Privacy Policy

Last Updated: June 12, 2026

1. Information We Collect

We collect user account information (such as name, email address, role, and organization) when you register. We process the contracts, playbooks, and templates you upload solely to execute your requested AI analysis.

2. How We Use Your Data

Your uploaded documents are processed on isolated container threads to run automated reviews and generate tracked changes. We enforce a no-training policy for public LLM API calls, and we never use your files to train public AI models.

3. Data Retention & Deletion

You retain complete control over your data. You can delete matter files, documents, and historical review logs from the workspace at any time. Deleted resources are immediately purged from our active databases and encrypted vault storage.

4. Third-Party Processing

Which infrastructure and service providers process your data depends on how LexCore is deployed for you. On a sovereign deployment, processing happens entirely inside your own boundary and no document content leaves it. Every provider that applies to your deployment is engaged under a data-processing agreement, and is listed in our published sub-processor register.

5. Google Workspace data we access

If you connect a Google account, LexCore requests only the permissions the features you enable actually need. This is the complete list, what each one is used for, and what happens to the data.

PermissionWhat we do with itWhat we keep
See your primary email addressIdentifies which Google account is connected, so you can see it in settings and disconnect it.The address, on the connection record. Nothing else.
See and edit events on your calendarsWrites court dates, filing deadlines and matter events you create in LexCore into your calendar, and reads them back so the two stay in step.Event id, title, time and the matter it belongs to. Not the contents of unrelated events.
Manage your tasksCreates a task when a matter deadline is assigned to you, and marks it done when the deadline is met.Task id and completion state, linked to the matter.
See, edit, create and delete only the files you open with LexCoreImports a document you pick, and writes an agreed redline back to that same file. It cannot see any other file in your Drive.The document text, in your workspace, until you delete it.
See and download all your Drive filesOnly where your organisation switches on Drive browsing, so LexCore can list folders instead of asking you to pick each file. Requested for the listing itself; a document is read only when you choose it.Folder and file names while browsing. File contents only for documents you select.
Read Google Meet conference recordsAttaches a meeting recording to the matter it belongs to, for organisations using the governance module.The meeting id and its link to the matter.
Send email on your behalfOff unless your organisation enables it. Sends a document for signature or a client update from your own address rather than ours.That the message was sent, and to which matter. We do not read your mailbox — this permission cannot.

We never read your Gmail inbox. No permission we request allows it.

How it is stored. Google data is encrypted in transit and at rest, held in the workspace of the organisation that connected the account, and reachable only by members of that organisation who have access to the matter it belongs to. Access is written to a tamper-evident audit record.

How to stop it. Disconnect the account in LexCore settings, or revoke access directly at myaccount.google.com/permissions. We delete the stored tokens immediately. Documents already imported into a matter remain until you delete them, because they have become part of the firm's file — delete them the same way you delete any other document.

What we never do. We do not sell Google user data, use it for advertising, use it to train any AI model, or transfer it to anyone except as needed to run the feature you connected or where the law requires it.

6. Google API Services — Limited Use

LexCore's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

In practice that means we do not use Google Workspace data to train any AI model, we do not sell it, we do not transfer it to others except as needed to provide the feature you connected or where the law requires it, and no person reads it except with your explicit permission or for security and legal reasons.