Skip to content
Back to Home

Privacy Policy

This policy explains what information X1 Wealth collects, what we do with it, who can see it, and the rights you keep over it. It replaces all earlier versions of our privacy policy.

Last updated: September 9, 2026

1. The short version

X1 holds your household's financial record: your documents, entities, decisions, and the corrections you make along the way. That record is yours. We use it to run the product for you. We do not sell it, we do not give it to advertisers, and we do not use your household's record to serve other customers without your explicit consent. You can export it, and you can ask us to delete it.

The rest of this policy is the detail behind those sentences. Where a detail limits a promise, the detail is stated plainly rather than buried.

2. Who we are

X1 Wealth is operated by Lever Wealth LLC, a Wyoming limited liability company doing business as X1 Wealth LLC ("X1 Wealth," "we," "us"). Our mailing address is 7660 Fay Ave - H141, La Jolla, CA 92037, United States. You can reach us at hello@x1wealth.com.

3. Two zones: the website and the platform

We treat our public marketing website and the authenticated X1 platform as two different places with two different rules.

The marketing website (pages you can visit without signing in) uses advertising measurement tools such as Google Analytics and, on some signup pages, the Meta pixel, so we can tell which of our own marketing works. These tools see website behavior such as pages visited and signup events. They never see the inside of your X1 account.

The authenticated platform (everything after you sign in) carries no advertising pixels and no ad-network code. It uses product analytics and error monitoring so we can fix problems and understand which features are used. Your financial content is never shared with advertising or ad-measurement services of any kind.

4. What we collect

On the platform, the information falls into four groups:

  • Account information. Name, email, authentication details, roles, and billing records.
  • Your record. The documents you upload, the accounts you connect (for example through Plaid), the entities, facts, policies, and relationships X1 organizes from them, and the people and professionals you invite or authorize.
  • Your working history. Questions you ask, answers X1 gives, decisions you log, corrections and confirmations you make, and coordination with your professionals.
  • Usage and device information. Product events, log data, and error reports that tell us the software is working.

On the marketing website we collect the usual website data: pages visited, referral source, and anything you submit in a form.

5. How we use information

  • To provide, secure, and support the product.
  • To build and maintain your household's record and keep it accurate.
  • To generate the briefs, packets, answers, and suggestions you ask for.
  • To process payments and manage subscriptions.
  • To communicate with you about your account and the service.
  • To measure and improve the product.
  • To comply with law and enforce our terms.

6. What X1 learns with you stays yours

Modern AI products learn from how you use them. We think you should own that learning, so we treat the following as your information, not ours: your prompts and questions, the answers generated about your household, your corrections and confirmations, your logged decisions and their outcomes, and the memory X1 builds from all of it.

  • It stays in your boundary. Your household's record serves your household. A firm's practice record serves that firm. One customer's record is never used to answer another customer's questions, except through the consented path described in section 8.
  • You can take it with you. The product can generate a bounded, portable file of supported record sections. The file states whether every supported section fit within the self-serve limits and includes an integrity hash over the fields it emits. When the file is complete and X1 export signing is configured, it also includes a cryptographic signature. If a section exceeds the self-serve limits, the file is labeled incomplete and you can request a fuller access extract from us.
  • You can build on it. You may use your exported record and X1 outputs about your own household or practice to train or evaluate models of your own. What X1 learned with you is yours to keep using.
  • We keep the machinery. X1 retains its own software, models, scoring systems, and the platform improvements we make from operating the service in aggregate. Owning your record never means owning our code.

7. AI model providers

X1 uses commercial AI providers (currently including Anthropic, OpenAI, and Google) to process content you submit through business API services rather than personal consumer accounts. X1 does not grant those providers permission to train their models on household content. The standard commercial API terms for these services generally restrict provider training without customer permission.

We are completing a route-by-route verification of each provider's retention behavior for the specific paths X1 uses, and we maintain a subprocessor schedule available to customers on request. We will not claim a specific retention guarantee for a specific route until we have verified it.

