Privacy Policy

For an overview of how we use your data, please see our Data Controls page.

Last Updated: October 25, 2025

1. Introduction

This Privacy Policy describes how Lexi (“Lexi”, “we”, “us”, or “Company”) collects, uses, and handles your personal data (“Personal Data”), and what choices you have when you use our website, applications, platforms, and services (collectively, the “Services”). By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy.

If you do not agree to the practices described in this Privacy Policy, please do not access or use the Services. Any capitalized terms not defined herein have the meaning ascribed to them in our Terms of Service.

2. Information We Collect

We collect several different types of information for various purposes to provide and improve our Services, including Personal Data and Usage Data as set forth below. If you do not provide your information when requested, you may not be able to use some or all of our Services if that information is necessary to provide you with our Services or we are legally required to collect it.

A. Personal Data

While using our Services, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personal Data may include without limitation:

  • Email address
  • First name and last name
  • Phone number
  • Law firm or organization name
  • Cookies
  • Usage Data (as defined below)
  • Any other Personal Data that you voluntarily provide to Lexi

B. Usage Data

We may collect information related to your interaction with or usage of the Services, including without limitation: your IP address, device type, browser type and version, pages of our Services that you visit, the time and date of your visit, the time spent on those pages, device language, unique device identifiers, system logs, performance metrics, and other diagnostic data related to your interaction with the Services (“Usage Data”). When you access the Services with a mobile device, Usage Data may also include information such as the type of mobile device, mobile device unique ID, mobile IP address, mobile operating system, mobile Internet browser type, and other diagnostic data.

C. Legal Document Content You Provide

We collect legal document content and data that you provide to us in order to use the Services. This may include documents, case files, and other legal materials you upload or create using Lexi. We never train our AI models on your client data. Your case files stay completely private, encrypted, and under your control. We process this content solely to deliver the Services to you.

D. Third-Party Platforms

We may collect information when you connect to your account using an account maintained by a third party, such as a social media account or professional network (“Third-Party Account”). The Services may collect information about you from your Third-Party Accounts in accordance with your permissions. Connecting your account to a Third-Party Account is completely optional, and you will have the opportunity to grant permission when you attempt to connect. You can revoke permission by logging into the Third-Party Account and disconnecting Lexi from there.

E. Payment Information

When you sign up for any of our Paid Services, our third-party payment processor, Stripe, Inc. (“Stripe”), collects and processes your payment-related information, such as your name, email, billing address, credit/debit card or banking information, or other financial information. Stripe’s privacy policy is available at stripe.com/privacy.

F. Other Information You Provide Directly To Us

You may have the option to submit additional information as you use our Services. For example, you may choose to participate in surveys where you can provide feedback on our products.

3. Use of Data

Lexi may use Personal Data and Usage Data for the following purposes:

  • Service Operation. To provide, update, maintain, improve, monitor, and protect our Services. We never train our AI models on your client data or legal documents.
  • Communication. To provide customer and technical support, to send service-related emails, and to send marketing emails about new product features or other news about Lexi.
  • Digital Advertising. To display digital advertising to you on our website or other websites (including through the use of cookies or other technologies).
  • Administration. For transactional, billing, account management, tax, and administrative matters.
  • Compliance. To comply with applicable laws and regulations or a court or other legal order.
  • Risk Mitigation. To detect violations of our legal terms, enforce the legal terms that govern your use of the Services, or to detect, prevent, and respond to potential fraud or misuse of the Services.
  • Interaction Improvement. To develop and improve our marketing activities to better match your interests and preferences.
  • Marketing. To contact you with marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following any unsubscribe link or other mechanism provided to remove yourself from such communications.
  • Other. For other lawful purposes with your consent.

Our lawful basis to collect and use your Personal Data and Usage Data will depend on the type of information and the context in which we process it. We may process your information to enter into or perform a contract with you, for the purposes of our legitimate interests (unless your rights and freedoms override those interests), with your consent, or to comply with our legal obligations.

