Lexperly ("we," "us," or "our") is an AI-powered administrative platform for small law firms. References to "you" mean the law firm, its authorized users (attorneys, staff), and in some contexts the individual creating an account.
Lexperly acts as a data processor for the personal data of your clients and third parties that you input into the Service, and as a data controller for account and usage data we collect directly from you.
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Contract performance |
| Processing AI assistant requests on your behalf | Contract performance |
| Billing and subscription management | Contract performance |
| Sending product updates, security notices, and support responses | Legitimate interest / contract |
| Improving and developing our AI models and features | Legitimate interest (using anonymized data only) |
| Fraud prevention and security monitoring | Legitimate interest / legal obligation |
| Complying with legal obligations | Legal obligation |
| Marketing communications (with opt-out) | Consent |
We do not use your Firm Data (including client information or matter details) to train AI models without your explicit consent.
We share information only as necessary to provide the Service:
We use Anthropic (Claude) to power AI assistant responses. Prompts and context you send to AI assistants are transmitted to Anthropic's API. Anthropic's use of this data is governed by their own Privacy Policy and API Terms. We recommend reviewing their data handling practices, particularly regarding data used for model training.
If you connect Gmail, Google Calendar, or Google Drive, we access those services on your behalf using OAuth. We only access the data necessary to perform the tasks you request. Google's Privacy Policy applies to your Google account data.
If you connect Microsoft Outlook or OneDrive (when available), similar OAuth access terms apply. Microsoft's Privacy Statement governs your Microsoft data.
Billing is handled by Stripe. We do not store payment card numbers. Stripe's Privacy Policy applies to payment data.
The Service runs on Google Cloud Platform. Data is stored in US-based data centers. Google's infrastructure privacy practices apply.
When you connect third-party tools like LeanLaw, Clio, DocuSign, or Calendly, those providers' privacy policies govern how they handle data. Lexperly is not responsible for third-party data practices.
We may disclose information if required by law, court order, or to protect the rights, property, or safety of Lexperly, our users, or others.
We do not sell personal data to advertisers or data brokers.
We understand that information processed through Lexperly may include privileged attorney-client communications and confidential client matter details. We treat all Firm Data as confidential and implement appropriate safeguards. However:
We retain your account and Firm Data for as long as your subscription is active. After termination:
Backups may persist for up to 60 days beyond the deletion date.
We implement industry-standard security measures including:
No system is completely secure. If you believe there has been a security incident affecting your account, contact us immediately at hello@lexperly.ai.
We use session cookies strictly necessary to maintain your login state. We do not currently use advertising cookies or cross-site tracking technologies.
We may use basic analytics (page views, feature usage) using privacy-respecting tools. We do not sell or share analytics data with advertising networks.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at hello@lexperly.ai. We will respond within 30 days.
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect and to opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, contact us at hello@lexperly.ai.
If you are located in the European Economic Area or United Kingdom, you have rights under the General Data Protection Regulation (GDPR). Our legal basis for processing is described in Section 3. You may lodge a complaint with your local supervisory authority if you believe we have violated your rights.
The Service is not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
Lexperly operates in the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US, where data protection laws may differ from those in your jurisdiction. By using the Service, you consent to this transfer.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the changes.
For privacy questions, data requests, or to report a concern:
Lexperly
Email: hello@lexperly.ai
Website: lexperly.ai
We aim to respond to all privacy inquiries within 5 business days.