Policies

Privacy Policy

Version 3.0 Last updated 2026-08-15

Introduction and scope

Xive is a social and creator platform. People use it to post, watch and comment on video and Shorts, broadcast and watch live streams, send direct and group messages, make voice and video calls, follow and befriend other people, and support creators with paid gifts and subscriptions. This Privacy Policy explains how Velaris Management Group LLC, a Kentucky manager-managed limited liability company that owns and operates the Xive platform (“Xive,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with thexive.com, the Xive mobile applications, and related services (collectively, the “Services”).

Velaris Management Group LLC owns and operates the Xive platform and is the entity responsible for the personal information described here; see https://velarismanagement.com/. Privacy and data-protection inquiries for the Services are handled through the contact addresses below.

The Services are for adults. You must be at least 18 years old to hold a Xive account. See “Minimum age” below.

This policy does not apply to information about Xive employees, contractors, or job applicants processed solely for employment purposes, which is covered by separate notices where required.

Laws differ by country and region. Where this policy describes rights or practices (for example, GDPR- or CCPA-style rights), those sections apply to you only to the extent required by the law applicable to our relationship with you. Nothing in this policy limits rights you may have under mandatory local law.

This document is for transparency and operational clarity. It is not legal advice for you or for Xive; you may wish to consult your own counsel regarding your situation.

Roles: controller and processors

For personal information whose purposes and means of processing we determine in connection with the Services, we act as a data controller (or the equivalent concept under your law). We also use processors — infrastructure, payment, communications, and safety vendors — that process personal information on our instructions. The providers we currently rely on are named in “Who we share personal information with” below and in our Third-Party Vendors policy; subprocessors may change as we operate the Services.

Some parties act as independent controllers rather than as our processors. In particular, Stripe, Apple, and Google process your payment and purchase data under their own privacy policies as well as ours.

Personal information we collect

“Personal information” (or “personal data”) means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked — directly or indirectly — with an identified or identifiable individual. It does not include data that has been de-identified or aggregated in line with applicable law.

Account and identity information. When you create an account we collect your email address, username, display name, and profile photo where you provide one. Sign-in credentials are handled by our identity provider at auth.thexive.com; Xive does not store your password. To satisfy the platform minimum age we collect either a date of birth or an age attestation, and we record the date on which age verification succeeded.

Profile and social graph. Your bio, links you add to your profile (for example a Twitch or other social handle), your follows, friends, top friends, blocks, and the communities and creators you support.

Content you create. Posts, Shorts, comments, photos, video, audio, live broadcasts and their recordings, direct and group messages, live-chat messages, reactions, gifts you send or receive, reports you file, and the metadata that comes with them (timestamps, media dimensions, duration, and similar).

Live streaming and calls. When you broadcast, we hold the stream credentials issued to your channel (stored encrypted), the start and end times of each broadcast, viewer and chat activity during it, and the recording of the broadcast itself. When you place or join a voice or video call, we process the signalling data needed to connect it and the participation record (who joined, when, for how long); we do not record calls.

Payments and creator earnings. Purchases of credits, gifts, Sparks, and subscriptions are processed by Stripe on the web and by Apple’s App Store or Google Play in our mobile apps. We receive confirmation of the transaction, the product purchased, the amount, and the processor’s transaction identifiers. We do not receive or store full card numbers. If you take payouts as a creator, Stripe Connect collects and holds the identity, bank, and tax information required to pay you; we receive account status and payout results, not your full banking credentials.

Device, technical, and log data. IP address, browser and device type, operating system, app version, push notification tokens, diagnostic and error logs, and security signals such as failed sign-in attempts or abuse patterns tied to an address or account.

Sign-in telemetry and approximate location. When you sign in we record the event with your IP address and device information so you can review your sessions and so we can detect account takeover. Where your client supplies coordinates, we convert them into a city and region using OpenStreetMap’s Nominatim service, which means those coordinates are sent to that third party for that purpose. We do not track continuous or background location, and we do not collect GPS location for advertising.

Cookies, local storage, and similar technologies. Described in our Cookie Policy.

Information from third parties. Payment and payout status from Stripe, Apple, and Google; purchase validation results from the app stores; abuse, fraud, and security signals from our edge and infrastructure providers; and reports about you submitted by other users.

