Trust
Your health data is not our product.
We don’t sell it. We don’t use it for targeted advertising. We don’t use it to train third-party AI models. And you can read exactly where it goes before you agree to anything.
Who touches your data, and why
The services behind Lexi, each with one job.
- AI conversation
- Generates Lexi's replies. Your conversations are not used to train its models.
- Voice transcription, recorded
- Turns recorded voice messages into text, and powers memory search.
- Voice transcription, live
- Turns live voice into text. Nothing kept beyond the request.
- Voice
- Gives Lexi her voice. Only her reply text is sent.
- Hosting
- Runs the service and its database.
- Photo storage
- Stores progress photos, encrypted.
- Sends account emails.
- Crash reporting
- Helps us fix bugs. Set up not to receive your messages, health data or passwords.
- Website hosting
- Serves meetlexi.ai and keeps request logs briefly. The app does not use it.
- Beta application storage
- Holds beta applications sent from this website. Separate from the app's own database.
How long we keep it
Clear periods, in plain words.
Each one is a commitment in our privacy policy, set to honor the rights that state health privacy laws give you.
- While your account is active
- Kept.
- Delete your account
- Gone from view at once, erased within 30 days.
- Inactive for two years
- We tell you first, then erase 30 days later.
- Voice audio
- Never kept.
- Progress photos
- Yours to delete one at a time.
- Security logs
- One year.
- Usage records
- Which services ran and what they cost, never your messages: detailed for 90 days, then monthly totals.
How we protect it
Security, in plain words too.
- Encrypted in transit
- Everything between your phone and Lexi travels over TLS 1.2 or higher.
- Encrypted at rest
- The database is encrypted where it is stored, and progress photos are encrypted with AES-256.
- Sessions you control
- Sign-in sessions expire quickly and can be revoked from our side at any time.
- Guarded at every door
- Every signed-in request is rate limited, and every database query is parameterized.
- Told within 72 hours
- If a breach is ever confirmed, affected members hear from us within 72 hours.
- Built private from day one
- Voice audio is never stored. Apple Health is read-only. Crash reports are set up never to receive your messages or health data.
Consent comes first
Your rights
Your rights, wherever you live.
Some states write strong privacy rights into law. We give every member the same rights, whichever state you live in. See it, correct it, export it or delete it: emailprivacy@meetlexi.ai and we answer within 30 days.
- Washington
- My Health My Data Act: confirm, access, delete and withdraw consent for your health data.
- Illinois
- Biometric Information Privacy Act: separate written consent before any biometric data is collected.
- California
- Know, delete, correct and opt out. We don't sell your data.
- Texas
- Your rights over biometric identifiers under state law.
- Connecticut, Colorado, Virginia, Utah
- Access, correct, delete and take your data with you.