This page explains what LEX stores about a firm and its clients, where that data lives, which providers touch it, how it is protected, how long it is kept, and how a firm gets it out or has it deleted.
- In short
- 1. What LEX stores
- 2. What it is used for
- 3. AI processing
- 4. Where data lives and who processes it
- 5. How data is protected
- 6. How long data is kept
- 7. Getting your data out, and deleting it
- 8. The Firm's responsibilities
- 9. Cookies
- 10. Age
- 11. Changes and contact
In short
LEX stores the records, documents and conversations a law firm puts into its workspace, and sends the relevant parts to an AI model to do the work the firm asked for. Each firm's data is walled off from every other firm. We do not sell data, we do not show ads, and we do not train models on your content. The firm can get its data out, and can have it deleted.
1. What LEX stores
Depending on how the Firm uses the service:
- Account details: email address, the name you choose to display, your role, and sign-in records.
- Firm details: the firm's name, plan and settings.
- Case and client records: names, contact details, case descriptions, tasks, follow-ups and notes your team enters.
- Documents you upload, the text and page images extracted from them, and the classification, facts, drafts, summaries and compliance flags generated from them.
- Conversations with Lex, including documents attached in chat.
- Case values, fees and related notes entered by administrators.
- Usage records: which feature ran, when, and how many AI tokens it used. These never contain document text.
- Technical logs (such as IP address and browser type) kept for security and troubleshooting.
2. What it is used for
To provide the service the Firm asked for, to generate AI output, to keep the service secure, to support you, and to apply usage allowances and billing. We do not use Firm Content to train our own or anyone else's models, we do not sell it, and we do not use it for advertising.
3. AI processing
To read a document or answer a question, LEX sends the necessary text (and, when scanned-page reading is on, images of scanned pages) together with case context and your chat messages to Anthropic's Claude API and receives the result. We send only what the task needs.
Under Anthropic's commercial terms, data submitted through the API is not used to train Anthropic's models. Anthropic may retain API data for a limited period for abuse and safety monitoring, as described in its policies. AI output is stored in the Firm's workspace like any other record.
4. Where data lives and who processes it
Infinity Link runs LEX on the following providers ("subprocessors"). Each is bound by its own terms and security commitments; we choose providers that encrypt data in transit and at rest.
| Provider | What it does for LEX | Where |
|---|---|---|
| Supabase | Database, sign-in, and private document storage | United States (AWS us-east-2, Ohio) |
| Vercel | Hosting of the web application and its server functions | United States |
| Anthropic | AI model (Claude) that reads documents and drafts text | United States |
| Resend | Transactional email: invitations and password resets | United States |
| Hostinger | Server running the document-processing workflow (n8n) | United States |
5. How data is protected
The main safeguards, in plain terms:
- Firm isolation: every record is tagged with the firm it belongs to and the database enforces that a signed-in person can only read their own firm's records. This isolation is tested.
- Documents live in a private storage bucket that browsers cannot read; the application serves each file only to a signed-in member of the owning firm, through a short-lived link.
- Lex, the AI assistant, can only see what the signed-in person can see, and the only change it can make to records (filing a document to a case) requires a human to click Approve.
- Administrator-only areas (team management, case values and fees) are enforced in the database, not just hidden in the interface.
- Data is encrypted in transit (HTTPS) and at rest by our providers. Passwords are never stored in readable form.
- AI usage records hold token counts, never document text.
6. How long data is kept
Firm Content is kept for as long as the Firm's workspace is active, or until the Firm deletes it. Sign-in and technical logs are kept for a short period for security. Usage records are kept for accounting. Our providers' backups expire on their own schedules, typically within thirty days.
7. Getting your data out, and deleting it
A Firm administrator can ask for an export of the Firm's clients, cases, notes and stored documents by writing to elixira86@gmail.com. A self-service export inside LEX is on our roadmap.
A Firm administrator can ask us to close the workspace. We delete the Firm's content 30 days after a verified request, except what we must keep by law or for accounting, and we confirm in writing when it is done. Administrators can remove individual team members at any time from Settings; a person can ask for their own account to be deleted at the same address.
8. The Firm's responsibilities
For its clients' information, the Firm is the party that decides what is collected and why; Infinity Link processes it on the Firm's instructions. The Firm is responsible for its professional confidentiality and ethics rules, for any client notices or consents those rules require, and for not uploading material it may not share with a service provider.
10. Age
LEX is for professionals and is not intended for anyone under 18.
11. Changes and contact
We will post updates to this page at https://asklex.legal/privacy with a new effective date and email workspace administrators about material changes. Questions or requests: elixira86@gmail.com.