Connecting ChatGPT, Codex, Claude, or another assistant

This policy also covers the X1 Wealth plugin and MCP connector. When you connect an assistant to X1, X1 processes the information described below to carry out your requests. The assistant provider separately processes the conversation and any X1 results it receives under its own privacy policy and your account settings. X1's business API arrangements with AI providers don't replace the terms of your separate assistant account.

What the connection sends to X1

X1 receives the tool name and arguments sent by your assistant. Depending on your request, these can include a search query or question, selected record identifiers, document names and contents, facts you propose saving, and the details of a requested action. Uploaded documents can contain personal and financial information about you, your household, or people mentioned in them. Only send information you're entitled to provide. Don't include passwords, security codes, full payment-card details, government identifiers, or protected health information in assistant requests or documents sent through the connector.

The connection also uses your authenticated X1 identity, account role, permissions, and connection credentials to check access. Sign in through the sign-in flow, not by putting credentials in a conversation. X1 receives the specific inputs the assistant sends to its tools, not automatic access to your entire chat history. An excerpt you or your assistant includes in a tool input is information X1 receives.

What X1 returns to the assistant

Results can include permitted household or professional records, document titles and source passages, financial facts, entity and relationship information, coordination history, generated answers, citations, and action status. Record identifiers and links let the assistant find a selected source or resume the same work. Available results depend on your role, the connection, and current X1 permissions. Connecting an assistant doesn't give it access to every X1 record.

When an available action requires confirmation, X1 stores the proposed details and your approval or rejection. Approval can create or update the specified X1 record. For an approved upload, the supported flow may return an upload capability to the client handling the file. Installing a skill or connecting the assistant isn't approval of an action. Review the details and intended audience in X1 before confirming.

Why we process it and who receives it

We use these inputs to authenticate the connection, search your permitted records, answer your question, scan and index uploaded documents, carry out authorized actions, and preserve the history needed to resume work. We also record access and approval events for security, accountability, troubleshooting, and abuse prevention. Connection and feature-use events help us measure whether the integration works; they can include your account identifier, role, connection type, outcome, and timing. Document access records can include source identifiers, query fingerprints, and network or device information.

The assistant provider receives the tool results returned to it. X1's hosting, database, storage, authentication, document-processing, AI, analytics, and error-monitoring providers process the information needed for their part of the service. These include Vercel, Supabase, Clerk, and the AI providers described above, with product analytics and error monitoring through PostHog and Sentry. Processing may occur outside your country. People with applicable household or professional permissions can see the resulting X1 records; connecting an assistant doesn't itself create a new professional or public sharing grant.

Retention and your controls

A connector request that saves a document, fact, or other record becomes part of your X1 record and follows section 12. Action requests and approval history are stored separately from the conversation and can remain after an action expires or the connection ends. Expiry limits whether an action can run; it doesn't mean its history has been erased. Security and operational records follow their applicable retention and legal-hold requirements. We don't promise that every connector record or service-provider copy expires on one fixed schedule.

You can stop using the connection, remove it in your assistant's connection settings, or revoke an X1 API key in X1 Settings if you use one. Contact us if you need help revoking access. You can decline proposed actions and use X1's available correction, export, sharing, and deletion controls. For access, erasure, or a question about the retention of a particular record, email hello@x1wealth.com. Disconnecting doesn't delete records already saved in X1 or copies already returned to the assistant. Use the assistant provider's own controls for its conversation history and retained copies.

8. Learning across households: consent only

A firm or program on X1 can benefit from anonymized patterns across the households it serves, but only under all of the following conditions: the household has explicitly opted in (and can revoke at any time), the pattern is drawn from a minimum-size cohort so no household is identifiable, concentration and diversity checks pass, and the result is a proposal a human at the firm must approve. No raw household record ever feeds another household or firm.

