We built LexAI with one simple belief: your legal data belongs to you. No tricks, no fine print surprises. Just honest, transparent privacy.
Last updated: May 1, 2026

LexAI Technologies, s.r.o. (hereinafter "LexAI" or "we") operates the LexAI platform — an AI-assisted legal tool (hereinafter "Platform"). When processing personal data, we are committed to protecting the privacy of our users and comply with all applicable legislation, in particular:
The data controller within the meaning of Article 4(7) GDPR is:
LexAI has not designated a Data Protection Officer (DPO), as this is not obligatory given the nature and scope of the processing carried out. For any data protection queries, please contact: support@lexaitechnologies.com.
| Category | Specific Data | Purpose | Legal Basis |
|---|---|---|---|
| Account | Email (verified), name, hashed password | Registration, authentication, account management | Performance of contract (Art. 6(1)(b) GDPR) |
| Conversations | Chat history, AI queries and responses | Providing AI assistance, project management | Performance of contract |
| Documents | Uploaded files (PDF, DOCX), extracted text | Document analysis and processing | Performance of contract |
| Payments | Stripe customer ID, subscription ID, invoices | Billing, subscription management | Performance of contract; Legal obligation (tax purposes) |
| Security | IP addresses, device information, 2FA tokens, WebAuthn credentials | Security monitoring, fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Usage | Token count, web searches, and query count per month | Limit management, billing, service optimisation | Performance of contract; Legitimate interest |
| Gamification | XP points, achievements | Platform features | Performance of contract |
| Communications | Content of emails sent to the User (SendGrid logs) | Support, notifications, email verification | Performance of contract; Legitimate interest |
LexAI intentionally does not process special categories of personal data within the meaning of Article 9 GDPR (health data, biometric data, racial or ethnic origin, etc.) as part of registration or profile settings.
We note, however, that Users may upload legal documents that contain special categories of personal data (e.g. contracts, court submissions, medical reports in the context of litigation). In such cases:
This section is key to understanding how LexAI handles your conversations and documents.
LexAI operates a zero-knowledge architecture inspired by ProtonMail. This specifically means:
| Component | Algorithm | Parameters |
|---|---|---|
| Data encryption | AES-256-GCM | 12-byte IV, 128-bit auth tag |
| Key derivation | PBKDF2-SHA256 | 600,000 iterations |
| Password hashing | PBKDF2 | 600,000 iterations, constant-time comparison |
| Device binding | PBKDF2 | 100,000 iterations |
What the server never sees in unencrypted form:
What the server stores (all encrypted):
The 12-word Recovery Phrase is the only means of recovering access to data if the password is lost. The server stores only its hash (PBKDF2). LexAI cannot restore access to data by any other method. The User is solely responsible for keeping their Recovery Phrase safe.
| Trigger | Action |
|---|---|
| Tab close | Keys cleared from memory |
| 2 hours of inactivity | Session keys cleared |
| Logout | All keys cleared |
| Session expiry | 24-hour maximum lifetime |
When you submit a query to the AI chat or upload a document for analysis:
Anthropic (Anthropic, PBC, USA) processes the content of your queries and documents as our data processor in accordance with their API terms and Data Processing Agreement. Key points:
LexAI uses the following sub-processors for data processing. By accepting this Privacy Policy, you consent to the transfer of data to these sub-processors to the extent described below.
| Sub-processor | Location | Purpose | Data Processed |
|---|---|---|---|
| Anthropic | USA | AI query processing | Chat message content, documents for analysis |
| Supabase | EU (Frankfurt) | Database and authentication | All user data (in encrypted form) |
| Vercel | USA / EU | Serverless hosting | Request logs, API calls |
| Hetzner | EU (Frankfurt) | Proprietary servers (legislation vector DB, security logs, document processing) | Security logs, document processing for export/import |
| Qdrant | EU (Frankfurt) | Vector database for public legislation | Embeddings of public legal sources — no user data |
| Stripe | USA (EU compliance) | Payment gateway | Payment data, invoices, subscription IDs |
| SendGrid (Twilio) | USA | Email communications | Email addresses, content of notification emails |
| SerpAPI | USA | Web search | Search queries (without user identifiers) |
| Brave Search | USA | Alternative web search | Search queries (without user identifiers) |
| IPInfo | USA | IP address geolocation | User IP addresses |
Several sub-processors (Anthropic, Vercel, Stripe, SendGrid, SerpAPI, Brave Search, IPInfo) are based in the USA. Transfers of data to the USA are carried out on the basis of Standard Contractual Clauses (SCC) pursuant to Article 46(2)(c) GDPR, or in accordance with the EU–U.S. Data Privacy Framework adequacy decision where applicable.
