Data & privacy

How Lexware handles your data.

Lexware is built for privileged work. The short version: your matters live on your machine, there is no Lexware server, and the only ways any matter content can reach a cloud are things you switch on yourself. Here is the long version, in plain language.

The one-liner: matter content stays on this machine by default. The two precise carve-outs are opt-in per-matter cloud AI (only the consented text for that request) and the licence check (opaque subscription id only). Billing contact details for a paid subscription are held separately by Stripe and our billing Worker — never your briefs. See the Privacy policy for personal information about you as a visitor, tester or customer.

No Lexware server holds your matters

Lexware is a desktop application, not a web service. There is no account to create, no sign-in to your matters, no cloud backend that holds your data. Everything a matter is made of — the documents, the text extracted from them, the chronology, the pleadings analysis, your excerpts and notes — lives in a local database on your own machine, under your user account.

We don't collect telemetry. We don't run analytics. The application doesn't phone home to tell us what you opened or how you used it. We have no way to see your matters, because they are never sent to us.

Two housekeeping connections are worth naming, and neither is about your matters. Lexware checks our release feed over HTTPS to see whether a newer version exists. And if you activate a paid subscription once the beta ends, it confirms the subscription is current by checking in with our licence service when it starts and about once a day while you're online — that request carries only an opaque subscription identifier, over an encrypted connection, and none of your matters, their content, or anything about what you opened or how you worked. Separately, Stripe and our billing Worker hold the subscriber contact details needed for billing and licence administration — name and email, subscription status and period dates — not matter content. During the beta, Lexware is free, so the subscription check doesn't run at all. The full list of what can and cannot leave your machine is on the security page.

Your originals are never altered

When you point Lexware at a brief folder, it indexes the files in place and read-only — it never moves, renames or rewrites your source documents. Importing an eBrief ZIP or a compiled court book unpacks a working copy into Lexware's own folder (or a destination you choose); your delivered brief is left exactly as it arrived.

The two cloud features — and they're both off by default

Lexware can do everything in its core loop without sending a single byte of a matter anywhere. There are exactly two optional features that can transmit matter content to a third party, each separate, each opt-in:

1. Cloud AI for extraction & review (Claude or OpenAI's ChatGPT)

By default, Lexware extracts dates using a model that runs entirely on your machine — nothing is sent anywhere. For higher accuracy you can instead choose a cloud provider in Settings — Claude or OpenAI's ChatGPT — each run through that provider's own command-line tool on your own subscription, so Lexware never holds an API key. It's a deliberate, opt-in choice, and the local engine stays the default.

Crucially, cloud extraction is gated per matter: it transmits a document's text only for a matter you have explicitly switched cloud AI on for — the same per-matter consent the assistant uses (see below). No text leaves your machine for a matter you haven't enabled it on, and the AI assistant on the Review screen runs through that same consent. For privileged work, leave a matter local unless you specifically intend its text to go to a cloud provider.

2. The drafting assistant

The optional drafting assistant is a separate, per-matter integration. When it hands work to a cloud provider — Claude or OpenAI's ChatGPT, on your own subscription, as with extraction — it is off for every matter until you explicitly enable it for the matter you want it on. While it's off, no assistant text goes to a cloud provider; the feature only prepares local files. The assistant can alternatively run on a local model through Ollama on your own device, which keeps the work on the machine.

Consent is re-checked between chunks of work, so turning it off stops the next step rather than killing a request already in flight — cancel an active job if you need transmission to stop immediately. Every prompt sent is stored verbatim on the matter as your own audit record.

Before anything is sent: pseudonymisation

When you do use one of those cloud paths, Lexware can replace identifying details with placeholder tags before the text leaves your machine, and restore the real details locally from the reply. Masking is a per-matter setting. With it on, the identifiers recorded on the matter — its name and number, and the parties you've entered — are always swapped, together with pattern-matched details: emails, phone numbers, addresses, ABNs/ACNs and court file numbers; and on-device name detection, which runs entirely on your machine, widens this to names that appear only in the document text. Where that detection isn't available, a name nobody has recorded on the matter can still reach the provider. With masking off, the full text is sent — which Lexware warns you about, and shows you in full, before anything leaves.

