Lexware Pty Ltd (ABN 32 698 115 463) (“Lexware”, “we”, “us”) · Brisbane, Australia · Last updated: 24 July 2026
How this page relates to the others. This is the formal APP policy for personal information Lexware holds about people. How Lexware handles your data is the plain-language product explainer for matter content inside the app. Security & architecture explains the local-first design. If you are a beta tester, the beta program privacy policy also applies to that program; where both speak to the same point, this policy and the beta policy should be read together.
1. About this policy
This policy is published to meet APP 1.3: it is clearly expressed, up to date, and free to access. It explains, in relation to personal information:
- the kinds of information we collect and hold;
- how we collect and hold it;
- the purposes for which we collect, hold, use and disclose it;
- how you may access and seek correction of it;
- how you may complain about a breach of the APPs, and how we will deal with that complaint; and
- whether we are likely to disclose personal information to overseas recipients, and if practicable the countries.
Lexware Pty Ltd currently falls within the Privacy Act’s small business exemption. We nonetheless handle personal information in line with the Australian Privacy Principles as a matter of practice, and this policy is written on that basis.
2. Who we are
Lexware is a local-first litigation workspace for barristers, published by Lexware Pty Ltd, an Australian company based in Brisbane, Queensland. Contact details for privacy requests are in section 12.
3. Matter content is not personal information we collect
Lexware is a desktop application. Documents, matters, chronologies, pleadings analysis, notes and related work product live in local files and a local database on your machine. We do not operate a server that receives or stores matter content, and we do not use the application to collect telemetry or analytics about what you open or how you work.
That is not an absolute claim that “nothing ever leaves the machine.” Two carve-outs apply, and both are exact:
- (a) Per-matter cloud AI (opt-in). If you enable cloud AI for a particular matter, the application may send only the matter content you have consented to send for that request to the AI provider you have chosen (for example Claude or OpenAI’s ChatGPT, through that provider’s own tool on your own subscription). That content goes from your device to that provider; Lexware does not receive it and does not hold an API key for the provider. These features are off for every matter until you switch them on. Details are on the product privacy page and the security page.
- (b) Licence check and billing records. When a paid subscription is active, the application’s licence check transmits only an opaque subscription identifier to our licence service — not matter content, document names, or usage analytics. Separately and necessarily, our billing / licence Worker holds the subscriber’s Stripe contact details for billing and licence administration (see section 5).
We are not the collector or holder of your clients’ or other parties’ matter information for Privacy Act purposes. You (or your instructing solicitors) remain its custodian; your professional obligations in respect of it are unaffected.
4. Kinds of personal information we collect and hold
Depending on how you deal with us, we may collect and hold:
4.1 Website visitors (lexware.ai)
- Server and security logs — when you visit this website, our host (Cloudflare) automatically processes standard technical request data such as IP address, date and time, requested URL, referrer, user-agent, and similar connection metadata. That processing is part of hosting, security, abuse prevention and reliability.
- Bot-challenge / edge security data — Cloudflare may apply automated bot-management or challenge mechanisms and process related technical signals to distinguish legitimate traffic from abusive traffic. We do not run client-side analytics, advertising pixels, or tracking scripts on this site (the site’s Content-Security-Policy is
script-src 'none'for page scripts). - Messages you send us — if you email us (for example via a mailto link on the site), we receive the content of that correspondence and your email address.
We do not use first-party tracking cookies for advertising or product analytics on this website. Security or operational cookies set by Cloudflare as part of hosting or bot management may still be involved at the edge under Cloudflare’s own terms.
4.2 Beta testers and programme participants
- Contact and professional details — name, email address, chambers or firm, and role, when you join or request access to the beta.
- Feedback and support correspondence — bug reports, feature requests, emails, and any screenshots or files you choose to attach.
- Distribution and update technical records — requests to download a build or check for updates may include app version, operating system and IP address, processed by our website host (Cloudflare) and, where applicable, by distribution providers (for example GitHub for release assets, or Dropbox for certain shared links) under their own privacy policies.
Further detail for the short-run beta is also set out in the beta program privacy policy.
4.3 Trial, download and marketing contacts
Where we operate an email-gated download or trial funnel, we may collect and hold:
- email address;
- timestamps of request, download or related events;
- EULA or terms version and record of assent; and
- unsubscribe / marketing preference state.
Those records are held so we can provide the download, record acceptance of terms, and send the related product emails you would reasonably expect (with an unsubscribe path for commercial electronic messages, consistent with the Spam Act 2003 (Cth)).