9. What we never do

  • We never sell your personal information.
  • We never give your information to data brokers, ad networks, or third-party advertisers.
  • We never run advertising, remarketing, or tracking pixels inside the authenticated platform.
  • We do not grant AI providers permission to train their models on your household content.
  • We never use one customer's record to serve another outside the consented path in section 8.

10. When we share information

We share information only in these situations:

  • Service providers. Companies that host, store, process, or deliver parts of the product for us (hosting, database, authentication, AI processing, payments, email, notifications, analytics, error monitoring, and financial account connectivity). They are bound to use your information only to provide their service to us.
  • People you authorize. Family members, advisors, coaches, and other professionals you invite or approve. What they see is scoped by the permissions you grant, and you can revoke access.
  • Legal requirements. When required by law, subpoena, or to protect the rights, safety, or property of X1, our users, or others.
  • Business transfers. If X1 is acquired or merges, your information may transfer with the business. The commitments in this policy follow the data; a successor cannot use it in ways this policy prohibits without obtaining your consent.

11. Cookies and analytics

We use cookies to keep you signed in and to remember preferences. The marketing website uses analytics cookies and, on some pages, advertising measurement cookies as described in section 3. The authenticated platform uses cookies for sign-in, security, and product analytics only. Your browser settings can limit cookies; the product may not work without the sign-in ones.

12. Retention and deletion

Different information lives for different lengths of time:

  • X1-controlled temporary AI processing data (such as application traces that X1 intentionally retains) is kept only as long as needed for debugging, quality, security, or legal obligations, then deleted or deidentified. Provider-side processing and retention follow the route-specific terms and settings described in section 7; we do not represent every provider route as having the same retention period.
  • Your active record is kept while your account or an authorized professional relationship remains active, subject to the retention limits and legal exceptions that apply to the relevant record.
  • Deleting content invokes the applicable deletion path for that item. It may not remove related shared records, derived records, legally retained records, backups, or service-provider copies at the same moment.
  • Ending account access or removing a login identity prevents future sign-in and starts the applicable account-minimization process. It is not, by itself, evidence that every related record has been erased from every system.
  • A verified erasure request is a separate privacy process. We verify identity, define the request scope, review legal holds and shared or professional records, apply the deletion or minimization processes available for that scope, and explain what was completed and what must be retained. We do not promise universal cross-system erasure within a single fixed period.
  • Professional and compliance records (for example, approval records a firm is legally required to keep, or billing records we are required to retain) are kept for the period the law requires, even after deletion of the rest of the account.

13. Security

Your data is encrypted in transit and at rest. Authenticated roles, current professional relationships, and explicit sharing grants limit access. We record key document access and sharing events to support accountability, security review, and incident response. Documents live in private storage with scoped access rather than public links. No system is perfectly secure, and we will notify you as required by law if a breach affects your information. Our current security posture is described at x1wealth.com/security.

14. Your rights and choices

Regardless of where you live, you can: access the information we hold about you, export supported sections of your record, request a fuller access extract, correct inaccurate information, delete supported content, ask us to end account access or remove your login identity, make a verified erasure request, and opt out of marketing email. Those actions can have different scopes and consequences, as section 12 explains. If you are in a jurisdiction with specific privacy rights (for example the CCPA in California or the GDPR in Europe), those rights apply and we honor them; we do not sell or share personal information as those laws define it. To exercise any right, email hello@x1wealth.com. We will verify your identity before acting on a request and respond within the time the applicable law requires.

15. Children

X1 is for adults. Accounts require you to be at least 18. Where family features involve information about minors (for example, family governance documents), that information is provided and controlled by the responsible adult on the account. We do not knowingly collect information directly from children.

16. Changes to this policy

When we change this policy, we will update the date at the top. If a change meaningfully reduces your rights over your information, we will notify you before it takes effect and give you a chance to export your record first.

17. Contact

Questions about this policy or your information: hello@x1wealth.com.