It isn't applied to every cloud action, and it's an automated aid, not guaranteed anonymisation: always review the exact text shown before it's sent, and don't rely on it where complete anonymisation is required.

Both cloud features are independent and both are off until you turn them on. With them off, no matter content leaves your machine — anywhere, to anyone.

Why local-first matters for privileged work

For most software, keeping data on the device is a performance choice. For privileged legal work it is a professional one. The moment a brief — or any part of it — is sent to a third-party service, confidentiality and legal professional privilege rest on that provider's terms, retention settings and security, rather than on your own control of the material. Lexware's protection is structural, not contractual: by default there is no third party, because nothing is sent.

Australian bar associations and courts have published guidance on the use of generative AI in legal practice. The themes are consistent — preserve client confidentiality, guard against the loss or waiver of legal professional privilege when material is exposed to a third party, and remember that the practitioner remains responsible for their own work. That guidance is not limited to public AI chatbots; it extends to any software that sends matter content to a cloud service, including legal software with built-in AI features.

Lexware is built so you can meet those obligations by default. The core workflow — reading, highlighting, the chronology, the pleadings analysis and your notes — runs entirely on your machine and sends nothing. The two optional cloud features above stay off until you turn them on, act only on the text you direct to them, and can mask identifying details before anything leaves the machine. AI is something you switch on for a specific purpose — not a default you have to remember to switch off.

Nothing enters your chronology without you

This isn't a privacy point so much as a control one, but it's the same philosophy. Lexware never writes events to your chronology on its own. It proposes candidate dates; you review and confirm. (There are two deliberate, opt-in exceptions for confident dates — a per-matter auto-review setting, and an explicit choice you make each time you run date extraction — and every one is recorded in an audit log; but the default is that you decide what is true about your matter.)

Logs never contain document content

Lexware keeps a small local diagnostic log to help when something breaks. It records paths and event names only — never the content of your documents. Those paths can include file and folder names (which might carry a matter or party name), so if you ever send a log with a problem report, you can glance over it and redact first. Problem reports are never sent automatically: the in-app report opens a pre-filled email containing only the app version and your operating system version, which you send yourself.

Where your data lives

Your matters live in a single folder on your machine — on macOS, ~/Library/Application Support/Lexware/; on Windows, in your AppData folder under %APPDATA%\Lexware.

Lexware has a built-in Back up, in Settings: one click writes an encrypted snapshot — of a single matter, or of all your matters — to a local folder you choose, with nothing sent anywhere. It's a consistent snapshot, so you don't need to quit the app first, and it's encrypted at rest by default with a passphrase you set. Restore brings a snapshot back and never overwrites an existing matter — it restores as a copy. Backups are kept local: Lexware won't write one to a cloud target, and warns you if you point it at a cloud-synced folder like Dropbox.

Every backup is verified the moment it's made. As soon as the snapshot is written, Lexware reopens it with your passphrase and checks it end to end — the same check a restore runs — so a backup that couldn't actually be restored (a mistyped passphrase, a write that went wrong) fails plainly there and then, not months later when you reach for it. Settings keeps a list of every backup you've taken — its date, what it covered, size, whether it's encrypted and whether it verified — with a Verify again on each, and the backup reminder names the matter that has gone longest without a verified copy.

Because your matters are also just files on disk, you can copy that folder yourself if you'd rather. Either way, you remain in complete control of where your matter data is, who can reach it, and how it's retained or destroyed.

For the architecture behind all of this — how the app is put together, signed builds and updates, and exactly what can and cannot leave your machine — see Security & architecture.

This page describes how the software treats your matter content. The formal Privacy Act 1988 / Australian Privacy Principles policy — covering website-visitor data, beta-tester contact details, and billing / licence records held by Stripe and our billing Worker — is the Privacy policy. If you're a beta tester, the personal information we hold about you as a participant is also covered by the beta program privacy policy.


Request beta access