Roleplay by XL.netFor sales leadersCoaching insightsArticlesPricingRequest a pilot
For sales leadersCoaching insightsArticlesPricing

Privacy Policy

Last updated: August 26, 2026

This policy covers roleplay.xl.net, operated by XL.net Inc., and every channel on which you can reach XL Roleplay Coach, our AI agent — web chat, SMS, email, and voice.

Tracking, Profiling & Automated Identification

We believe transparency beats fine print, so here is everything this site does to understand its visitors — including the parts most sites leave out. All of it is first-party: we use no third-party analytics service, advertising network, or social-media tracker, and none of this data leaves our own server.

  • First-party page tracking: our own server records each page view with the path, referring page, IP address, browser user agent, and any campaign (UTM) parameters. This powers our traffic dashboards and abuse prevention.
  • Company (not person) identification: we look up visitor IP addresses against a locally stored database to identify the organization or networka visit came from (for example, “a visitor from Acme Corp's network”). The lookup happens on our own server, identifies companies rather than individuals, and sends no data to anyone else.
  • Repeat-visit linking:we compute a short hash of IP address + browser user agent to connect a day's repeat visits into one anonymous session. This record contains no name or email unless you later identify yourself (for example by signing in), at which point your visits may be linked to your contact record.
  • Landing-page recovery: a small script on our pages reports the address of the page your browser says referred you. It exists because some browsers pre-load our pages in a way that hides that information from our server.
  • Form submissions and their source: when you submit a form we record which traffic source you arrived from — the referring site, landing page and campaign parameters above — alongside the email address you provide, and a session identifier linking it to the pages you viewed on this site. We keep these records for up to 730 days.
  • AI assistant fetches: when a request identifies itself as an AI assistant (ChatGPT, Claude, Perplexity and similar), we record which assistant, which page, when, and the network address it came from. These are kept separately from visitor analytics for up to 180 days.

AI Agent Processing & Human Oversight

Conversations with XL Roleplay Coach — web chat, SMS, email, and voice — are processed by our AI systems and stored so the agent can answer you and we can review quality.

Every email XL Roleplay Coach sends is copied to a human at XL.net Inc., so an unsupervised AI is never our only record of what was said.

Chat Page Context

While you use the chat widget, XL Roleplay Coach can see the page you are on — its address, title, and visible text — so it can answer questions about what you are looking at. While the chat panel is open, it is also told short descriptions of elements you point at or text you select (for example, “the ‘Pricing’ heading”) so you can gesture at what you mean.

Nothing is captured while the chat is closed, form values and passwords are never read, and the widget shows a “Sees this page” indicator with an off switch whenever sharing is active. Shared page context is stored with the conversation like any other chat content.

Issue Reports

If you report a problem through the chat, your report — including a short excerpt of the conversation and, when page sharing is on, a snapshot of the page you were viewing — is emailed to XL.net Inc. staff so a human can act on it. If you include a contact address, staff may use it to follow up. To review or erase a report, contact adam@xl.net.

Persona Memory

XL Roleplay Coach keeps a private, per-person memory: facts you share and your conversation history, so later conversations can pick up where you left off. Your memory is visible only to you (and to XL.net Inc. staff reviewing quality) — never to other visitors — and XL Roleplay's own published knowledge always outranks remembered facts when they conflict.

