Privacy Policy
Your data, in plain English.
This policy covers xlnc.co and the services of XLNC, LLC. It says what we collect, why, who helps us process it, and how to reach us. Effective date: September 28, 2026.
The short version.
- We collect only what you type into our forms or give us when you book a call, plus a few technical details needed to store it and block spam.
- We use no tracking or advertising cookies, and we run no analytics or advertising scripts.
- We do not sell your personal information, and we do not share it for targeted advertising.
- Data our customers send for measurement stays theirs. We use it only to deliver the service they asked for, and keep it no longer than that needs.
- You can ask to see, fix, or delete your data at any time. Email matt@xlnc.co.
Who we are.
XLNC, LLC is a New Hampshire limited liability company. Mailing address: 12 Exchange St, Gorham, NH 03581, USA. Our founder works from the Philippines. For anything in this policy, write to matt@xlnc.co.
For the forms on this site, we are the controller of your data (the party that decides why and how it is used). For data our customers send us to measure, the customer is the controller and we act as their processor (in California terms, their service provider).
Privacy contact: Dr. Matt Barney, matt@xlnc.co. He is also our data protection officer under the Philippine Data Privacy Act. We have not yet appointed a representative in the European Union or the United Kingdom, and will name one here when we do. Until then, people in the EU and the UK can write to us directly at matt@xlnc.co.
What we collect on this site.
When you send a form, we collect what you enter:
- The short request form (home page, Solutions and similar pages): your email address and, if you add it, one line of text.
- The whitepaper form: first and last name, work email, role, company, what you are evaluating, an optional note, and whether you ticked the box that lets us email you about our work. We also record the campaign tags (such as utm_source) in the link you arrived by, if any.
- Emails you send us: whatever you choose to include.
- Booking a call: if you use our booking link, our scheduling provider Cal.com collects your name, email address, the time you choose, and any notes you add, and passes them to us. The meeting also appears in our Google Workspace calendar. Cal.com runs the booking page, so its own privacy policy and cookie terms also apply while you are on that page.
Giving us data is optional, but we need your email address to reply. With each form we also record, automatically: the time, the page you sent it from, the referring page, your browser type (user agent), your country as reported by our hosting network, and a salted one-way hash of your IP address that we use to stop spam and repeat abuse. Our database and our contact manager store only the hash, never the IP address itself.
Browsing without sending a form: we set no cookies of our own and run no analytics or advertising scripts. If our hosting network needs to check that a visitor is not an automated attack, it may set a strictly necessary security cookie, which is not used to track you. Our hosting network, Cloudflare, processes the technical details every website receives (such as IP address and browser type) to deliver the pages and protect them from attack, and gives us aggregate traffic counts. We serve the site's typeface ourselves, so opening a page does not contact any font provider.
Why we use it, and our legal basis.
- To reply to your request and send what you asked for, such as the whitepaper, or to arrange and hold a call you booked. Basis: steps you asked us to take before any contract, or our legitimate interest in answering you.
- To email you about our work. Basis: your consent, given by ticking the optional box on the whitepaper form or by asking us for updates. You can withdraw at any time, and every such email says how.
- To deliver the site and keep it and the forms secure and free of spam. Basis: our legitimate interest in running a safe website.
- To deliver services under a customer contract. Basis: that contract, and the customer's instructions.
- To meet legal duties, such as tax records or answering lawful requests. Basis: legal obligation.
We do not use your data for automated decisions that have legal or similarly serious effects on you.
Who helps us process it.
We use a small set of service providers. Where a provider offers data processing terms, we use them, so it may use the data only on our instructions. Telegram acts under its own privacy policy.
- Cloudflare: website hosting, security, our form database (D1), encrypted daily backups (R2), and Cloudflare Email Service, which sends our founder an emailed copy of each form submission. Cloudflare keeps the form database and its backups in its Asia-Pacific region.
- Airtable: our contact manager, which keeps a copy of form submissions (with the IP hash, not the IP address).
- Telegram: an instant alert to our founder that a form has arrived. It carries only our internal reference number for the submission, none of your details.
- Fly.io: servers for our hosted measurement service, in the European Union (Amsterdam and Frankfurt).
- Venice.ai: language models used as judges inside the measurement pipeline. We use no other model provider for customer data unless the customer's contract directs it.
- Cal.com (United States): scheduling, for calls you book through our booking link.
- Google Workspace: our email and calendar, which hold messages you send us, the emailed copies of form submissions, and calls you book.
The providers that may touch customer data are listed in our Data Processing Agreement, and customers get 30 days' notice before we add one. We may also disclose data if the law requires it, or to a buyer if our business is sold, under this same policy.
Customer data in our services.
Our services include hosted measurement, a self-hosted container, the Design-Partner Readout, custom measurement work, and Updates (in development). When a customer sends us evaluation data, traces, or outputs, that data belongs to the customer.
Our hosted service is in early access. Commitments on this page marked "at general availability" start when the hosted service reaches general availability, and we will update this page on that date. Until then, hosted early-access work is covered by the customer's order: we keep its data only for that engagement, and delete it when the engagement ends or when the customer asks, whichever comes first.
- We process it only to deliver the work the customer ordered, and keep it only as long as that work needs (see "How long we keep it").
- Our hosted measurement service runs in the European Union, on Fly.io servers in Amsterdam and Frankfurt.
- We do not sell it, we do not use it to train models, and we never give it to another customer.
- Benchmark Contribution (at general availability; it is not running today, and no customer data is used for it now). If a customer leaves Benchmark Contribution on, we add numbers from its results, at the moment we process them, to anonymous statistics. We keep no row per result. We publish only statistics that combine at least 10 customers, carry statistical noise, and cover public model versions. We commit to keep those statistics anonymous and not to try to identify any customer or person from them, and we require everyone who receives them to make the same commitment. Benchmark Contribution is off unless turned on for enterprise and regulated customers and for anyone who sends us data about people. Details are in our Data Processing Agreement.
