Lexie Privacy Policy

Last Updated: September 29, 2026

1. Data Controller

Interlinear Oy
Albertinkatu 26-28
elina@lexielearn.com
Business ID: 3523811-5

2. Key Principles

2.1 Mobile App - Minimal Data Collection

  • The app works without registration. An account is optional and is only needed to unlock content purchased on our website (see 3.3)
  • Learning content is stored on the user's device. Content you scan or type is sent to our server only transiently for AI processing and is not permanently stored on our servers
  • We do not collect names, phone numbers, or location data through the app

2.2 Privacy Principles

  • We minimize data collection to what is necessary for service operation
  • We prioritize user privacy and data security
  • We are transparent about what data we collect and why

3. Processed Data

3.1 Mobile App usage data

  • Device operating system, device model, and app version
  • App usage pattern and version
  • Anonymous analytics data about app functionality (for example the number of study sets created and study session statistics)
  • An app-specific device identifier, used to prevent misuse, to count free study sets, and to key anonymous usage statistics. It is not linked to your name.
  • Content you submit to create study materials (photos of study materials, typed or imported text, PDF files). This content is sent to our server, processed transiently by AI to generate your study materials, and is not permanently stored on our servers.
  • Answers and chat messages you type while studying, sent to our server transiently for AI feedback and grading
  • Feedback you choose to send through the app (your message, an optional screenshot, and an optional reply email address)
  • Purchase status (whether you have an active subscription or pass). Payments in the app are processed by Apple's App Store or Google Play; we never receive your payment card details.
  • Study sets you create cannot be shared with other users. Sharing is only available for Lexie's own courses.

3.2 Mobile App - What data is NOT collected

  • Name or phone number
  • Email address, unless you choose to sign in with an optional account (see 3.3)
  • Location data
  • Advertising identifiers. The app contains no ads and no ad tracking.

3.3 Account

An account is optional in the mobile app. On our website (lexielearn.com), an account is required to create study sets. Signing in happens with your email address and a one-time code; there is no password. If you create an account, we process:

  • Your email address (used for signing in)
  • An account identifier created when you sign up
  • Purchase status (whether a purchase has been made with your account, so that paid content opens for you). Your account identifier is shared with our purchase management provider (RevenueCat) so that your purchase can be recognized across the website and your devices.
  • Study sets you create on the website (see 3.4)

Accounts are intended for users aged 13 and over. Younger students can use everything Lexie does in the mobile app on a single device, without an account. You can delete your account and its data directly in the app, or by contacting us at elina@lexielearn.com.

3.4 Website study sets

  • Files you upload on the website (photos, screenshots, PDF files) are processed transiently to create your study set and are not stored, except for Image Occlusion (see below).
  • The study sets you create on the website, including text recognized from your files or text you have written or pasted, are stored in your account. They are available only to you and are kept until you delete them or your account.
  • Image Occlusion: when you create an Image Occlusion exercise on the website, the image you upload is stored as part of the study set. It is available only when you are signed in, and it is deleted when you delete the study set or your account.

3.5 Website purchases and gift codes

  • Subscriptions and passes bought on the website are processed by RevenueCat and Stripe. We receive your purchase status and purchase history, not your payment card details.
  • Gift codes are sold through Stripe. We process the buyer's email address and the purchase details needed to deliver the code.

4. Purpose and Legal Basis of Data Processing

4.1 Mobile App and website processing purposes

  • Providing the service, including storing your study sets in your account on the website
  • Developing app functionality
  • Improving user experience
  • Identifying and fixing technical issues
  • Analyzing usage statistics
  • Processing purchases and delivering gift codes

4.2 Legal basis for processing

  • Legitimate interest in developing and operating the service, including usage statistics
  • Contract performance (providing the service you requested, including purchases)
  • Legal obligation (for example bookkeeping of purchases, and responding to legal requests when required)

5. Data Storage and Protection

5.1 Data storage

  • Analytics data is stored in the EU/EEA area
  • In the mobile app, user-created content remains on the user's device. Content sent for AI processing is processed transiently and is not permanently stored on our servers.
  • On the website, study sets are stored in the user's account in an EU-hosted database (Supabase) until the user deletes them or their account
  • Image Occlusion images are stored in EU-hosted storage (Supabase, Sweden) until the user deletes the study set or their account
  • Generated audio is cached temporarily in server memory so the same text does not have to be generated again. The cache is cleared automatically within 7 days, and in practice whenever the server is updated.
  • Account data (email address, purchase status) is stored in an EU-hosted database (Supabase)
  • Data is stored only as long as necessary