4. Use of Cookies and Other Tracking Technologies

Lexi, and the third parties we work with, use cookies and other tracking technologies on the Services to collect information about your usage of the Services and your device. Cookies are small data files stored on your device that help us improve our Services and your experience.

5. Online Analytics and Tailored Advertising

A. Analytics

We may use third-party web analytics services on the Services, such as those of Google Analytics. These vendors use technology to help us analyze how users use the Services, including by noting the third-party website from which you arrive. The information collected by such technology will be disclosed to or collected directly by these vendors, who use the information to evaluate your use of the Services.

B. Tailored Advertising

We engage in advertising for our own products and services and track ad attributions to measure effectiveness. We may use cookies or similar technologies to collect information about your use of our Services to optimize and serve our marketing content based on your interactions with our website and Services. We do not sell your data or use it to optimize ads for other companies.

6. Retention of Data

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We retain your Personal Data for different periods of time depending on what it is, how we use it, and how you configure your settings. We will either delete or anonymize Personal Data once it is no longer needed or after expiration of the applicable retention periods.

7. Transfer of Data

Your information, including Personal Data, may be transferred to – and maintained on – computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.

Lexi will take steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

8. Sharing With Others

This section describes when we may disclose Personal Data:

  • Service Providers. We may disclose Personal Data with Service Providers who are working on our behalf (e.g., billing and payment service providers, cloud providers, communications providers). Your data is never used to train third-party AI models.
  • Customers. If a customer of Lexi (e.g., your law firm or employer) has given you access to the Services, we may disclose certain information about you (e.g., your account information) with that Customer to satisfy our contractual obligations.
  • Protection of Lexi and Others. We may disclose your information to protect the rights, property, or personal safety of Lexi, its agents and affiliates, its users, and the public. This includes exchanging information with other companies and organizations for fraud protection and similar purposes.
  • Business Transfers. We may disclose your Personal Data in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • Affiliates. We may disclose Personal Data with our affiliates who use Personal Data as set out in this Privacy Policy.
  • Others with Your Consent. We may share your Personal Data with other third parties with your express consent.

9. How We Secure Your Information

The security of your data is important to us. We implement technical, administrative and physical safeguards to protect the information we collect from loss, misuse and unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

10. Your Data Protection Rights Under GDPR

If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

In certain circumstances, you have the following data protection rights to:

  • Access, update or delete the information we have on you
  • Have your information rectified if that information is inaccurate or incomplete
  • Object to our processing of your Personal Data
  • Request that we restrict the processing of your personal information
  • Be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format
  • Withdraw your consent at any time where we rely on your consent to process your personal information

Please note that we may ask you to verify your identity before responding to such requests. You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data.

11. Children’s Personal Data

To use the Services, you must be at least 18 years old. Our Services are designed for legal professionals and are not intended for children. If you are a parent or guardian and become aware that your child provided us with Personal Data, please contact us.

12. Service Providers

We may use third-party companies, vendors, personnel and other service providers to facilitate our Services, provide Services on our behalf, analyze how our Services are used, and provide similar third-party services (collectively, “Service Providers”). These Service Providers may have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

13. Links to Third-Party Websites

The Services may contain links to third-party websites or services. We are not responsible for the content or practices of those websites or services. The collection, use, and disclosure of your information by third parties will be subject to the privacy policies of the third-party websites or services, and not this Policy. We urge you to read the privacy and security policies of these third parties before providing information to them.

14. Changes to This Privacy Policy

We’ll update this Privacy Policy from time to time. When we make changes, we’ll update the date at the top of the Privacy Policy. If a modification meaningfully reduces your rights, we will notify you (by, for example, sending you an email or displaying a prominent notice within the Services). The notice may designate a reasonable period after which the new terms will take effect.

Modifications will not apply retroactively. We encourage you to check back periodically to review this Privacy Policy for any changes since your last visit.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at legal@getlexi.io.

16. Privacy Notice for California Residents

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA). These rights include the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information (note: we do not sell your personal information).

To exercise these rights, please contact us at legal@getlexi.io.