Xfigura logo

Xfigura

xfigura.ai
Moderate Risk
Updated March 16, 2026

Xfigura presents moderate risks for professional use. While the terms explicitly grant users ownership of their AI outputs from Enterprise Models, the platform retains broad rights to use all AI content for service improvement. Key concerns include vague data retention policies, limited opt-out mechanisms, and extensive indemnification requirements. The service distinguishes between Enterprise Models and Third-Party Models, with different ownership and usage rights applying to each.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Low Risk

Users retain ownership of their AI inputs. Xfigura explicitly states that users keep ownership of their AI Input and must have necessary rights to provide it.

Confidence
90%

Output Data Ownership

Moderate Risk

Users own AI outputs from Enterprise Models, but ownership of outputs from Third-Party Models depends on third-party agreements. AI outputs may not be unique, and other users could receive identical results.

Confidence
85%

Training Data Usage

Moderate Risk

Xfigura may use AI content from Enterprise Models to improve services but explicitly states they won't train on content from Third-Party Models. Users cannot opt out of this use for Enterprise Models.

Confidence
90%

Data Retention & Deletion

High Risk

No specific data retention schedules or deletion timelines are provided. Users can delete accounts but there's no clear process for data deletion requests or retention periods.

Confidence
70%

Third-Party Data Sharing

Moderate Risk

The terms don't explicitly mention selling data to third parties, but Xfigura uses third-party payment processors and may share data as required by law. The service includes Third-Party Models which inherently involves data sharing.

Confidence
75%

Opt-Out Rights

High Risk

No opt-out mechanisms are provided for data collection, model training use, or third-party sharing. The terms require users to grant broad licenses for AI content use without opt-out options.

Confidence
85%

Compliance & Certifications

Moderate Risk

The service references GDPR, UK GDPR, and includes a Data Processing Addendum with standard contractual clauses. However, no specific certifications like SOC 2, ISO 27001, or HIPAA compliance are mentioned.

Confidence
80%

Model Explainability & Auditability

High Risk

No transparency into model behavior or enterprise auditing capabilities are mentioned. The terms explicitly warn that AI outputs may be inaccurate and should not be relied upon.

Confidence
85%

Security Practices & Breach History

Moderate Risk

Limited security details provided. The DPA mentions breach notification requirements but doesn't describe specific security controls like encryption or penetration testing. No breach history disclosed.

Confidence
65%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The service offers subscription tiers with different features and includes a Data Processing Addendum for enterprise use. However, core data handling terms appear to apply equally to all users.

Confidence
70%

Human Review of User Inputs

Moderate Risk

While not explicitly stating routine human review, Xfigura reserves broad rights to monitor and investigate service use, which could include reviewing user content.

Confidence
75%

Regulatory & Litigation Exposure

Moderate Risk

The terms acknowledge potential government data requests and legal disclosures. Extensive arbitration requirements and broad indemnification clauses could expose users to legal risks.

Confidence
80%

PII & SPI Data Inventory

Moderate Risk

The terms mention collecting name, email, password, and payment information but don't provide a comprehensive data inventory. The Privacy Policy is referenced but wasn't accessible for review.

Confidence
60%

You've read all 15 risk ratings for Xfigura. Create a free account to see the exact policy wording behind each rating.