Skip to content
Lexapient
Capabilities Privacy Process Pricing FAQ
Get the app
Legal

Privacy Policy

Last updated: August 2, 2026 · Version 1.1

Contents

  1. Overview & Our Promise
  2. Zero-Access Architecture
  3. Data We Collect
  4. Data We Never Collect
  5. Local Data Storage
  6. API Key Handling
  7. Network Endpoints
  8. Google's Data Handling
  9. Analytics & Telemetry
  10. The Lexapient Website
  11. Your Rights & Choices
  12. Changes to This Policy
  13. Contact

1Overview & Our Promise

Lexapient is a Windows desktop application that automates the extraction, classification, and structuring of information from documents. It connects directly to the Google Gemini API. There is no intermediary server, no cloud backend, and no third-party processing layer operated by Lexapient.

Our core guarantee: Document content, prompts, Playbooks, and extraction results never pass through any infrastructure controlled by Lexapient. We cannot see your data. That is not a policy promise; it is how the application is built.

This Privacy Policy explains what data the application handles, where it is stored, what network connections it makes, and what choices you have.

2Zero-Access Architecture

Privacy is the foundational design principle of Lexapient. The application communicates directly with the Google Gemini API. Every API call goes straight from your machine to Google.

  • No man in the middle. Lexapient (the vendor) never sees, processes, stores, or has access to any document content, prompts, LLM responses, Playbooks, or extraction results.
  • No telemetry on content. The application does not transmit any user data, document content, or extraction results to Lexapient or any third party.
  • Both authentication modes are direct. Whether using a vendor-provisioned batch-scoped key or your own API key, every API call goes directly from your machine to generativelanguage.googleapis.com.

3Data We Collect

Lexapient collects the minimum data necessary to operate and improve the application:

Data Purpose Storage
Email address (account) Account creation, sign-in, and service communication about the application Our systems
Credit balance & usage totals Track your free starter credits and metered usage so the application can show costs and remaining balance Our systems. Counts and totals only, never document content
Anonymised usage analytics Feature usage counts (e.g., number of extractions run, Playbooks created). No content is included. Our systems

4Data We Never Collect

The following data never leaves your machine and is never transmitted to Lexapient:

×Document content

Your files, PDFs, and Word documents

×LLM prompts & responses

The queries sent to Gemini and the answers returned

×Playbooks & extraction rules

Your custom extraction configurations

×Extraction results

The structured data extracted from your documents

×Citations & source references

Verbatim text snippets linked to answers

5Local Data Storage

All application data resides on your local machine or your organisation's infrastructure:

Data Storage Location Vendor Access
Source documents Local filesystem, accessed in place and never copied None
Playbooks Local application data folder None
Extraction results Local application data folder None
LLM prompts & responses Prompts are transient in-memory only. The latest response for each document is saved to the local application data folder so sessions can be reopened. None
API key (vendor-provisioned) Transient in-memory only, created per batch and deleted on completion Key issuance only; never sees data processed with the key
Application settings Local application data folder None

6API Key Handling

The current release authenticates to the Gemini API using vendor-provisioned keys only.

Vendor-Provisioned Keys

A temporary API key is created per extraction batch, restricted to generativelanguage.googleapis.com only. The key is held in memory (never written to disk) and deleted immediately when the batch completes.

Bring Your Own Key (BYOK)

Not available in the current release. If a bring-your-own-key option is introduced, this policy will be updated before it ships.

7Network Endpoints

The application communicates only with the following endpoints. No other outbound connections are made:

Endpoint Purpose Data Transmitted
generativelanguage.googleapis.com Gemini API calls Document content + Playbook (encrypted in transit via TLS)
Vendor management service Create and delete batch-scoped API keys; record usage statistics Authentication credentials and usage counts only, no document content

You and your IT administrators can verify this via firewall rules or network monitoring tools.

8Google's Data Handling

Under Google's current Gemini API terms (as of the date of this policy):

  • API inputs and outputs are not used to train Google models.
  • Data is processed transiently and not retained beyond the API call lifecycle.

Lexapient surfaces Google's data handling terms during application setup and links to the current policy for transparency. We monitor changes to Google's terms and communicate any material changes to users.

For the latest information, refer to Google's Gemini API Terms of Service.

9Analytics & Telemetry

Lexapient may collect anonymised usage analytics, for example feature usage counts such as the number of extraction batches run or Playbooks created. This data:

  • Contains no document content, prompts, responses, or extraction results.
  • Contains no personally identifiable information beyond what is necessary for account management.
  • Is used solely to improve the product and understand feature usage patterns.

10The Lexapient Website

The sections above describe the desktop application. This one describes lexapient.com.

No Cookies, No Tracking

The website sets no cookies. It runs no analytics, no advertising or marketing pixels, no session recording, no fingerprinting, and no cross-site tracking of any kind. We do not build profiles of visitors, and we do not sell or share visitor data with anyone.

No Third-Party Content

Every asset the site loads, including styles, scripts, images, icons and typefaces, is served from lexapient.com itself. The site makes no requests to third-party domains, so no other company receives your IP address or learns that you visited. This is enforced by a Content Security Policy that restricts every content type to this origin, which you can inspect in the response headers using your browser's developer tools.

Links to the Microsoft Store, Google, and other external sites are ordinary links. They transmit nothing until you choose to follow one, at which point the destination's own privacy policy applies.

Browser Storage

One page uses browser local storage. The sign-in page, which the desktop application opens in an embedded browser view, saves a single value named lexapient-theme when you use the light and dark toggle, so that your choice survives into the next session. It records only the word light or dark. It contains no identifier and no personal data, it is never transmitted anywhere, and it is removed when you clear your browser's site data. No other page on the site stores anything.

Server Logs

The site is hosted on Microsoft Azure Static Web Apps. As with any web server, the hosting platform records standard request data: your IP address, browser user-agent string, the URL requested and a timestamp. This is necessary to deliver pages and to protect the service against abuse and attack, and our lawful basis for it is legitimate interests. That data is held by Microsoft under its own retention schedules. We do not combine it with any other data, we do not use it to identify or profile individual visitors, and we do not use it for analytics or marketing.

Why There Is No Cookie Banner

Consent banners exist because sites store or read information on your device for purposes you did not ask for. This site does not do that. The only thing it stores is a display preference that you set yourself by clicking a toggle, which is exempt from consent requirements under UK and EU e-privacy rules. Rather than show a banner asking for permission we do not need, we have built the site so that the permission is unnecessary. If that ever changes, we will ask properly, and this policy will be updated before it does.

11Your Rights & Choices

You have full control over your data:

  • Disable analytics: Turn off all anonymised usage analytics in the application settings.
  • Delete local data: All Playbooks, results, and settings are stored in your local application data folder and can be deleted at any time.
  • Verify network activity: The application's limited network endpoints can be verified with any firewall or network monitoring tool.
  • Request account deletion: Contact us to have your account and any associated data (email, credit balance, usage totals) permanently deleted.

12Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the application and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

13Contact

If you have questions about this Privacy Policy or our data practices, please contact us:

Lexapient

Email: privacy@lexapient.com

Lexapient

Intelligent document workspace.
Privacy by architecture.

Product

CapabilitiesProcessPricingFAQDownload

Privacy

ArchitecturePrivacy policyTerms of service

© 2026 Lexapient. All rights reserved.

support@lexapient.com