The short version
- Your work stays on your computer, unless you send it.Projects, memories and glossaries are saved locally. We receive text only when you run AI or share a project with your team.
- No ads and no analytics.This website doesn’t use an analytics or advertising tool. The server still writes a short security log, and the download is fetched from GitHub, which sees your IP address.
- We don’t train on your texts.We don’t use them to train models, and we don’t opt in to OpenAI training. OpenAI can still keep API request text for up to 30 days to look for abuse, unless a zero-retention add-on is on. It is not on today.
- You’re in control.Ask us at any time to see, export, correct or delete your data.
Who is responsible
The controller is:
Your full name
Street and number
Postcode, city, country
Email: privacy@lexorastudio.com
There is no company yet. The person above decides why and how this data is used. If we later register a company and it becomes the controller, we update this page and email account holders before that happens. The same name and address are in our legal notice.
We are established outside the EU and we offer Lexora to people in the EU. We have not yet appointed a representative in the Union. Until we do, write to the address above. We will name the representative here once appointed.
The desktop app
Lexora Studio saves your projects, documents, memories, glossaries and settings in your Windows user folder. We can’t see projects you don’t share and don’t send to AI. The app has no analytics and no crash reporting. Spellcheck runs through Windows on your computer.
The app does contact the internet in these cases:
- Sign-in and licence. When you sign in, and every few hours while the app is open, it asks our server to renew your licence. It sends your sign-in token, an ID for this computer and the computer’s name. See Your account.
- Updates. It checks for and downloads new versions from GitHub. GitHub sees technical data such as your IP address, the time, and device and app details. See Who receives data.
- AI features, when you use them. See AI review and translation.
- Team projects, if you join a team. See Teams.
This website
Server logs
When you visit, the host of this website, hosting provider and country, records what your browser sends with each request: IP address, date and time, the page requested, the referring page, and browser and system type. We use this only to deliver the site and keep it secure. We delete our copy after 14 days. The host’s own retention can be longer, and we don’t control that.
Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).No ads or analytics
This website doesn’t use an analytics, advertising or tag-manager tool. Fonts and our own files are served from our server. The account page and the Log in window contact Supabase and our Lexora server only when you sign in or sign up. The Download button fetches the installer from GitHub, which sees your IP address and other technical data described under GitHub below. That is not an analytics tool of ours, but it is a disclosure, so we don’t call the site “no tracking”.
Storage in your browser
- Signed in: when you sign in on this website, the browser keeps the sign-in in its local storage, so you stay signed in and the menu shows “Account” instead of “Log in”. It is deleted when you sign out. Signing in goes through Supabase. We don’t set a cookie for this.
- Your language choice: if you pick a language in the example on the home page, the browser remembers it in local storage, so the example opens in that language next time. It never leaves your browser. It is written only after you pick a language.
Both store data only for a function you asked for, so they don’t need a consent banner. You can delete them in your browser settings. If we ever add a non-essential cookie, we will ask first.
Your account
You need an account to use Lexora Studio, including the free trial. The account is how the app knows your plan.
- What we store: your name and email address; your plan and where it comes from (your subscription, your team’s plan or the free trial); when your trial started; when you signed up and when you last used Lexora.
- Your computers: for each computer you sign in on, we store an ID for that computer, its name as Windows shows it, and when it was added and last used. The ID is a hash of the ID Windows gives the computer. It can’t be turned back into that ID. An account can be signed in on two computers, and you can sign one out in the app. A Windows computer name is often a person’s name, so we treat it as personal data.
- Your licence: the app keeps a licence on your computer that our server signed. It contains your name, email address, plan and computer ID, and lets the app work offline for up to 7 days.
- Sign-in: sign-in runs through Supabase, which stores your email address (and your name, if you sign in with Google) and sends the short-lived sign-in codes. Lexora never stores a password.
- Sign in with Google: if you choose it, Google confirms your name and email address. We never receive your Google password. Google’s own privacy policy applies to its part.
