
No specific data retention schedules or deletion timelines are provided. Users can delete accounts but there's no clear process for data deletion requests or retention periods.
Third-Party Data Sharing
The terms don't explicitly mention selling data to third parties, but Xfigura uses third-party payment processors and may share data as required by law. The service includes Third-Party Models which inherently involves data sharing.
Opt-Out Rights
No opt-out mechanisms are provided for data collection, model training use, or third-party sharing. The terms require users to grant broad licenses for AI content use without opt-out options.
Compliance & Certifications
The service references GDPR, UK GDPR, and includes a Data Processing Addendum with standard contractual clauses. However, no specific certifications like SOC 2, ISO 27001, or HIPAA compliance are mentioned.
Model Explainability & Auditability
No transparency into model behavior or enterprise auditing capabilities are mentioned. The terms explicitly warn that AI outputs may be inaccurate and should not be relied upon.
Security Practices & Breach History
Limited security details provided. The DPA mentions breach notification requirements but doesn't describe specific security controls like encryption or penetration testing. No breach history disclosed.
Enterprise vs. Consumer Risk Delta
The service offers subscription tiers with different features and includes a Data Processing Addendum for enterprise use. However, core data handling terms appear to apply equally to all users.
Human Review of User Inputs
While not explicitly stating routine human review, Xfigura reserves broad rights to monitor and investigate service use, which could include reviewing user content.
Regulatory & Litigation Exposure
The terms acknowledge potential government data requests and legal disclosures. Extensive arbitration requirements and broad indemnification clauses could expose users to legal risks.
PII & SPI Data Inventory
The terms mention collecting name, email, password, and payment information but don't provide a comprehensive data inventory. The Privacy Policy is referenced but wasn't accessible for review.
You've read all 15 risk ratings for Xfigura. Create a free account to see the exact policy wording behind each rating.