Overview
This Privacy Policy describes how Lexis OS (“Lexis”, “we”, “our”, or “us”) collects, uses, and shares information about you when you use our website (https://lexisos.com), our web application (https://app.lexisos.com), our Chrome extension, and any related services (collectively, the “Services”).
We built Lexis OS as an integrated sales-operations platform. That means we handle real, sensitive business information — CRM records, email conversations, calendar events, LinkedIn activity, and more. This policy tells you exactly what we do with it, how we secure it, and what rights you have over it.
Short version: we collect only what we need to run the Services you subscribe to, we don’t sell your data, we don’t train third-party AI models on it, and you can delete it whenever you want.
Who we are
Lexis OS is the data controller for information collected through the Services when we determine the purposes and means of processing (for example, our own operations, billing, and platform improvements). For customer-uploaded data and data we process on behalf of our business customers, Lexis OS acts as a data processor, and the customer is the data controller.
Contact for privacy inquiries: support@lexisos.com.
Data we collect
3.1 Information you give us directly
- Account data: name, email address, password (hashed with bcrypt), organization name, role, and profile photo.
- Billing data: billing contact, tax identifiers, invoice history. We do not store full payment card numbers — those are handled by our payment processor.
- Content you upload: Leads, Contacts, Companies, Deals, Pipelines, Custom Fields, Lists, Tags, Views, Templates, Workflows, Campaigns, Signals, Notes, Files (via WorkDrive), Scheduling pages, Event Types, Bookings, and any HTML or text you author inside the Services.
- Communications: support emails you send us, feedback you submit, and any transcripts of interactions with our team.
3.2 Information from your connected accounts
When you connect a third-party service to Lexis OS, we receive data from that service as authorized by you:
- Email & Calendar (Gmail, Microsoft 365, IMAP): mailbox metadata, message threads, message bodies, attachments, calendar events, attendees, and RSVP status — for the mailboxes and calendars you connect.
- CRM (Zoho, HubSpot): contacts, leads, accounts, deals, activities, custom field definitions, and pipeline configurations for the modules you sync.
- Conferencing (Zoom, Zoho Meet): your account email, user ID, and OAuth tokens used to create meetings when a booking is confirmed. We do not access recordings, chat, participants, or presence.
- Enrichment (Apollo and similar): contact and company records you retrieve through the enrichment provider on your behalf.
- LinkedIn (via our Chrome extension): profile data, connection lists, message threads, and search results that you explicitly retrieve while signed in to your own LinkedIn account. See section 16 for the full LinkedIn-specific disclosure.
3.3 Information collected automatically
- Device & browser data: IP address, user agent, browser type and version, operating system, and language settings.
- Usage data: pages viewed, features used, actions taken, timestamps, and referrer URLs. We use this to run the product, debug issues, and measure product quality.
- Cookies & local storage: session tokens, feature flags, and preferences. See section 12.
- Public booking pages: when someone books a meeting on your scheduling page, we record their name, email, timezone, chosen slot, form answers, UTM parameters, referrer, an anonymized IP hash, and a truncated user agent string.
3.4 Information from public sources
Where you or your teammates paste, upload, or link publicly available information (e.g. a LinkedIn URL) into the Services, we process it to fulfill the feature you invoked (e.g. importing a profile).
How we use data
- Provide the Services. Authenticate you, run workflows, sync calendars, send campaigns, deliver bookings, generate AI drafts, and everything else you asked us to do when you signed up.
- Secure the Services. Detect and prevent fraud, abuse, credential stuffing, spam, malware distribution, and other unauthorized activity.
- Support you. Respond to your requests, investigate incidents, and help you use the platform.
- Improve the Services. Understand which features are used, fix bugs, and measure performance. We use aggregated/anonymized usage data where feasible; where we need identified data, we minimize retention.
- Communicate with you. Send transactional emails (confirmations, alerts, invoices), respond to your questions, and — with your consent where required — occasionally share product news.
- Comply with the law. Enforce our terms, respond to lawful requests, and defend legal claims.
What we don’t do: we don’t sell your data, we don’t rent it, we don’t share it with data brokers, and we don’t use it to train third-party AI models.
Legal bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we process personal data under the following legal bases:
- Performance of a contract — most processing needed to operate the Services you subscribed to.
- Legitimate interests — securing the platform, preventing fraud, improving the product, and running our business, balanced against your rights and freedoms.