- Usage of the plan: for each month we record how many AI credits you used, how many AI requests you made, and what they cost us. We don’t record the text in that usage record. This is how we apply your plan’s limits. It is account data, not analytics of how you work.
We keep your account data while your account exists and delete it within 30 days after you close it, except records the law requires us to keep (see Payments).
Legal basis: performing our contract with you (Art. 6(1)(b) GDPR).AI review and AI translation
AI features are off until you turn them on for a project, when you create it or later in its settings. The app remembers your last choice for the next new project, and you can change it there. When you then run AI review or AI translation, the app sends to our server the source and target text of the segments you chose, the language pair, matching glossary terms, and the project brief if you wrote one. For AI translation it also sends the sentence before and after each segment, and up to three similar translations from the project’s memories, so the translation fits its context. For AI review it also sends the language of the app’s interface, so the findings are explained in that language.
Our server passes this to OpenAI, or to DeepL if you choose DeepL for a translation, and sends you the result. Our server doesn’t store the text. It records the credits and the cost of the request.
- OpenAI. The API contract is with OpenAI OpCo, LLC (San Francisco). OpenAI Ireland Limited processes personal data of people in the EEA under that contract. API data is not used to train OpenAI models unless we explicitly opt in. We don’t opt in. This is not zero-retention. By default, abuse-monitoring logs may contain the request text and are kept for up to 30 days, and longer if the law or a safety review requires it. EU-only processing is not turned on. Transfers outside the EEA are covered by the EU Standard Contractual Clauses in OpenAI’s data processing addendum, not by the EU-US Data Privacy Framework.
- DeepL. This describes DeepL API Pro, contracted with DeepL SE, Maarweg 165, 50825 Cologne, Germany. On that plan, submitted text is kept only as long as needed to produce and send the translation, then deleted. It is not used to improve DeepL’s models. In an error, DeepL may keep the content encrypted for up to 72 hours. Access logs may keep the time and the size of the request, not the text. Unless we have bought DeepL’s data-residency add-on, and we have not, customer content may be processed in AWS regions outside Europe, including the United States and Asia-Pacific. Transfers use the EU-US Data Privacy Framework and Standard Contractual Clauses. The free DeepL API is a different product: it may store text and use it for training. Lexora does not use the free DeepL API.
Documents you translate may contain personal data about other people. For that content you decide what is sent, and we process it on your behalf (Art. 28 GDPR). Business customers get our data processing agreement before this starts. Ask at privacy@lexorastudio.com.
Legal basis: performing our contract with you, because you ask for the feature (Art. 6(1)(b) GDPR).Teams
If you create or join a team, we store:
- your name in the team, your role, the colour and symbol of your avatar, when you joined and when you were last online;
- the team’s activity history: who changed what in a shared project, and when;
- invite codes, which expire after 7 days and are then deleted;
- the projects members share: their documents, segments, glossary terms, memory entries and original files, so the team can work on them together.
Projects you don’t share stay on your computer. The memories and glossaries a shared project uses are shared with the team only when you share the project or tick them in it. Your other memories never leave your computer. Your team sign-in works only with your own Lexora account. Each team can store up to 2 GB. When someone is removed, they lose access at once. When the owner closes the team, or asks us to delete it, we delete the team’s data within 30 days, except where the law requires us to keep a record.
Legal basis: performing our contract with the team owner (Art. 6(1)(b) GDPR). For the content of shared projects we act on the team owner’s behalf (Art. 28 GDPR).Payments
Paid plans are paid through Whop Inc., 300 Kent Ave #401, Brooklyn, NY 11249, United States. Whop receives your payment details. We never see or store card numbers. Whop tells our server when a subscription starts, renews or ends, and sends the buyer’s email address, the plan, the renewal date and a subscription ID, so we can match the purchase to your Lexora account. If you link a purchase with its licence key, we store only a hash of the key. Whop’s privacy policy applies to the payment. Transfers from the EU to Whop use EU Standard Contractual Clauses. We keep invoices and payment records for as long as tax law requires, usually up to 10 years.