- Language models used as judges receive only the content needed to score it.
- The self-hosted container runs in the customer's own environment. We process none of that data: the customer controls and processes it.
- We ask for redacted data wherever the work allows.
- At general availability: once a hosted result is deleted we cannot send it again. A new request is a new measurement and may give a different result, so please store your own copy.
Our Data Processing Agreement, including the standard contractual clauses where needed, applies to customer data.
Future human measurement.
We are developing adaptive measurement for people. Before we collect any data from people taking a measure, a separate privacy notice for that product will explain what is collected, the legal basis, who sees the results, and how long they are kept. That notice will take priority over this policy for that product.
How long we keep it.
- Website form data: deleted from our form database and our contact manager 24 months after you send it, or sooner if you ask.
- Call bookings: kept in Cal.com and our calendar for as long as we need them to arrange and follow up the call and our relationship with you, or longer if the law requires. Ask us and we will delete them.
- Emailed copies of form submissions: kept in our founder's mailbox and deleted within 24 months, or sooner if you ask.
- Emails you send us: kept in our mailbox for as long as we need them to deal with your request and our relationship with you, or longer if the law requires. Ask us and we will delete them.
- Backups of our form database: 90 days, then deleted automatically. So data we delete, at 24 months or at your request, leaves the backups within 90 days. When you ask us to delete your data, we remove it from live systems within one month. If we ever restore a backup, we delete your data again.
- Operational logs: 7 days or less, at our hosting providers.
- Hosted measurement during early access: kept only for the engagement, and deleted when it ends or when the customer asks, whichever comes first.
Our hosted measurement service, at general availability:
- Data you send us for a hosted measurement job: used only to run that job and deleted when its result is ready, except for the fingerprints below.
- Results from our hosted measurement service: kept encrypted for up to 72 hours after they are ready, so you can fetch them again if a transfer fails. We delete a result, and the key that unlocks it, as soon as your system confirms it received an exact copy, or after 72 hours, whichever comes first. Customers can ask for a shorter period. Results are never included in our backups.
- Delivery receipts: for 13 months we keep a record of each job with no content in it: which account ran it, when, what it cost, which model versions scored it, whether it was delivered, and digital fingerprints (hashes) of what was sent and returned. We use these only for billing, resolving disputes, security, and legal claims.
- Data sent for custom measurement work or the Design-Partner Readout: kept only as long as that work needs, then deleted or returned, as the customer chooses.
- Service performance data (at general availability): we keep figures about the speed, reliability, and availability of the models we use, combined per minute. They carry no customer, account, or request identifier and no customer content, so they cannot be linked to any customer. We use them to learn which AI systems are faster and more dependable.
- Benchmark totals (at general availability): each customer's coded share is kept for no more than 24 months, then merged into totals with no code. Published anonymous statistics are kept indefinitely.
- Billing records, and other records we must keep by law: for the period the law requires.
None of this applies to customers who run our self-hosted Docker container. We process no data from it; it stays in their own environment, and they control how long it is kept.
Your rights.
Wherever you live, you can ask us to:
- tell you what data we hold about you and give you a copy;
- correct it;
- delete it;
- send it to you or another company in a usable format;
- stop or limit how we use it, or object to our use of it;
- withdraw consent you gave, without affecting earlier use.
Email matt@xlnc.co. We may need to confirm your identity. We answer within one month, or sooner where your local law requires. If we cannot do what you ask, we will say why and how to appeal. An authorized agent may ask for you. We will not treat you differently for using any of these rights. If a customer holds your data and we process it for them, we will pass your request to that customer.
You can also complain to your data protection authority. For example: your EU supervisory authority, the UK Information Commissioner's Office, the California Privacy Protection Agency, Brazil's ANPD, the Office of the Privacy Commissioner of Canada, or the Philippines' National Privacy Commission.
California and other US states.
This section is our notice at collection under California law. In the last 12 months we collected these categories of personal information: identifiers (name, email, and a hashed IP address); professional information (role and company); general location (country); and limited internet activity (browser type, and the page and referrer at the moment you sent a form). We keep each category for the periods under "How long we keep it." Sources: you, your browser, and our scheduling provider when you book a call. Purposes: those listed above. We disclosed these categories only to service providers, such as those listed above, and only for business purposes.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not collect sensitive personal information. We do not knowingly sell or share the data of anyone under 16.
Data sent across borders.
XLNC is a US company, our founder works from the Philippines, and our providers operate in the United States, the European Union, and elsewhere. When we move personal data out of the EU, the UK, or another country that restricts transfers, we use an approved safeguard for that move, such as the European Commission's standard contractual clauses with the UK addendum, Brazil's standard contractual clauses, or the provider's certification under the EU-US Data Privacy Framework. You can ask us for a copy of the safeguard.
Children.
Our site and services are for businesses and working adults. We do not knowingly collect data from anyone under 16. If you think a child has sent us data, email us and we will delete it.
Security, and if something goes wrong.
We encrypt data in transit and at rest, keep our databases and backups private, limit access to the people who need it, and keep keys in our providers' secret stores. No system is perfectly secure. If a breach puts your data at risk, we will tell the relevant authority and you without undue delay and within the time the law sets (for example, 72 hours to the authority under the GDPR and the Philippine Data Privacy Act), and say what happened and what we are doing about it.
Changes and contact.
We will post any change here with a new date. If a change is material, we will say so at the top of this page and, where we hold your email for that purpose, tell you directly.
Questions or requests: matt@xlnc.co, or XLNC, LLC at the mailing address above. See also our Terms of Service.