Where the GDPR or a similar framework applies, we rely on one or more of the following legal bases, depending on the activity: performance of a contract with you (operating your account, delivering content you request, completing purchases and payouts); legitimate interests that are not overridden by your interests or fundamental rights (securing the Services, preventing abuse and fraud, moderating content, measuring reliability, and improving the product); compliance with a legal obligation (tax and financial records, responding to lawful requests, age assurance); and, where required, your consent (for example non-essential cookies, or push notifications where consent is the appropriate basis).

You may withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal, except where otherwise limited by law.

How we use personal information

  • Operate the Services: deliver feeds, Shorts, video, live streams and replays, messaging, calls, notifications, and search.
  • Create and manage accounts, authenticate you, keep you signed in, and let you review and end your sessions.
  • Enforce the 18+ minimum age and other eligibility rules.
  • Rank and recommend content, including trending, discovery, and the live and Shorts rails on the home screen.
  • Count views, viewers, and engagement so creators and we can see how content performs.
  • Process purchases of credits, gifts, Sparks, and subscriptions, calculate creator earnings, run reserves and payouts, and detect payment fraud and chargeback abuse.
  • Moderate content and accounts, act on reports, and enforce our Terms, Community Standards, and other policies.
  • Keep the platform secure: detect and block scanners, credential stuffing, spam, ban evasion, and other abuse, including by blocking IP addresses at our network edge.
  • Send transactional and service messages by email and push notification, and notify you about activity you asked to follow.
  • Provide support and respond to your requests, including data export and deletion.
  • Comply with law, respond to lawful requests from public authorities, and establish or defend legal claims.

We do not use your personal information to serve targeted advertising, and we do not build advertising profiles about you. The advertising we show on the website is non-personalised: an ad is selected from the content of the page and coarse location, not from your history, your activity on Xive, or your account.

Automated systems and content screening

We use automated systems alongside human review. Being specific about them matters more than describing them in the abstract:

  • Text screening. Captions, posts, comments, and live-chat messages pass through a deterministic filter that blocks or holds certain content for review.
  • Image and video screening. Media uploaded to the platform is screened by a machine-learning model running on our edge provider’s infrastructure. That system only raises a flag for human moderators; it does not delete, hide, or alter your content on its own.
  • Ranking and recommendation. We use signals such as recency, engagement, follows, and your interactions to order feeds and suggest content.
  • Abuse and fraud detection. Automated rules identify spam, scraping, exploit scanning, payment fraud, and coordinated abuse, and may throttle or block the source.
  • Age gating. If you submit a date of birth showing you are under 18, your account is closed automatically. This is an automated decision with a significant effect, and you may contest it through our Appeals Process.

Except for the age gate described above, enforcement decisions that remove content or restrict an account involve human review. Where the law requires it, we will provide information about the logic involved and the consequences of such processing.

What other people can see

Xive is a social platform, so much of what you do is visible to others by design. Your username, display name, profile photo, bio, and profile links are public. Posts, Shorts, comments, live broadcasts, replays, and live-chat messages are visible according to the audience you choose when you publish them. Follower and following counts, gifts sent during a live stream, and supporter status are visible in-product.

Direct and group messages are visible to the people in the conversation. They are stored encrypted at rest on our servers, and they can be produced to moderators or to authorities where our policies or the law require it — so they are private from other users, not from us in every circumstance.

Live broadcasts are recorded by default so they can be replayed. Anything you say or show on a broadcast may be watched later by anyone who could watch it live.

Who we share personal information with

We share personal information with the providers that run the Services. The material ones today are:

  • Google Cloud — compute and managed PostgreSQL hosting for the platform and its database (United States).
  • Cloudflare — DNS, CDN, network security and bot mitigation; Cloudflare Stream for live ingest, recording, and video delivery; Cloudflare R2 for stored media; and Cloudflare Workers AI for the media screening described above.
  • Stripe — card payments on the web, and Stripe Connect for creator identity verification and payouts.
  • Apple and Google — in-app purchases made through the App Store and Google Play, and delivery of push notifications to iOS and Android devices.
  • Expo — the push notification service that routes our notifications to Apple’s and Google’s push gateways.
  • Postmark — transactional and administrative email.
  • OpenStreetMap Foundation (Nominatim) — converting coordinates supplied at sign-in into a city and region.
  • Microsoft Azure — storage of a legacy set of media files that predates our move to Cloudflare R2.
  • Google (Google Analytics) — website usage analytics, on the website only.
  • Google (Google AdSense) — non-personalised advertising on the website. Receives page context, IP address, and approximate location, and not your account identity.