- Consent — where you opt in (for example, marketing emails or non-essential cookies).
- Legal obligation — where we must retain records to comply with tax, accounting, or lawful requests.
You can withdraw consent at any time. See section 13.
Third-party services (subprocessors)
We rely on carefully vetted third-party providers to operate the Services. Each subprocessor is bound by a written agreement that restricts their use of your data to the services they provide to us.
| Provider | Purpose | Data |
|---|---|---|
| Microsoft Azure / VPS host | Application hosting, database, storage | All processed data (encrypted at rest) |
| Google (Gmail, Calendar, Meet) | Email & calendar sync, video conferencing | OAuth tokens, mailbox, calendar |
| Microsoft (Graph, Teams) | Email & calendar sync, video conferencing | OAuth tokens, mailbox, calendar |
| Zoom | Meeting creation for scheduling | OAuth tokens, account email + user ID |
| Zoho (CRM, Meet) | CRM sync, video conferencing | OAuth tokens, CRM records |
| HubSpot | CRM sync | OAuth tokens, CRM records |
| Apollo (or similar enrichment) | Contact enrichment | Email/company lookups you initiate |
| Postmark (or SMTP provider) | Transactional email delivery | Recipient email, message content |
| Anthropic / OpenAI (per your org) | AI generation (drafts, summaries) | Prompts you submit |
| Pinecone (per your org) | Semantic search embeddings | Text embeddings you index |
| hCaptcha | Anti-abuse on public booking form | IP, challenge token |
| Payment processor | Billing and subscription | Billing contact, tokenized payment method |
This list may be updated from time to time. Material additions are announced at least 30 days before they take effect for customers with a data-processing addendum in place.
AI processing
Lexis OS uses large language models (LLMs) to generate email drafts, summaries, and workflow suggestions when you opt in to those features. We treat AI processing with the following commitments:
- No training on your data. Every LLM provider we use is bound by contract to a zero-retention or explicit no-training clause. Your prompts and completions are not used to train their models.
- Bring your own key. You can connect your own Anthropic or OpenAI account and route all AI calls through it — in that case, we act only as a pass-through and the data-handling agreement is between you and the provider.
- Human-in-the-loop by default. AI-generated content is drafted, not sent. A human reviewer approves outbound content before it leaves the platform on any workflow that dispatches messages to third parties.
- Local logging only. We may log AI request/response pairs for debugging for a short window. This is stored under the same encryption controls as the rest of your data and is not shared externally.
Google user data — Limited Use
When you connect a Google account (Gmail, Google Calendar) to Lexis OS, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8.1 What we access
- Gmail (
gmail.modify). When you connect a Gmail mailbox, we read message threads and metadata so you see them in your team inbox, send new emails and replies from your connected mailbox at your direction, and apply / remove labels so your Gmail folder taxonomy stays in sync. We do not permanently delete messages on your behalf. - Google Calendar (
calendar). When you connect a Google Calendar, we read events so they appear alongside your CRM records, and we create, update, or cancel events when you take those actions inside Lexis OS. We only touch calendars owned by the signed-in Google account. - Email address (
userinfo.email). We read your primary Google email address once during connection so we can identify which mailbox / calendar you authorized and display it in the UI.
8.2 How we use it (Limited Use)
Data obtained from Gmail and Google Calendar is used only to provide or improve user-facing features of Lexis OS that are prominently visible in the app. Specifically, we do not:
- Transfer Google user data to third parties, except (a) as necessary to provide the features you invoke (for example, storing the data securely with our hosting provider), (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets — in which case notice will be given.
- Use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- Allow humans to read your Google user data, except (a) with your affirmative agreement for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in a way that no individual message or user can be identified.
- Use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. We do not send Gmail message bodies or Calendar event contents to any third-party AI provider for training. AI features inside Lexis OS (draft generation, template drafting) operate on content you author, not on your inbox contents.
8.3 How we store and secure it
- OAuth refresh and access tokens for Google are encrypted at rest using AES-256-GCM envelope encryption, with a per-organization data-encryption key derived from a master key held only in our production environment.
- Traffic between Lexis OS and Google APIs is transported exclusively over TLS 1.2 or higher.
- Access to our production systems is restricted to a minimal engineering group under role-based access control, with mandatory MFA and audit logging for privileged operations.
