Privacy Policy
Last updated: 2026-09-26
What we collect
- Account email, name, and auth provider (Supabase Auth).
- Documents you upload and chat messages you send.
- Usage telemetry: API call counts, feature usage, error reports (Sentry), page views (PostHog).
- Billing data managed by Polar.sh — we do not store card numbers.
How we use it
To provide the service, improve it, and respond to support requests. We do not sell your data.
Sub-processors
- Supabase (Postgres + Auth + Storage)
- Pinecone (vector index)
- Voyage AI, OpenAI, Anthropic, Google (LLM/embeddings — your data is not used to train their models)
- Polar.sh (billing)
- Resend (transactional email)
- Sentry (error monitoring)
- PostHog (product analytics)
- Vercel (hosting)
- Upstash (rate limit)
Your rights (GDPR)
You can export or delete your data from Settings. Email privacy@lexilift.dev for any other request. We respond within 30 days.
Data retention
Account data is retained until you delete your account. Soft-deleted accounts are hard-deleted within 30 days.
Contact
privacy@lexilift.dev