Our identity provider, our realtime messaging service, and our voice and video calling service run on infrastructure we operate ourselves rather than on a third-party SaaS platform.

We may also disclose personal information to: other users, according to your settings and the nature of the Services; professional advisers such as lawyers and auditors under confidentiality obligations; law enforcement, regulators, courts, or others when we believe in good faith that disclosure is necessary to comply with law, to respond to lawful requests, or to protect the rights, safety, or integrity of users, Xive, or the public; and a buyer or successor in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards and notice where required.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under U.S. state privacy laws — our advertising is non-personalised and is selected from page content rather than from any profile of you. We use Google Analytics and Google AdSense on our website; our mobile apps contain no advertising or analytics software development kits.

International transfers

Our servers and primary database are hosted in the United States. Media and live video are delivered through a global content delivery network, which means copies of published content may be cached in the country closest to the person watching it. Our payment, email, and push notification providers process data in the United States and in other countries where they operate.

Where required — for example for transfers from the EEA, UK, or Switzerland — we implement appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, supplemented by technical and organisational measures where appropriate. You may request further information about these safeguards by contacting [email protected].

How long we keep personal information

We keep personal information for as long as we need it for the purposes described in this policy, unless a longer period is required or permitted by law. Some specifics worth stating plainly:

  • Account and profile data is kept while your account exists.
  • Posts, Shorts, comments, and messages are kept until you delete them or we remove them under our policies.
  • Recordings of live broadcasts are retained by our video provider for 21 days, after which they are deleted automatically unless they have been published as a replay or preserved for a safety or legal reason.
  • Data export archives are generated on request and the download link expires after 7 days.
  • Financial records — purchases, creator earnings, payouts, chargebacks, and tax documentation — are kept for the periods required by tax and accounting law, typically several years, even after an account is deleted.
  • Security and access logs are time-boxed on a rolling schedule, and kept longer where they relate to an open investigation.
  • Moderation records, including content preserved for an open case, are kept until the matter is resolved and for the period our Enforcement Policy requires.

When you delete your account, we begin a deletion workflow across our systems. Residual copies may persist briefly in backups and caches until routine overwrite cycles complete. Our Data Retention Policy describes the full picture.

How we protect personal information

We implement technical and organisational measures designed to protect personal information against unauthorised access, loss, or alteration. These include TLS for data in transit, encryption at rest provided by our cloud storage and database providers, application-level encryption of direct and group message content, encryption of the streaming credentials issued to creators, row-level security policies in the database, signed and expiring URLs for private media and video playback, and restricted administrative access.

No method of transmission or storage is completely secure. Use a strong, unique password, keep your devices secure, and never share your stream key. Our Data Storage & Security Overview has more detail, and our Incident Response policy describes what happens if something goes wrong.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal information; to restrict or object to certain processing; to withdraw consent; to opt out of certain “sharing” or targeted advertising where defined by law; and to lodge a complaint with a supervisory authority. California and other U.S. state residents may have additional rights under applicable state law.

In-product, you can edit or delete your profile information and content, control who can message you and see your activity, manage notification preferences, review and end active sessions, block other users, request a full export of your data, and delete your account. We honour Global Privacy Control signals on the web as a request to reject non-essential cookies.

You may also contact [email protected]. We will verify requests as required by law and respond within applicable timeframes. See our User Rights policy for a structured summary.

Minimum age

Xive is an 18+ platform. You must be at least 18 years old to create or hold an account, regardless of the minimum age set by the law of your country. We enforce this at sign-up: an account whose stated date of birth shows the holder is under 18 is closed automatically, and we do not offer a supervised or minor account tier.

We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has an account or has provided us with personal information, contact [email protected] and we will take appropriate steps, including closing the account and deleting the information.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version and update the “Last updated” date. Where the change is material, we will ask you to review and accept the new version the next time you use the Services, and we will provide additional notice where the law requires it.

Contact us

For privacy questions or requests: [email protected]. For help with your account: [email protected]. You may also have the right to contact your local data protection authority, and where applicable to make a complaint to it about how we have handled your personal information.

More policies