Lexi
AI Performance Coach

Privacy Policy

Flagship Digital LLC · Effective April 28, 2026 · Last updated April 28, 2026 · v1.1
01

Introduction

Flagship Digital LLC ("we," "us," or "our") operates the Lexi AI Performance Coach application ("Lexi," "the App"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use Lexi.

By using Lexi, you agree to the practices described in this policy. If you do not agree, please do not use the App.

Contact: privacy@meetlexi.ai
Registered Agent: 7901 4th St N STE 300, St. Petersburg, FL 33702

02

Information We Collect

Information You Provide Directly

Information Collected Automatically

Information from Third-Party Services

03

How We Use Your Information

04

Data Sensitivity Classification

We recognize that health data is sensitive. We classify your data by sensitivity level:

Highest Sensitivity
  • Progress photos & VA results
  • Voice recordings
  • Journal entries
  • Injury history & medical conditions
  • Menstrual cycle data
  • Eating disorder history
High Sensitivity
  • Weight & body composition
  • Body fat percentage
  • Macro & calorie data
  • Hydration & alcohol logs
  • Workout & fitness data
  • Fasting windows
05

AI Processing Disclosure

Lexi is powered by artificial intelligence. When you interact with Lexi:

We have configured Zero Data Retention (ZDR) with Anthropic — your data is not used to train Anthropic's models. OpenAI Whisper transcription is processed and discarded.

Lexi is not a licensed medical professional, registered dietitian, or certified personal trainer. Lexi's coaching is for informational and motivational purposes only and is not a substitute for professional medical, nutritional, or fitness advice.

5b

Beta Program — Operator Review of Tester Conversations

If you participate in the Lexi beta program via TestFlight, you acknowledge and consent that authorized members of the Lexi team (operators) may review your conversations with Lexi and your account data for the limited purposes of:

This operator-review access applies only to users designated as beta testers (is_test = TRUE in our systems) and only while the beta-program operator-review feature flag is active. Every operator view of beta tester data is recorded in our audit log, including the operator identity, timestamp, and scope of access.

This access does not apply to production (non-beta) users. Once Lexi launches publicly, operator access to user conversations transitions to the user-initiated support pathways described in our public Customer Support Flow, which require explicit, time-bound user authorization or a documented legal/safety basis.

If you wish to withdraw from the beta program at any time, contact us at privacy@meetlexi.ai. Withdrawal terminates beta access and triggers our standard data retention process described in Section 7.

06

Sub-Processors

We share data with the following third-party service providers to operate Lexi:

ServicePurposeData Shared
AnthropicAI coaching, visual assessmentMessages, health context, progress photos
OpenAIVoice transcription (Whisper)Voice audio (transcribed and discarded)
ElevenLabsVoice response generationLexi's text responses only
RailwayCloud hosting and databaseAll app data (encrypted at rest)
Cloudflare R2Progress photo storageProgress photos (encrypted at rest)
SendGridTransactional emailEmail address
TwilioSMS notifications (if enabled)Phone number
AppleHealthKit data syncHealth metrics you authorize
StripePayment processingPayment information (not stored by us)

We do not sell your personal data to third parties. We do not share your data with advertisers.

07

Data Retention

Data TypeRetention Period
Active account dataUntil account deletion
Deleted account PIIAnonymized within 30 days of deletion
Expired session tokensDeleted after 30 days
API usage logs90 days
Phone verification codes24 hours
Audit logs365 days
Progress photosUntil deleted by you or account deletion
Journal entriesUntil deleted by you or account deletion

Upon account deletion, we anonymize your personally identifiable information within 30 days — within the 45-day maximum required under Washington's My Health MY Data Act (MHMDA) and Connecticut's CTDPA.

08

Your Rights

All Users

Washington State (MHMDA)

California (CMIA)

Connecticut (CTDPA), Illinois (BIPA), Texas (CUBI)

Applicable rights under each state's data protection law apply to residents of those states.

To exercise any of these rights, contact us at privacy@meetlexi.ai. We will respond within 45 days.

09

Biometric Data (Illinois BIPA)

If you use voice input features or upload progress photos, you may be providing biometric identifiers subject to the Illinois Biometric Information Privacy Act (BIPA). By using these features, you provide written consent to our collection and processing of this data as described in this policy. Biometric data is not sold or shared beyond the sub-processors listed above.

10

Children's Privacy

Lexi is intended for users aged 17 and older. We do not knowingly collect personal information from anyone under the age of 17. If you believe a minor has provided us with personal information, contact us at privacy@meetlexi.ai and we will delete it promptly.

11

Data Security

Despite these measures, no system is completely secure. We encourage you to use a strong password and enable biometric authentication within the App.

12

Mental Health and Crisis Content

Lexi includes safety guardrails for mental health content. If Lexi detects language related to suicide, self-harm, or eating disorders, it will refer you to professional resources and will not attempt to coach through these situations.

If you are in crisis: Contact the 988 Suicide and Crisis Lifeline (call or text 988) or the Crisis Text Line (text HOME to 741741).
13

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the App after changes take effect constitutes your acceptance of the updated policy.

14

Contact Us

For privacy questions, data requests, or concerns:

Email: privacy@meetlexi.ai
Mail: Flagship Digital LLC, 7901 4th St N STE 300, St. Petersburg, FL 33702

For urgent privacy matters, please include "URGENT PRIVACY" in your subject line.