Privacy Policy
Effective date: April 1, 2026
LexiNote is operated by MbMedia. This policy explains what information we collect, how we use it, and your rights regarding your data. If you have any questions, email us at hello@lexinote.app.
1. Information We Collect
We collect information in the following ways:
- Account information β your email address and password (stored as a secure hash) when you register.
- Uploaded content β text, images, PDFs, and camera captures you submit to LexiNote for processing.
- Learning data β vocabulary entries, quiz results, mastery scores, and revision history generated from your uploads.
- Payment information β billing details (card number, billing address) processed directly by Stripe. LexiNote never stores your raw card data.
- Usage data β pages visited, features used, and error logs collected automatically to help us improve the service.
- Device and browser data β IP address, browser type, and operating system for security and analytics purposes.
2. How We Use Your Information
- To provide, operate, and improve the LexiNote service.
- To process uploaded content using OCR and AI to extract and structure your learning material.
- To generate quizzes and revision sessions personalised to your saved content.
- To manage your account, subscription, and billing.
- To send transactional emails (account confirmations, password resets, billing receipts).
- To send push notifications if you have opted in.
- To detect and prevent fraud, abuse, or security incidents.
- To comply with applicable laws and legal obligations.
We do not sell your personal data to third parties. We do not use your uploaded learning content to train AI models or share it with any party other than those listed in Section 3.
3. Third-Party Services
We use trusted third-party services to operate and improve LexiNote. These providers may process limited user data only as necessary to perform their functions on our behalf.
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication and session management | Email, authentication data |
| Stripe | Payment processing and subscription billing | Payment details (handled securely by Stripe), billing metadata |
| Cloudflare R2 | Secure file storage for uploaded content | Uploaded files (notes, images, PDFs) |
| OpenAI | AI-powered quiz generation and note structuring | User-provided content (notes, prompts) |
| Google Cloud Vision | OCR for images and scanned PDFs | Uploaded images and documents |
| OneSignal | Push notifications (opt-in only) | Device tokens, notification preferences |
Each provider operates under its own privacy policy and data protection practices. We do not sell your personal data to any third parties. We only share the minimum data required for these services to function.
4. Data Retention
We retain your account and learning data for as long as your account is active. If you delete your account, we delete your personal data and uploaded files within 30 days, except where we are required to retain records for legal or financial compliance purposes.
5. Cookies and Tracking
LexiNote uses essential cookies to keep you signed in and maintain your session. We may use analytics tools that set non-identifying cookies to understand how users navigate the product. We do not use advertising cookies or track you across other websites.
6. Your Rights
Depending on where you are located, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your account and associated data.
- Export your learning data in a portable format.
- Withdraw consent for optional communications (push notifications, marketing emails).
To exercise any of these rights, email us at hello@lexinote.app. We will respond within 30 days.
7. Children's Privacy
LexiNote is not intended for children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
8. Security
We use industry-standard measures including HTTPS encryption, hashed passwords, and access controls to protect your data. No method of transmission over the internet is completely secure, but we take reasonable steps to safeguard your information.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For significant changes, we will notify you by email or via an in-app notice.
10. Contact
For any questions or concerns about this Privacy Policy, contact us at hello@lexinote.app.