4.4 Subscribers, billing and licence data
When you purchase or manage a subscription:
- Stripe processes payment and billing details as our payment processor. Lexware Pty Ltd is the merchant of record. Stripe typically holds information such as name, email, billing address, payment method details, and transaction history under Stripe’s own privacy policy. Lexware does not store full card numbers.
- Our billing / licence Worker necessarily holds subscriber contact and licence-administration data derived from Stripe (for example name, email, subscription status, plan, period dates, and the opaque licence / subscription identifier) so we can issue, renew, revoke and support licences and issue related notices.
- The application’s licence check sends only that opaque subscription identifier to the licence service. It does not send matter content.
4.5 Support and security reports
If you contact support or report a security concern, we collect the information you provide in that correspondence. Please do not include client documents, privileged material, or confidential matter information in reports or attachments unless we have expressly arranged a secure process for a specific investigation.
5. How we collect personal information
We collect personal information:
- directly from you — for example when you request beta access, download software, subscribe, email us, or send feedback;
- automatically — technical logs and security data when you use the website or download endpoints, via our host and related infrastructure; and
- from service providers acting for us — notably Stripe, which provides subscriber and payment status information to our billing / licence Worker so we can operate licences.
We do not buy marketing lists of barristers for cold outreach as a substitute for the contacts above.
6. Purposes of collection, use and disclosure
We collect, hold, use and disclose personal information only for purposes that are reasonably necessary for our functions and activities, including to:
- operate, secure and improve the website and download infrastructure;
- administer the beta programme and commercial subscriptions (access, licences, updates, billing, renewals, cancellations and related notices);
- provide support and respond to feedback or security reports;
- send product-related communications you would reasonably expect (and marketing only where permitted, with an unsubscribe mechanism where the Spam Act applies);
- comply with law, enforce our terms, and protect our rights, users and systems; and
- keep internal business records (for example accounting and tax records associated with subscriptions).
We do not sell personal information. We do not use personal information for third-party advertising.
7. Who we disclose personal information to
We may disclose personal information to:
- Cloudflare — website hosting, DNS, edge security, and (for licence/billing infrastructure) Worker compute and related storage;
- Stripe — payment processing and subscription billing;
- email and communications providers we use to send transactional or permitted product email;
- distribution or repository providers involved in shipping builds or release metadata (for example GitHub for release assets);
- professional advisers (for example accountants or lawyers) where reasonably necessary; and
- regulators, courts or law-enforcement bodies where required or authorised by law.
Service providers act on our instructions or under their own terms as independent controllers for some processing (for example Stripe for payment data). We take reasonable steps appropriate to the circumstances so that personal information we disclose is handled consistently with this policy.
8. Overseas disclosure
Some of our service providers store or process data outside Australia, including in the United States (for example Cloudflare, Stripe, and common email or repository providers). When we disclose personal information to an overseas recipient, we take reasonable steps in the circumstances so that the recipient does not breach the APPs in relation to that information (APP 8), subject to the exceptions in the Privacy Act.
9. How we hold and secure personal information
We take reasonable steps to protect personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include, as applicable:
- encryption in transit (HTTPS) for the website and licence service;
- access limited to people who need it to run the business;
- secrets and signing keys stored in controlled secret stores rather than in application source; and
- vendor selection appropriate to a small, high-trust professional product.
No method of transmission or storage is perfectly secure. The architecture of the product is designed so that matter content is not among the personal information we hold on servers — see section 3 and the security page.
10. Retention and destruction
We keep personal information only as long as we need it for the purposes above, or as required for legal, accounting or dispute-resolution reasons. When it is no longer needed, we take reasonable steps to destroy or de-identify it. Matter files on your device are under your control; uninstalling the app or deleting local data is something you do on your machine.
11. Access, correction and complaints
You may request access to the personal information we hold about you, or ask us to correct it, by emailing support@lexware.ai. We will respond within a reasonable period (and in any event within 30 days). We may need to verify your identity. In limited cases the Privacy Act permits us to refuse access or correction; if we do, we will explain why (unless we are not required to) and how you can complain.
If you believe we have breached the APPs or this policy, contact us at the same address. We will acknowledge the complaint, investigate, and tell you the outcome. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
12. Contact
Lexware Pty Ltd (ABN 32 698 115 463)
Brisbane, Australia
Privacy and support: support@lexware.ai
General: hello@lexware.ai
13. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page and, where appropriate, notified by email to people we hold an address for (for example active subscribers or beta participants).
Related pages: How Lexware handles your data (product explainer) · Security & architecture · Beta program privacy policy
Request beta access How Lexware handles your data Security & architecture