LexForge / privacy
Legal document privacy notice
This privacy notice covers how LexForge collects, uses and protects your data.
Data processed
LexForge processes account details, workspace settings, uploaded house-style templates, source documents, generated outputs, wording-check metadata, usage records, browser error telemetry, product analytics, support messages and billing records.
To prevent repeat Free-trial abuse, LexForge retains a pseudonymous personal data marker: a domain-separated, one-way hash of the signed Clerk user, the historical account reference and the redemption timestamp. It contains no raw Clerk ID, email, name, organisation ID or document data. We retain it only while needed to enforce the one-trial-per-signed-user rule; it is not used for other purposes.
Document content
Document content is customer confidential data. Wording-check summaries avoid storing full document text by default. Generated documents and uploaded files are retained only for the period needed to provide the service and support customer review.
Sub-processors
Sub-processors include Microsoft Azure for hosting, storage, database and Document Intelligence optical character recognition (OCR) in UK South. Structure and layout analysis runs through the Azure OpenAI EU Data Zone within the EEA. LexForge also uses Clerk for sign-in and user accounts, Stripe for billing, Mailjet for transactional email, Sentry for browser error monitoring and PostHog for cookieless product analytics. Azure OpenAI receives relevant full-page images and extracted text for structure and layout analysis in the EU Data Zone. Requests use storage disabled (store=false), so normal Responses API conversation state is not retained. Customer material is not used to train generative models. Microsoft performs automated abuse monitoring. Material flagged by the abuse-monitoring system, or identified as part of a potentially abusive pattern of use, may be stored in a Microsoft-controlled abuse-monitoring store and reviewed by authorised Microsoft staff. Documents and OCR remain in UK South. See the full list on the security page.
Monitoring and analytics
Browser error monitoring and product analytics are limited to operational metadata, such as which product area was used and whether a conversion workflow succeeded or failed. They must not include document text, filenames, extracted wording, email addresses, names, job IDs or tenant IDs.
Customer control
Customers can export generated outputs, delete their tenant and request deletion of stored files. Contact support@lexforge.app to exercise these rights.
Uploaded scans are scheduled for automatic deletion from active storage two hours after upload. Standard extracted-text cache entries are scheduled for deletion after two hours. If application cleanup is delayed, Azure Storage lifecycle rules make both eligible for deletion once they are more than one day old. Microsoft controls the exact lifecycle processing time. Deleted blobs may remain recoverable to authorised administrators for up to seven days under Azure soft delete. Converted outputs are kept for your workspace's retention period, seven days by default and up to 30 days. See the security page.
Privacy questions can be sent to support@lexforge.app.