Legal basis: performing our contract with you and our legal obligations (Art. 6(1)(b) and (c) GDPR).Emails and support
Sign-in codes are sent by Supabase, not by a separate newsletter tool. Payment receipts are sent by Whop. We email you from hello@lexorastudio.com about your account, price changes and these terms. We don’t send product news unless you subscribe. The legal basis for product news is your consent, and every one of those messages has an unsubscribe link. Withdrawing consent doesn’t affect the service emails the contract requires.
When you write to us, we use what you send to answer you. We keep it for as long as the thread is open and delete it within 24 months after the last message, unless we need it for a claim or a legal duty.
Legal basis: the contract (Art. 6(1)(b) GDPR) for service emails; consent (Art. 6(1)(a)) for product news; legitimate interest in answering (Art. 6(1)(f)) for messages from people who don’t have an account.Who receives data
We use these providers. We don’t sell personal data and we don’t share it for advertising. Where a provider acts for us, it does so under a contract. Google and GitHub also act for their own purposes when you use their pages, under their own policies.
| Provider | What for | Where | Transfer |
|---|---|---|---|
| Hosting provider | This website and its server logs | Country | Named once the host is fixed |
| OpenAI OpCo, LLC, with OpenAI Ireland Limited processing EEA personal data | AI review and AI translation | United States, and not limited to the EU | EU Standard Contractual Clauses. Not the Data Privacy Framework. |
| DeepL SE | DeepL translation, if you choose it | Germany, and AWS regions that can include the US and Asia-Pacific | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Supabase Pte. Ltd. | Sign-in and sign-in codes | Database and auth set to EU (Frankfurt). Supporting data can be processed elsewhere. | EU Standard Contractual Clauses. Not the Data Privacy Framework. |
| Sign in with Google, if you choose it | EU and United States | Google’s own safeguards. We receive only your name and email. | |
| GitHub, Inc. and GitHub B.V. | Installer download and app updates | United States and Netherlands | EU Standard Contractual Clauses and GitHub’s EU-US Data Privacy Framework. GitHub’s privacy statement says personal data may be used to train models. |
| Whop Inc. | Payments, receipts and subscription status | United States | EU Standard Contractual Clauses |
Supabase’s region is only a real limit if the project is set to eu-central-1 (Frankfurt). Choosing that region keeps the database, auth and storage objects there. It does not by itself cover backups, logs, edge functions or sub-processors. Supabase Pte. Ltd. is in Singapore.
Your rights
You can ask us to:
- tell you what data we hold about you and give you a copy (Art. 15 GDPR);
- correct it (Art. 16);
- delete it (Art. 17);
- limit how we use it (Art. 18);
- give it to you in a machine-readable format, where that right applies (Art. 20).
You can object at any time to processing based on our legitimate interests (Art. 21). You can withdraw any consent you gave, with effect for the future (Art. 7(3)).
Write to privacy@lexorastudio.com. We answer within one month. You can also complain to a data protection authority, in particular in the country where you live or work, or where the issue happened. Because we are not established in the EU, there is no single lead EU authority yet. Once we appoint an EU representative, we will name their authority here.
More details
Do you have to give us data?
Only an email address, to create the account that Lexora Studio needs. AI text and team files are sent only if you use those features.
Automated decisions
We make no decision about you that has a legal effect, or a similar significant effect, based solely on automated processing. AI review gives suggestions. You decide what to use. Plan limits are the application of the quota you bought, not a decision about you as a person.
Children
Lexora is not meant for people under 18, and we don’t knowingly collect their data. If you believe we have, write to us and we will delete it.
Security
Data in transit is encrypted (HTTPS). Licence keys are stored only as hashes. Sign-in works without a password we keep. Licences are signed so they can’t be edited on a computer. Team files are stored on our server. Keep your own copies.
Changes
When we change this policy, we update the date at the top. We email account holders about important changes before they apply.