LexAI does not use cookies or similar tracking technologies for marketing or analytical purposes. For this reason, we do not require cookie consent and we do not implement a cookie banner.
The Platform may technically use session storage and IndexedDB exclusively for the secure storage of encryption keys on the User's device (see Section 4). This storage is necessary for the functioning of the zero-knowledge architecture and is not used to track the User.
| Data Category | Retention Period |
|---|---|
| Conversations — paid tiers (Plus, Premium, Business, Enterprise) | As per the user's preference in settings (applies to non-archived chats); archived conversations retained indefinitely |
| Conversations — Free tier | Hard limit of 60 days; user preference capped at 14 days; archived conversations are not exempt from the hard limit |
| Top-up token records | 3 months from purchase |
| Invoices and payment records | Indefinitely (statutory obligation under accounting and tax law) |
| Security logs | 90 days |
| Emails and email logs | 180 days |
| Account data — paid tier | Until Account deletion by the User; or a hard limit of 2 years from last login (after this period of inactivity, we will send a notification and delete the Account) |
| Account data — Free tier | Until Account deletion by the User; or a hard limit of 6 months from last login |
| Uploaded documents | As per the User's settings; automatically deleted upon deletion of the conversation or Account |
After the applicable retention period, data is securely deleted or anonymised.
As a data subject under the GDPR, you have the following rights:
You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of it along with information about the processing.
You have the right to request correction of inaccurate or completion of incomplete personal data.
You have the right to request erasure of your personal data where:
Erasure can be carried out directly in the Platform settings (Account deletion) or by contacting support@lexaitechnologies.com. Erasure does not apply to data we are legally obliged to retain (in particular invoices and accounting records).
You have the right to request restriction of the processing of your personal data in the cases provided for by the GDPR (e.g. where the accuracy of data is contested or an objection has been lodged).
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller. The Platform provides a data export function (data export endpoint).
You have the right to object to the processing of personal data carried out on the basis of legitimate interest (Article 6(1)(f) GDPR). In that case, we will cease processing unless we demonstrate compelling legitimate grounds that override your rights and interests.
Where processing is based on consent (where applicable), consent may be withdrawn at any time without any negative consequence for processing already carried out.
Submit requests to exercise your rights to: support@lexaitechnologies.com. We will respond without undue delay and in any event within 30 days of receiving your request. In the case of complex or extensive requests, this period may be extended by a further 60 days, of which we will inform you.
You have the right to lodge a complaint with a data protection supervisory authority. The lead supervisory authority for LexAI is:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Website: www.uoou.cz
Email: posta@uoou.gov.cz
You may also contact the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
LexAI implements comprehensive technical and organisational security measures:
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the supervisory authority (ÚOOÚ) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
The Platform is not intended for persons under the age of 18. LexAI does not knowingly collect personal data from children. If we become aware that we have collected personal data from a person under 18 without verified parental or guardian consent, we will delete such data without delay.
If you have reason to believe that a person under 18 has provided us with personal data, please contact us at support@lexaitechnologies.com.
| Legal Basis (Article 6 GDPR) | Examples of Processing |
|---|---|
| Performance of contract (Art. 6(1)(b)) | Registration, authentication, AI assistance, conversation storage, billing |
| Legal obligation (Art. 6(1)(c)) | Retention of invoices and accounting records |
| Legitimate interest (Art. 6(1)(f)) | Security monitoring, fraud prevention, rate limiting, service optimisation |
| Consent (Art. 6(1)(a)) | Any processing not covered by the above bases (where applicable) |
Where processing is based on legitimate interest, we carry out a balancing test weighing LexAI's legitimate interests (Platform security, fraud prevention, service improvement) against the rights and freedoms of Users. You are entitled to object at any time (see Section 9.6).
LexAI reserves the right to amend this Privacy Policy at any time. Users will be notified of material changes by email or by notice within the Platform at least 14 days before the changes take effect. The date of the most recent update is always stated in the header of this document.
Continued use of the Platform after the effective date of any changes constitutes acceptance of the updated Privacy Policy.
For any questions regarding the processing of your personal data, the exercise of your rights, or this Privacy Policy, please contact us:
LexAI Technologies, s.r.o.
Školská 660/3, Praha 1 - Nové Město 110 00 Praha 1
Email: support@lexaitechnologies.com
Website: www.lexaitechnologies.com
We will respond within 30 days of receiving your request.