Your data is encrypted (AES-256 at rest, TLS 1.3 in transit), logically isolated per firm, and processed only under contractual privacy protections. Our database and edge run on SOC 2 Type II–certified cloud infrastructure; our own application-layer SOC 2 audit is in progress. Privileged content and PHI are handled under a Business Associate Agreement and are never used to train public AI models.
Full details on our Security page.
We collect the following categories of data:
We use the data we collect to:
Important
Your matter data, client information, uploaded documents, and AI query content are not used to train any AI model — including Lexitio’s own models or any third-party model providers we work with.
We use Anthropic’s API under Anthropic’s zero-data-retention API terms, which prohibit Anthropic from using API input/output for model training. We apply the same contractual restriction to any other LLM provider we use.
We work with the following third-party services to provide the Service:
| Provider | Purpose | Data transferred |
|---|---|---|
| Anthropic | AI co-counsel (Claude) — primary, under BAA | Query text, document excerpts |
| OpenAI | AI language model (fallback, non-privileged) | Query text, document excerpts |
| Groq | AI inference for non-privileged tasks | Query text (non-privileged) |
| Neon | Managed PostgreSQL database (US) | Account, matter, and client data |
| Vercel | Frontend hosting & CDN | Request data, IP address |
| Hostinger | Backend application hosting (US) | Data processed during compute |
| Backblaze B2 | Encrypted offsite database backups | Backup copies of stored data |
| Stripe | Payment processing | Billing details (Stripe stores card data; we do not) |
| Resend | Transactional email delivery | Email address, email content |
| Sentry | Error monitoring | Stack traces, anonymized request metadata |
Active account data is retained for the duration of your subscription. When you cancel, your data is retained for 30 days to allow for export, then deleted.
Firm administrators may configure a custom retention policy (in days) for closed and archived matters via the firm settings page. Matters subject to a legal hold are exempt from automatic deletion.
Audit logs are retained for a minimum of 7 years for legal compliance and are append-only. They cannot be modified or deleted.
You have the right to:
The Service uses a session token stored in your browser’s local storage for authentication. We do not use third-party advertising cookies. We may use first-party analytics to understand feature usage; this data is aggregate and not linked to individual clients or matters.
The Service is not intended for users under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, contact us at privacy@lexitio.com and we will promptly delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice in the application at least 30 days before changes take effect.
For privacy-related requests or questions, contact our privacy team at privacy@lexitio.com.