8.4 How to revoke access
You can disconnect your Google account at any time from Settings → Mailboxes or Settings → Calendars inside Lexis OS. When you do, we immediately call Google’s token-revoke endpoint to invalidate the refresh token on Google’s side, and we delete the encrypted token from our systems. You can also revoke access directly from your Google account at myaccount.google.com/permissions. For content already synced into Lexis OS before you disconnected, follow the standard deletion process (section 10) to remove it from our systems.
Retention & deletion
- Customer content is kept for as long as your account is active. On termination, we retain it for up to 30 days to allow you to reactivate or export, then delete it within a further 30 days from primary systems and 90 days from backups.
- Booking pageviews are retained as raw records for 30 days, then rolled up into anonymized daily aggregates. Individual identifiers (hashed IPs, session IDs) are purged with the raw records.
- Email audit logs are retained for 90 days by default; enterprise plans can extend this.
- Billing records are retained for 7 years to comply with tax and accounting law.
- Backups are retained on rolling 35-day cycles.
You can also delete individual records (Leads, Contacts, etc.) at any time from within the product. Deletion is honored across primary systems within one business day.
International transfers
Lexis OS is operated from data centers in the United States (default region). If you are located outside the United States, your personal data will be transferred to and processed in the United States and other countries where our subprocessors operate.
Where required, we rely on Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent transfer mechanisms. Enterprise customers can request data residency in specific regions where feasible.
Security
- Encryption in transit via TLS 1.2 or higher on every network hop.
- Encryption at rest on the primary database and on encrypted-column secrets (OAuth tokens, cookies, API keys) via AES-256-GCM envelope encryption, with per-organization data-encryption keys derived from a master key held only in our production environment.
- Access controls. Role-based access to internal systems, MFA required for all engineering staff, and audit logs for privileged operations.
- Isolation. Every business table carries an
org_id; queries are scoped at the stored-procedure layer to prevent cross-tenant leakage. - Monitoring. Automated alerts on anomalous authentication, failed login patterns, and background job errors.
- Incident response. Documented playbooks, on-call rotation, and — where a personal-data breach is confirmed — notification to affected controllers within 72 hours.
No system is invulnerable. If you believe your account has been compromised, contact support@lexisos.com immediately.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (subject to legal retention requirements).
- Port your data in a common machine-readable format.
- Object to processing based on our legitimate interests.
- Restrict processing in certain circumstances.
- Withdraw consent where processing is based on consent.
- Complain to your local supervisory authority.
To exercise any of these rights, email us at support@lexisos.com from the address associated with your account. If you are a data subject whose data is being processed under a customer’s account (for example, a lead in a customer’s CRM), please contact that customer directly — they are the data controller for that data.
Children
Lexis OS is a business-to-business platform and is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it.
California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (as amended by the CPRA):
- The right to know the categories and specific pieces of personal information we collect.
- The right to delete personal information we have collected, subject to exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- The right to limit the use of sensitive personal information.
- The right to non-discrimination for exercising any of these rights.
Categories we collect (per CCPA taxonomy): identifiers, commercial information, internet or network activity, geolocation (approximate), professional information, and inferences drawn from the above. We do not use or disclose sensitive personal information beyond the purposes permitted by CPRA.
Companion extension & professional networks
The Lexis Chrome extension is an optional productivity companion that reflects information you’ve chosen to keep in your own signed-in browser sessions with third-party professional networks. It runs only inside your browser and only for pages you explicitly open. It does not observe activity outside those pages, and it does not act on your behalf against any third-party service’s policies.
- You are the actor. Any information the extension reflects into Lexis OS is information you already have access to as a signed-in user. You are responsible for complying with the applicable third-party network’s Terms of Service.
- Session cookies stay in your browser. Session cookies for third-party networks never leave your browser or reach our servers.
- Your data is yours. You can delete any imported record at any time. On account termination, all such records are deleted with the rest of your customer content.
- Uninstall in one click. The extension can be paused from the LexisOS UI and uninstalled from your browser at any moment, with no impact on the rest of your LexisOS account.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes (for example, a new category of data collection, a new subprocessor with a materially different data-handling profile, or a reduction in your rights) will be announced at least 30 days before they take effect for existing customers, via email to account admins and a notice on this page.
Non-material changes (clarifications, typos, or corrections) are made as needed and reflected in the “Last updated” date at the top of this page.
Contact us
Questions about this policy or how we handle your data? We’d rather hear from you than have you guess.