// legal documents

Privacy Policy

Effective date: 1 January 2026  ·  Last updated: 15 April 2026  ·  Version 1.2

Plain English summary: LexAI collects the minimum data needed to operate the platform. We use your documents only to provide the AI services you request. We never sell your data. You own your documents and can delete everything at any time. AI outputs are generated by Anthropic's Claude API — your documents are sent to Anthropic under their enterprise privacy commitments (no training on your data).

Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. AI Processing & Third-Party Services
  5. Case Law Data Sources
  6. Self-Learning System
  7. Data Sharing & Disclosure
  8. Data Retention
  9. Your Rights
  10. Security
  11. Cookies & Analytics
  12. International Transfers
  13. Children's Privacy
  14. Changes to This Policy
  15. Contact & DPO

1. Who We Are

LexAI.llc ("LexAI", "we", "us", "our") is an AI-powered legal technology platform operated by Dollar Double Empire, registered in Bermuda. Our registered address is Bermuda 🇧🇲.

We operate the website at lexai.llc and all associated subdomains and applications. This Privacy Policy applies to all users of our platform, including visitors, free-tier users, paid subscribers, and firm-plan licensees.

For privacy enquiries, please contact: privacy@lexai.llc

2. What Data We Collect

2.1 Account Information

When you create an account, we collect:

2.2 Documents You Upload or Create

When you use LexAI's features, we store:

2.3 Usage Data

We automatically collect:

2.4 Feedback & Learning Data

If you use the Self-Learning feature:

2.5 Payment Data

Payments are processed by Stripe. We do not store your credit card details. We receive and store:

2.6 Technical Data

Data typePurposeRetention
IP addressSecurity, fraud prevention30 days
User agent / browserCompatibility, security30 days
Session tokensAuthentication30 days or until logout
Error logsPlatform stability14 days
API response timesPerformance monitoring7 days (aggregated only)

3. How We Use Your Data

We use your data strictly for the following purposes:

We do not: Sell your data, use your documents to train AI models, share your content with other users, or use your documents for any purpose other than providing you the requested service.

4. AI Processing & Third-Party Services

4.1 Anthropic Claude API

All AI-generated outputs on LexAI are powered by Anthropic's Claude API (models: Claude Sonnet 4.6 and Claude Haiku 4.5). When you use any AI feature, the relevant text or document content is transmitted to Anthropic's API servers for processing.

Anthropic's enterprise API commitment: Anthropic does not use content submitted via their API to train or improve their models. Your documents are processed in transit and not stored by Anthropic. See anthropic.com/privacy for their full policy.

We send to Anthropic: the document text or prompt you submit, along with any jurisdiction/preference context we have learned for your account (see Section 6). We do not send your name, email, or any identifying information to Anthropic.

4.2 Stripe (Payments)

Payment processing is handled by Stripe, Inc. When you subscribe, your payment details go directly to Stripe — we never see or store your card number. Stripe's privacy policy: stripe.com/privacy.

4.3 Google OAuth / GitHub OAuth

If you sign in with Google or GitHub, we receive your email, name, and profile photo from that provider. We do not receive or store your Google/GitHub password. These providers' policies apply to the authentication step.

4.4 Railway (Hosting)

LexAI is hosted on Railway (railway.app). Our database and server run on Railway's infrastructure. Railway has access to server logs and database backups as part of infrastructure operations. See railway.app/legal/privacy.

5. Case Law Data Sources

LexAI's case law search feature queries two public legal databases. Understanding these sources is important for professional use:

5.1 CourtListener (Free Law Project)

CourtListener is operated by the Free Law Project, a 501(c)(3) nonprofit. It contains 4M+ court opinions sourced from federal and state courts, PACER, and direct court feeds. Data is public domain (US government works). We query their API at courtlistener.com. Their privacy policy: free.law/privacy-policy.

Your search query is transmitted to CourtListener's API. CourtListener may log API queries per their policy.

5.2 Harvard Caselaw Access Project (CAP)

The Harvard CAP contains 6.7M cases from 1636 to 2020, digitised from Harvard Law School's physical collection. This data is made available for research and legal access purposes. We query their API at api.case.law. Their terms: case.law/terms.

5.3 Search Query Caching

To improve performance and reduce API load on public databases, case law search results are cached in our database for 24 hours keyed by a hash of the query. The raw query text is stored for this period and then deleted.

5.4 Accuracy Disclaimer

Case law results are provided for research purposes. LexAI does not guarantee the accuracy, completeness, or currency of case law data. Always verify citations through official legal databases before relying on them professionally. LexAI is not a substitute for qualified legal advice.

6. Self-Learning System

LexAI's self-learning feature is unique to our platform. Here is exactly how it works and what data it uses:

6.1 What Is Learned

When you rate an AI output or submit a correction, our system:

6.2 Scope of Learning

Learning is strictly per-user. Your patterns and corrections are never shared with other users, never used to improve the global AI model, and never aggregated for training purposes. They exist solely to personalise AI outputs for your individual account.

6.3 Document Memory (Knowledge Base)

Documents you save to your Vault are analysed to extract key facts, parties, and terms. These are stored as "knowledge items" and can be referenced in future AI prompts when relevant. This is opt-in by design — it happens when you save documents, not automatically for uploaded files that you don't save.

6.4 Deleting Learned Data

You can delete all learned patterns and knowledge items by deleting your account (see Section 9). We plan to add granular self-learning management in a future dashboard update.

7. Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:

We do not share your documents or data with other LexAI users outside of Shared Spaces you explicitly create.

8. Data Retention

Data typeRetention period
Account data (name, email, profile)Until account deletion + 30 days
Documents in VaultUntil you delete them or delete your account
Analyses & research resultsUntil you delete them or delete your account
Self-learning patternsUntil account deletion
Knowledge base itemsUntil you delete them or delete your account
Audit log (Firm plan)2 years from event date
Case law search cache24 hours
Session data30 days from last activity
Payment records7 years (legal/tax requirement)
Server access logs30 days
Deleted account residual backupsUp to 90 days in encrypted backups

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any right, email privacy@lexai.llc from the email address registered to your account. We will respond within 30 days. We may ask you to verify your identity before processing the request.

If you are in the EU/UK, you have the right to lodge a complaint with your local data protection authority.

10. Security

We take security seriously and implement the following measures:

No system is perfectly secure. In the event of a data breach that affects your personal data, we will notify you by email within 72 hours of becoming aware of it, in accordance with applicable data protection law.

To report a security vulnerability, email security@lexai.llc.

11. Cookies & Analytics

We use only essential cookies necessary for the platform to function:

We do not use Google Analytics, Facebook Pixel, advertising cookies, or any third-party tracking scripts. We do not build advertising profiles. Our analytics consist solely of server-side logs of feature usage, which are anonymised after 30 days.

12. International Transfers

LexAI is based in Bermuda. Our servers (via Railway) are located in the United States. When you use LexAI, your data is processed in the United States.

For users in the European Economic Area (EEA) or United Kingdom: transfers to the US are made under appropriate safeguards. We rely on Standard Contractual Clauses (SCCs) where required for transfers from the EEA/UK. By using LexAI, you consent to these transfers as described in this policy.

Anthropic, our AI provider, also processes data in the United States. Their API operations are covered by their enterprise data processing agreements.

13. Children's Privacy

LexAI is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact privacy@lexai.llc and we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

We maintain an archive of previous policy versions available on request.

15. Contact & Data Protection

For all privacy-related matters:

We aim to respond to all privacy requests within 5 business days and action them within 30 days.