In one sentence: We do not receive or store matter content. Off-device AI and Companion access are both off until you enable them.
The relevant boundary
We do not host matter content. Your confidentiality therefore does not depend on us controlling a hosted copy of your brief.
Two optional network features can transmit matter content from the computer. Off-device AI sends material to the provider you choose after per-matter consent. Companion access sends matter material to a paired iPad and returns supported marks and selected-passage Scratchpad excerpts to the computer, directly over the local network while the setting is on. Neither path sends matter content to us. Files you export or place in a synchronised folder follow the destination you choose.
How Lexware is put together
For the technically minded — your IT consultant can verify each of these from the running app:
- One matter, one database. Each matter has its own SQLite database and associated files under your operating-system account. There is no remote Lexware copy.
- Documents are read locally. PDF rendering, text extraction, supported OCR and the built-in rule-based date pass run on the computer. A local Ollama model also runs there.
- The ordinary internal interface remains local. The desktop interface talks to a backend bound to
127.0.0.1on a random port. Requests require a secret token created for that launch. - Companion access is separate. When Allow iPad access is on, Lexware opens a separate, limited listener for paired devices. It does not expose the ordinary application interface.
- No sign-in to matters. A subscription licence unlocks the software; it is not an account that stores or synchronises matter content.
When Lexware transmits matter content
The app transmits matter content over a network only for an off-device AI run or a paired Companion connection. Update and licence connections use the internet but contain no matter content.
Cloud AI — off for every matter until you switch it on
Claude and ChatGPT always operate off-device. Ollama is local only when both its endpoint and selected model run on this computer; a remote endpoint or Ollama Cloud model is an off-device destination. Each off-device run requires per-matter consent.
Source text included with a request can use Identity masking. Prompt-only sends, Matter-tools instructions and retrieved passages, and complete-pleading AI extraction are unmasked. Lexware identifies the destination and the applicable disclosure before a run begins. We do not receive the prompt or response. The privacy page explains these paths in more detail.
Lexware Companion for iPad
Lexware Companion is the iPad app. Companion access is app-wide and off by default. While it is on, a paired iPad connects directly to the computer over the local network or the computer's hotspot. There is no cloud relay.
The connection uses TLS and a separate credential for each device. Pairing requires a single-use code that expires after five minutes. A paired device can be removed from Settings at any time.
The iPad app can access only the Companion functions described here; it cannot reach the desktop application's ordinary internal interface. It temporarily caches documents needed for reading and keeps protected local copies of marks, Apple Pencil drawings and changes waiting to reach the computer. Forgetting the computer in the iPad app deletes its document cache, mark copies, unsent changes and Pencil drawings. Removing the iPad in desktop Settings prevents future access but cannot remotely erase an offline device.
The update check
Lexware checks our release feed over HTTPS to learn whether a newer version exists. That request carries no matter content — and no update installs without your say-so (more below).
The licence check — only once you activate a subscription
Every new install starts with a two-month free trial of Pro, then becomes Free unless you subscribe. Until you activate a subscription, the app determines trial and Free access locally without contacting the licence service.
After activation, the app checks your subscription when it starts and about once a day while you're online. That check carries only an opaque subscription identifier, over an encrypted connection — its request includes none of your matters, their content, or anything about what you opened or how you worked. A signed licence cached on your computer lets paid features keep working offline until its validity expires, including the subscription's grace period.
Billing is separate from that check. Subscriptions are processed by Stripe, with Lexware Pty Ltd as the merchant of record. Our small billing / licence Worker necessarily holds the subscriber contact details Stripe provides for billing and licence administration — typically name and email, with subscription status and period dates — so we can issue and maintain the licence. That is billing data about you as a customer, not matter content. Card numbers are handled by Stripe under its own terms; we do not store full card details.
Problem reports — never automatic
Nothing is reported home when something goes wrong. The in-app "report a problem" simply opens a pre-filled email containing the app version and your operating system version; you read it and you send it, or you don't.
With off-device AI disabled and Lexware Companion access off, Lexware sends no matter content beyond the computer. Its update and, after activation, licence checks carry no matter content.
What we deliberately don't build
Some of the strongest security decisions are the features that don't exist:
- No telemetry or usage analytics. Lexware does not report what you open or how you work.
- No Lexware-hosted matter copy. There is no Lexware account or hosted store for your matters.
- No tracking SDKs. The app contains no advertising or usage-tracking software, and this website runs no analytics.
- No cloud backup selected for you. Backups go to a folder you choose, and Lexware warns if that folder appears to be cloud-synchronised.
- No iPad relay. The iPad connects directly to the computer while iPad access is on.
Diagnostic logs — paths and events, not content
Lexware keeps a small local log to help diagnose problems. It records file paths and event names, never the content of your documents. Because a path can include a file or folder name — which might carry a matter or party name — glance over a log and redact before you choose to send one with a problem report. Logs, like everything else, are never transmitted automatically.
Signed builds, verified updates
macOS builds are signed with Lexware Pty Ltd's Apple Developer ID and notarised by Apple. Windows installers are Authenticode-signed as LEXWARE PTY LTD.
Updates are delivered over HTTPS and must pass the updater signature check before installation. Lexware tells you when an update is available and waits for you to apply it.
Your data is yours — files on your disk
Matter data lives at ~/Library/Application Support/Lexware/ on macOS and %APPDATA%\Lexware\data\ on Windows. New brief imports — folders, eBrief ZIPs and compiled court books — place working copies in the matter's own storage and leave the delivered files unchanged.
Live matter files are not encrypted by Lexware itself. Their at-rest protection depends on the computer's user-account security and full-disk encryption: FileVault on macOS, or BitLocker, Windows Device Encryption or an equivalent control on Windows. Enable that protection on any computer holding privileged material, and keep the Lexware data folder out of cloud-synchronisation tools.
Lexware's built-in backup creates a verified snapshot of each selected matter's database and managed files, including its imported document copies. Encryption is on by default and can be turned off; when encrypted, the snapshot is protected by a passphrase you set. Older matters may still read documents indexed in their original folders. Those external files are not included in a Lexware backup; back them up separately unless you have brought them into Lexware.
You control where your matter data lives, who can reach it, and how it is retained or destroyed — the same way you control a paper brief in chambers.
What about SOC 2 and the like?
We do not hold SOC 2 or ISO 27001 certification. Those certifications would assess our systems, including billing and release operations; they would not change the fact that we do not receive or store matter content. For matter security, the relevant controls are the architecture described here, the security of your computer and iPad, and the terms and controls of any off-device AI provider you choose.
Reporting a security concern
If you find, or suspect, a security problem in Lexware or this website, write to support@lexware.ai — it reaches the developer directly, and security reports are read first. Please don't include privileged or client material in a report.
For how the product treats matter content in plain language, see How Lexware handles your data. For the formal Privacy Act 1988 / Australian Privacy Principles policy covering website visitors, beta testers, and billing data, see the Privacy policy.
Start free trial How Lexware handles your data Privacy policy