  • One memory across channels: if you verify your mobile number on your account, your web chat, SMS, email, and voiceconversations share one memory keyed to that number. Email conversations join it only when the email provably came from you (it must pass DKIM authentication for your address's domain); mail that fails authentication is answered without reading or writing any stored memory.
  • Anonymous web chat remembers nothing. Memory applies to web chat only when you are signed in, and signed-in chat has a MEMORY ON/OFF toggle in the chat window — turn it off and that conversation is not saved to memory.
  • SMS always remembers. Texting XL Roleplay Coach keeps memory for your phone number (possession of the handset is the authentication); the first reply you receive says so and names the erasure keyword.
  • Erasure by text — “FORGET”: text FORGET to +18723448847 and we permanently erase the stored memories, conversation history, and call transcripts for that number — and, if the number is verified on an account, for that account's chat and email memory too. You get a confirmation text once the erasure has completed. FORGET is not STOP: STOP opts you out of receiving messages, FORGET erases what we remember.
  • What FORGET does not delete: SMS consent records (kept for legal compliance), usage metadata that contains no conversation content, the deletion-audit record proving the erasure happened, server and diagnostic logs, and the human-oversight copies of emails already sent.
  • Recycled numbers: memory is keyed to the phone number itself. If a number is reassigned by a carrier, its new holder could encounter memory from the previous holder — text FORGET from the number to erase it.
  • Caller-ID caveat:voice calls recall memory by the calling number, and caller ID can be spoofed — a determined attacker who spoofs your number on a call could expose that number's memories. If this concerns you, text FORGET to erase the memory, or skip verifying your number.

Account Data

If you sign in, we store your email address and display name (provided via Google OAuth or Microsoft OAuth, or an emailed sign-in link). This information is used only to authenticate you and personalize your experience. We never post on your behalf or access anything else in your provider account.

If you register a mobile number for text messaging, we also store that number, the date you verified it, and your opt-in consent record (see SMS / Text Messaging Data below).

Your Data Rights

Signed-in users can exercise both rights directly, without emailing anyone:

  • Export (data portability): download everything we hold about you — your account record, consent and notice history, and your stored conversations and memories with XL Roleplay Coach — as a machine-readable file from /api/account/export while signed in.
  • Deletion (right to erasure): delete your account and its data via a signed-in request to /api/account/delete, confirmed by typing your account email. This permanently erases your conversations, memories, and personal records, then removes the account itself, and returns an itemized count of what was erased.

Deletion keeps the narrow records the law or basic security requires: SMS consent records, the deletion-audit record proving the erasure happened, security logs with the account link removed, and — where you have made purchases — financial records with your identity removed. If anything blocks a deletion (for example an active paid subscription), the request tells you exactly what to resolve first. Questions or problems with either right: adam@xl.net.

What We Do NOT Do

  • We do not sell your data to anyone
  • We do not use your data for advertising
  • We do not use third-party analytics or tracking cookies
  • We do not serve third-party advertisements
  • We do not use your data to train AI foundation models. XL Roleplay Coach processes and stores your conversations to answer you, but your data is never sold to, or used to train, third-party models.

Cookies

Essential cookies only. We set a single httpOnly session cookie (roleplay_session, 30 days) when you sign in, plus short-lived cookies during the sign-in handshake. A first-party cookie (roleplay_attrib) remembers the landing page, the site that referred you, any advertising click identifier in the address (gclid, msclkid, fbclid and similar), and campaign parameters of your first visit; it is read only by our own server. Your theme preference and interface choices are kept in your browser's localStorage, and the chat widget's conversation state in sessionStorage. If you listen to an article, your chosen playback speed and how far through that article you got are also kept in localStorage, so you can pick up where you left off; that stays on your device. None of this is sent to any third party.

Because we set no analytics or advertising cookies, there is no cookie consent banner — there is nothing to consent to. Blocking all cookies in your browser will prevent you from signing in but does not affect the rest of the site.

Third Parties

We share data only with services necessary to operate the site:

  • Google OAuth / Microsoft OAuth: authentication only
  • Resend: email delivery and receiving for coach@roleplay.xl.net
  • Twilio: SMS and voice-call transport (phone numbers and message/call content, as required to deliver the service)
  • Cloudflare: DNS and secure tunnel (no personal data stored)
  • Large-language-model providers: when you interact with XL Roleplay Coach, your conversation content is sent to one or more of these providers via their APIs solely to generate the response. We use API terms under which providers do not use this content to train their models.
  • Text-to-speech provider: to produce the audio version of an article, the published article text is sent to a speech-synthesis API. Only the article — which is already public on this site — is sent; nothing about you, your visit, or your listening is included.

