Your data is encrypted (AES-256 at rest, TLS 1.3 in transit), logically isolated per firm, and processed only under contractual privacy protections. Our database and edge run on SOC 2 Type II–certified cloud infrastructure; our own application-layer SOC 2 audit is in progress. Privileged content and PHI are handled under a Business Associate Agreement and are never used to train public AI models.
Full details on our Security page.
We collect the following categories of data:
We use the data we collect to:
Important
Your matter data, client information, uploaded documents, and AI query content are not used to train any AI model — including Lexitio’s own models or any third-party model providers we work with.
We use our AI providers’ APIs under zero-data-retention terms, which prohibit them from using API input/output for model training. We apply the same contractual restriction to every LLM provider we use.
We rely on a small set of vetted providers to run the Service — US-based cloud hosting and CDN, a managed database with encrypted offsite backups, AI model providers (under contractual no-training terms), a payment processor, transactional email, and error monitoring. Each receives only the data needed for its function, is bound by contractual privacy and security obligations, and none may use your data to train AI models. A current list of subprocessors is available on request at privacy@lexitio.com.
Active account data is retained for the duration of your subscription. When you cancel, your data is retained for 30 days to allow for export, then deleted.
Firm administrators may configure a custom retention policy (in days) for closed and archived matters via the firm settings page. Matters subject to a legal hold are exempt from automatic deletion.
Audit logs are retained for a minimum of 7 years for legal compliance and are append-only. They cannot be modified or deleted.
You have the right to:
The Service uses a session token stored in your browser’s local storage for authentication. These necessary cookies are always on. With your consent, we also use third-party analytics cookies (such as Google Analytics) to understand how the Service is used and improve it; this data is aggregate and not linked to individual clients or matters. You can decline non-essential cookies at any time using the cookie banner (“Necessary only”), and analytics will not load unless you accept.
The Service is not intended for users under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, contact us at privacy@lexitio.com and we will promptly delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice in the application at least 30 days before changes take effect.
For privacy-related requests or questions, contact our privacy team at privacy@lexitio.com.