5.2 Data security

  • All communications are encrypted (HTTPS/TLS)
  • Access to data is restricted to necessary personnel only
  • Systems are secured with industry-standard security measures
  • User data is stored in secure EU-hosted databases
  • We implement appropriate technical and organizational measures to protect your data

6. Data Transfers and Third-Party Processors

6.1 Data is not sold or shared with third parties for marketing purposes.

6.2 We use the following third-party service providers who process data on our behalf:

AI processing (mobile app and website):

  • Google (USA / EU) - Google Cloud Vision for image text extraction (OCR), Google Generative AI (Gemini) for creating study materials, and Google Cloud Text-to-Speech and Speech-to-Text for audio features. Under Google's API terms, the data is not used for model training.
  • Anthropic (USA) - For some content processing tasks, such as AI feedback on your answers (Claude). Under Anthropic's API terms, the data is not used for model training.
  • OpenAI (USA) - For some text processing tasks. OpenAI does not use API data for model training, and our account does not share data with OpenAI.

Other service providers:

  • Supabase (EU-hosted) - Database and file storage: accounts (email address), website study sets, Image Occlusion images, anonymous usage counters and referral codes.
  • RevenueCat (USA) - For managing purchases and subscriptions in the app and on the website. RevenueCat processes your purchase history, an anonymous or account-linked user identifier, and the device information needed to validate purchases.
  • Stripe (USA / EU) - For processing payments on the website, including gift codes. Stripe processes your payment details; we never receive your card details.
  • Vercel (USA) - For hosting the website and collecting anonymous, cookie-free page view statistics.
  • Resend (USA) - For sending email, such as gift codes and support and feedback messages. Sign-in codes are sent through Supabase.

All third-party processors handle data in accordance with GDPR requirements and are bound by data processing agreements that ensure appropriate data protection measures.

6.3 Data may be shared when:

  • Required by law or legal process
  • Requested by government authorities or law enforcement
  • Necessary to protect our rights or the safety of users

7. User Rights

7.1 Users have the right to:

  • Receive information about the data processing
  • Object to data processing by stopping use of the service
  • If you have created an account: request access to, correction of, or deletion of your account data, including your saved study sets. You can delete your account directly in the app, or by contacting us at elina@lexielearn.com.
  • File a complaint with the supervisory authority (Finnish Data Protection Ombudsman)

7.2 Exercising your rights

  • Contact us in writing at elina@lexielearn.com
  • We respond to requests within 30 days
  • We may need to verify your identity before processing certain requests

8. Cookies and Similar Technologies

8.1 The mobile app does not use cookies.

8.2 For collecting analytics data, we use:

  • The app's internal analytics system, which collects only anonymized usage data
  • Vercel's cookie-free page view statistics on the website

8.3 Our website uses only essential cookies and local storage for basic functionality, such as keeping you signed in. We do not use tracking or advertising cookies.

9. Children's Privacy

9.1 Our mobile app is designed for use by students, including minors. The app can be used fully without an account, and we do not knowingly collect personal data such as names, email addresses, or phone numbers from children. Accounts (which require an email address) are intended for users aged 13 and over. Because creating study sets on the website requires an account, the website is intended for users aged 13 and over.

10. International Data Transfers

10.1 Some of our service providers (Google, Anthropic, OpenAI, RevenueCat, Stripe, Vercel, Resend) are based in the United States. When data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with GDPR-compliant terms
  • Commitment to data minimization and purpose limitation

10.2 We regularly review our data transfer mechanisms to ensure compliance with EU data protection laws.

11. Data Breach Notification

11.1 In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected users without undue delay if there is a high risk
  • Provide information about the nature of the breach and steps taken to address it

12. Privacy Policy Changes

12.1 We reserve the right to modify this privacy policy to reflect changes in our practices or legal requirements.

12.2 Material changes will be announced:

  • In the mobile app
  • On our website (lexielearn.com)

12.3 Continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Information

13.1 Data Protection Contact

Interlinear Oy
Albertinkatu 26-28, Helsinki, Finland
Email: elina@lexielearn.com
Business ID: 3523811-5

13.2 Supervisory Authority

Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: tietosuoja.fi

13.3 For privacy-related questions, data access requests, or to exercise your rights, please contact us at elina@lexielearn.com