None of these providers receive your data for their own marketing purposes.

SMS / Text Messaging Data

If you communicate with us via SMS, your mobile phone number and message contents are used solely to respond to your inquiry. Your mobile information will not be sold, rented, or shared with third parties or affiliates for their own marketing purposes. Mobile opt-in data and consent are not shared with any third parties except service providers that help us operate our messaging program, and those providers are restricted from using your information for any other purpose.

If you register your number with us, we record your opt-in consent (the consent language you agreed to, your IP address, and browser) and verify the number with a one-time code before it is added to your account. Message frequency varies based on your interactions with us. Message and data rates may apply. Text STOP to opt out at any time.

For full details on our text messaging program, see our SMS Terms & Conditions.

Data Retention & Deletion

  • Account data: as long as your account exists
  • Sign-in logs: up to 365 days
  • Page-view records: up to 730 days
  • IP-to-organization records: up to 365 days
  • Conversion records: up to 730 days
  • AI assistant fetch logs: up to 180 days
  • Email oversight copies: up to 730 days
  • Unverified phone-verification codes: 10 minutes
  • SMS consent records: for the life of the messaging program plus four years, as required for compliance

Upon a deletion request, all associated personal data is permanently removed within 30 days, except records we are legally required to keep (such as SMS consent logs).

Changes to This Policy

We may update this Privacy Policy from time to time. Changes are effective when posted to this page, and the “Last updated” date above reflects the most recent revision. Your continued use of the site after changes are posted constitutes acceptance of the updated policy.

Contact

To object to any of this processing, request deletion of your account and associated data, or ask privacy questions, contact adam@xl.net.

This policy is generated from the site's actual configuration so it cannot drift from behavior. It reflects engineered defaults, not legal advice.

Camera and Video: Practice Sessions and the Live Demo

The sections above are generated from this site's configuration, including the line just above saying the policy is generated from configuration and cannot drift from behavior. That line is about those sections. This one is written by hand, because it covers the part the generator does not know about: the live video stage where you practice a sales conversation with an AI character, and the free live demo on our homepage. Read it together with the sections above, not instead of them.

What we do with your camera. When a roleplay runs in video mode, and during the free live demo, your browser takes still images from your webcam about twice a second and sends them to our server. These are ordinary photographs of you at your desk: your face, and whatever is behind you. Each one is shrunk so its longest edge is 384 pixels, which is for speed and bandwidth, not anonymity. Our server passes each image to Google's Gemini API and asks one question about it: what is this person doing right now. Google returns a short structured answer with seven fields and nothing else: whether you are in frame, whether you are looking at the lens, at your screen or away, whether your hands are at rest, raised or out of the picture, how many fingers you are holding up when you deliberately hold some up, a short phrase when something about you has changed since the previous image, for example “looked down at screen” or “stepped out of frame,” how confident it is in what it reports, and one short factual clause of about fifteen words describing what is plainly visible, such as clothing colors, a headset or a mug you are holding, and what is behind you.

Why we do it. So the AI character can behave like a person on a video call: notice when you step out of frame, answer honestly when you ask whether it can see you, and react when you gesture. In a practice session the same readings become the body-language part of your coaching debrief. The instructions we send with every image forbid any reading of age, gender, ethnicity, attractiveness, identity, grooming, health or mood, and forbid transcribing writing, logos or printed text that happens to be visible in the picture.

Where this happens, and that your camera is on by default. It applies to the two video practice modes, Run Meeting and Attend Meeting, and to the free live demo. It does not apply to the phone-call modes, Book Meeting and Answer Sales Call, where there is no video at all, or to Watch a Meeting, where both seats are played by the AI and nobody is on camera. In both places where it does apply, your camera is switched on for you, not by you.

