LexScan — Privacy Policy
Last updated: February 19, 2026
ARKA Systems (“we”, “our”, “us”) operates the LexScan mobile application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use LexScan.
1. Information We Collect
1.1 Information You Provide
When you use LexScan, you may provide:
- •Apple Sign-In credentials — Your name and email address (only if you choose to sign in). Apple may provide a private relay email address.
- •Document content — Text extracted from legal documents you scan or import for analysis.
- •Feedback — Clause accuracy ratings or suggestions you voluntarily submit.
1.2 Information Collected Automatically
- •Usage data — Number of scans performed, subscription status, and app preferences (stored locally on your device).
- •Transaction data — Apple processes and manages all in-app purchase transactions. We receive only confirmation of your subscription status.
- •Diagnostic data — We do not collect crash reports, analytics, or device identifiers.
1.3 Information We Do NOT Collect
- •Location data
- •Contacts, calendar, or health data
- •Browsing history
- •Device advertising identifiers (IDFA)
- •Biometric data (Face ID is processed entirely on your device by Apple)
2. How We Use Your Information
- •Document analysis — We transmit extracted document text to our secure backend server, which forwards it to third-party AI services (Anthropic Claude and OpenAI) for legal analysis. See Section 5 for AI data practices.
- •Account management — To authenticate your identity if you sign in with Apple.
- •Service improvement — Aggregated, de-identified feedback may be used to improve analysis accuracy.
- •Subscription fulfillment — To verify your subscription status and provide appropriate feature access.
3. Data Storage and Security
- •Local storage — Documents, analysis results, and preferences are stored on your device using Apple's SwiftData framework with iOS file protection (Complete Unless Open).
- •iCloud sync — If you are a Pro subscriber and have iCloud enabled, your data may sync across your devices via Apple's CloudKit (encrypted in transit and at rest by Apple).
- •Server processing — Document text is transmitted to our backend over TLS 1.3 encryption. Our servers do not persistently store your document text — it is processed in memory and discarded after the analysis response is returned.
- •Biometric protection — You may optionally enable Face ID or device passcode lock. Biometric evaluation occurs entirely on your device via Apple's LocalAuthentication framework.
4. Third-Party Services
We use the following third-party services to provide document analysis:
- •Anthropic (Claude) — Primary AI model for document analysis. Anthropic's API usage policy states that data sent via their API is not used to train their models.
- •OpenAI (GPT-4o) — Fallback AI model. OpenAI's API data usage policy states that data submitted via the API is not used for model training.
- •OpenRouter — API routing service that directs requests to the appropriate AI provider.
- •Apple — Sign In with Apple, In-App Purchases, iCloud sync, and push notifications.
- •Vercel — Cloud hosting for our backend server.
We do not use any advertising networks, analytics SDKs, or tracking services.
5. AI Data Disclosure
When you scan or import a document, the extracted text is sent to AI language models for analysis. Important details:
- •Only the text content is sent — never images, thumbnails, or metadata.
- •Document text is not persistently stored on our servers.
- •AI providers (Anthropic, OpenAI) do not use API-submitted data to train their models.
- •AI-generated analysis may contain errors. It does not constitute legal advice.
- •You can delete all locally stored documents and analyses at any time from Settings.
6. Data Retention
- •On device — Documents and analyses remain on your device until you delete them or uninstall the app.
- •On our servers — Document text is not retained after processing. Server logs may retain anonymized request metadata (timestamps, response codes) for up to 30 days.
- •Account data — If you sign in with Apple, your user ID is retained until you delete your account.
7. Your Rights
You have the right to:
- •Access your data — Use the “Export All Data” feature in Settings.
- •Delete your data — Use “Delete All Documents” or “Delete Account” in Settings.
- •Opt out of data processing — You may use the app without signing in. You may decline AI processing by not scanning documents.
- •Portability — Export your data in JSON format at any time.
For California residents (CCPA): We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
For EU/EEA residents (GDPR): Our legal basis for processing is your explicit consent when you initiate a document scan.
8. Children's Privacy
LexScan is not intended for children under 17. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the “Last Updated” date and, where appropriate, providing in-app notice.
10. Contact Us
If you have questions about this Privacy Policy, contact us at:
ARKA Systems
support@arka-ai.com