  • In a practice session, starting a session with the Video avatar switch on, which is how it arrives, turns your camera on with it. Turning that switch off in the setup panel before you start means your camera does not come on, and nothing is captured, unless you switch it on yourself with the camera button during the session.
  • In the free live demo your camera is switched on when the session starts. If you arrived from a link in one of our emails, the session starts by itself as the page loads, so nothing is clicked first. Your browser still asks for camera permission the first time. If you granted it on an earlier visit, your browser will usually not ask again.

We do not keep the images. We do not write them to disk, we do not put them in any database, and no image appears in any log. Our server holds an image in memory only until Google's answer comes back, and then it is gone. Ending the session leaves no camera stills behind on our side. Two things this sentence does not cover, both described below: our ordinary server logs do record the readings themselves, and your session recording is a separate thing that does contain your camera.

What the server logs keep. Our voice server writes ordinary operational log lines about the readings: whether you were in frame, where you were looking, where your hands were, a finger count, the short change phrase when there is one, and how long the call to Google took. Those lines carry no image and no description of your appearance: the fifteen-word visible-detail clause is stripped before anything is logged. We do not put a retention window on operational logs here, because we cannot honestly commit to one.

What we cannot tell you. We send each image to Google's Gemini API using an API key. What Google does with an image after that, including how long Google keeps it and whether Google may use it for anything of its own, is governed by Google's terms and is not something we can verify from our side. So we make no claim about it here. The paragraphs above are about our servers, and they are the part we can stand behind. If Google-side handling matters to you, keep the camera off.

Written descriptions of you can last, even though the pictures do not. This is the half a short on-screen notice cannot carry, so it is spelled out:

  • The AI character is told what it can see, and it is instructed to say so out loud, and to back any claim that it can see you with a concrete detail such as what you are wearing, for example “I've got you in the blue shirt, by the bookshelf.” Everything the character says is transcribed, and we store the transcript of the session. So a written description of what you were wearing, what you were holding, or what was behind you can end up in a stored transcript even though the picture never does.
  • In the free live demo we store that transcript against the email address you gave us, and after the call we email the conversation back to you, in full or as a clearly marked excerpt when it runs longer than the email can carry. If the Coach described you out loud, that description is in the stored copy, and usually in the email. Demo records have no automatic expiry, so we keep them until you ask us to delete them: see below.
  • For practice sessions we send a summary of your body language to the model that writes your debrief: how much of the session you were in frame, how your attention was split between the lens and your screen, when and how long you were away, and notable gestures. We store the debrief it writes. That summary carries no image and no description of your appearance. We also store a small set of numbers with the session: frames read, frames skipped, the gaze split, the number and total length of absences, and a gesture count.

Session recordings. Separately from the camera reading, practice sessions are recorded. When the Video avatar switch is on, the recording is the side-by-side picture from the stage, the AI character on one side and your webcam on the other, with the audio of both; when that switch is off, the session is recorded as audio only, even if you turn your camera on by hand during it. The recording is stored as a file on our server and it is deleted automatically about 30 days after the session. Turning your camera off during a session does not stop the recording: it keeps running, and your side of the picture is blank for as long as the camera is off. The free live demo is not recorded: the server refuses the recording connection for demo callers.

Who can play a recording back. You can download your own recording from the session. Our own staff can review recordings, transcripts and debriefs for support and quality. And if your account sits under a company whose administrator we have promoted for your email domain, that administrator can play back the recordings, read the transcripts and read the debriefs of everyone in that domain, including yours. That is what the manager review feature is: if you are practicing on a company account, assume your manager can watch the video of your face.

How to turn it off. The camera button in the control bar under the stage switches your camera off at any point during a session, in the demo as well as in practice. With the camera off, no images are captured, nothing goes to Google, and the character stops being told what it can see. In a practice session you can also turn the Video avatar switch off before you start, so the camera never comes on in the first place and the recording is audio only.

How to have this removed. Email adam@xl.net to have any of it deleted, or to ask anything about this section. That is the route we can promise, because this site has no Delete button today: the deletion request described under Your Data Rights above is an API endpoint with no page or control wired to it yet. What deletion does reach when we run it for you: your practice sessions, your debriefs and your scores, including the body-language numbers stored with them. What it does not reach, and why the email matters: the turn-by-turn transcript of a practice session, and everything held for a demo, which has no account behind it at all. Both of those we remove by hand on request. Deleting an account does not delete recordings either. They go on the automatic sweep, up to about 30 days after the session, so tell us if you want one gone sooner.

How to read the sections above once a camera is involved. The sections above are generated for a site whose channels are text, email and audio. Most of what follows is a scoping note: those sentences are accurate for what they describe and simply do not describe the video stage. The last two are different. They are data-rights promises that the video stage does not keep, and they are the reason this list exists at all:

  • Third Parties describes large-language-model providers as receiving your conversation content. On the video stage they also receive text derived from your camera: what the character can see is written into the prompt sent to the model that plays the character, and the body-language summary is written into the prompt sent to the model that writes your debrief. The providers behind the video stage today are xAI (the character's words and voice, and the transcription of your speech), HeyGen (the on-screen avatar), Google (the camera reading described here), OpenAI (the written debrief) and Behavioral Signals (voice-tone analysis of your speech in practice sessions; the demo does not use it). Note that Google appears in the list above as our sign-in provider; the vision processing here is a second and separate role for the same company.
  • Third Parties also ends with two sentences about what those providers do on their own side: that we use API terms under which providers do not use the content to train their models, and that none of them receive your data for their own marketing purposes. We are not extending either sentence to the five providers named above. We have not checked the account terms vendor by vendor, and a promise about someone else's conduct that we have not verified is not one we are willing to print. What we can state for certain is what we do, in the next bullet.
  • What We Do NOT Do says your data is never sold to, or used to train, third-party models. What we can state for certain is what we do: we never sell your data, and we never send it to anyone for the purpose of training a model. Whether a provider trains on what we send it rests on that provider's terms rather than on our code, and we have not verified them, so we do not extend the claim past our own conduct.
  • Cookies ends “None of this is sent to any third party.” That sentence is about cookies and browser storage. It is not a statement about the video stage, which does send data to the providers named here.
  • Tracking, Profiling & Automated Identificationsays that all of it is first-party and that none of that data leaves our own server. That is true of the visitor analytics it describes. It is not true of a live roleplay or demo session: the camera reading in this section leaves our server, and so does the conversation itself and the context the session sends alongside it, all of it going to the providers listed above so they can generate the coach's replies.
  • Your Data Rights describes Export as downloading everything we hold about you. Read that as your account record, your consent and notice history, your billing records and your conversations with the coach. It does not yet include the things this section describes: practice transcripts, debriefs, session recordings, or the body-language numbers. To get those, or to ask what we hold, email adam@xl.net.
  • Your Data Rights also says deletion permanently erases your conversations, and Data Retention & Deletion says all associated personal data is permanently removed within 30 days. For the video stage that is not the whole picture, and the paragraph above is the accurate one: deletion reaches your sessions, debriefs and scores, while the turn-by-turn transcript of a practice session and everything held for a demo are removed by hand when you ask us, and recordings age out on their own sweep rather than on your deletion.

This section was added on August 26, 2026, the day the camera reading was switched on for every video session and for the live demo. Before that it ran only for administrator accounts with debug mode on.

Roleplay by XL.netFor sales leadersPricingRequest a pilotProduct demoHow it worksCoaching insightsArticlesBuilt by XL.netPrivacySMS TermsText with XL Roleplay CoachAccountcoach@roleplay.xl.net