Privacy Policy
Last updated: June 2, 2026 Effective date: June 2, 2026
This Privacy Policy explains how Leo Yang ("we," "us," or "LexSee"), an individual sole proprietor based in Nashville, Tennessee, USA, collects, uses, and shares information in connection with the LexSee mobile application and related services (the "Service"). By using the Service, you agree to the terms of this Privacy Policy.
If you do not agree with this Privacy Policy, please do not use the Service.
1. Information We Collect
We collect information in the following categories:
1.1 Information you provide directly
- Account information. When you create an account, we collect your email address, a display name you choose, your selected native language, your timezone, and an avatar image (either chosen color or photo you upload).
- Onboarding preferences. Your daily learning pace, mastery interval, growth style (stability or exam mode), and any wordlist you select.
- Words you collect. Each word you save, along with the hero image you chose, AI-generated phonetics, definitions, and any personal notes.
- Reviews and ratings. Your spaced-repetition review history (which words you rated easy / good / hard / forgot, when).
- Image uploads. When you upload a custom photo to the community image gallery, we store the image file along with the word it represents and your display name as the uploader.
- Votes. Which images you have selected for which words.
- Contact form messages. If you reach out via the in-app Contact form, we collect the contents of your message, the category you selected, and optionally your name and reply-to email.
1.2 Information collected automatically
- Device identifiers. When you enable push notifications, we receive an Expo Push token tied to your device. We do not collect IDFA or advertising identifiers.
- Usage data. Basic engagement signals (when you collect a word, when you complete a review session) so the algorithm can pace your learning. We do not use third-party analytics SDKs at this time.
- Crash and diagnostic logs. Server-side error logs to investigate bugs. These do not include the contents of your collected words.
1.3 Information from third parties
- OAuth sign-in providers. If you sign in with Google or Apple, we receive your name and email from those providers. We do not receive any other profile data and we do not post anything on your behalf.
We do not knowingly collect any other information.
2. How We Use Your Information
We use the information we collect to:
- Provide the core learning experience: scheduling reviews, generating definitions, looking up pronunciations, surfacing word images.
- Send you push notifications about reviews due and new words to collect (only if you opt in during onboarding or in Settings — you can revoke at any time).
- Allow you to participate in the community image gallery (uploads, votes).
- Respond to your contact form messages.
- Detect, prevent, and address technical issues, abuse, or fraud.
- Comply with legal obligations.
We do not sell your personal information. We do not use your data to train third-party AI models.
3. Third-Party Services We Use
The Service relies on the following third-party processors. Each processes data only as needed to provide their function and is bound by their own privacy practices:
| Provider | Purpose | Data shared |
|---|---|---|
| Amazon Web Services (AWS) | Hosting (Cognito for auth, DynamoDB for storage, S3 for images, Lambda for serverless functions). All data resides in the US-East region. | Account info, collected words, reviews, uploaded images. |
| OpenAI | Text-to-speech for word pronunciations, AI-generated definitions for words outside our bundled dictionary, translation of definitions into your native language. | The single word or short phrase being looked up. We do not send your account identity. |
| DeepSeek | AI-generated definitions for words outside our bundled dictionary (alternative provider used for some lookups). | The single word being looked up. |
| Serper | Image search results when you collect a new word and pick a hero image. | The single word being searched. |
| Expo (Push Notifications) | Delivery of push notifications via Apple Push Notification service and Firebase Cloud Messaging. | Your device's push token and the notification payload. |
| Resend | Delivering the contact-form messages you send to us via the in-app Contact page. | The message you wrote and your reply-to email if you provided one. |
| RevenueCat (planned, not yet enabled) | Managing in-app subscriptions and entitlements. | Your account identifier and subscription status. Apple processes the actual payment. |
| Apple App Store / Google Play | Processing in-app subscriptions. | Apple/Google receive your payment details directly; we never see your card number. |
We do not share your information with any other third parties for their independent use.
4. How Long We Keep Your Information
- Account data. For as long as your account is active. If you delete your account, we delete all associated data within 30 days, except where retention is required by law.
- Reviews. Retained for the lifetime of the card. If you delete a word, the review log for that card is also deleted.
- Image uploads. Retained until you delete them. Images you upload to the community gallery may continue to appear for other users who selected your image, with your display name credit, even if you delete your account — you may request manual takedown via the contact below.
- Contact form messages. Retained for up to 12 months for support continuity, then deleted.
- Server logs. Up to 90 days, then rotated out.
5. Your Choices and Rights
You can:
- Edit your profile at any time via Settings → Identity.
- Disable notifications in Settings → Region or directly in iOS Settings → Notifications → LexSee.
- Delete a collected word by long-pressing it in the Inventory.
- Delete an uploaded image from the My Uploads tab in the Image Gallery.
- Delete your entire account by tapping Settings → Identity → Delete account. All associated data is removed within 30 days.
If you are a resident of the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, or the California Consumer Privacy Act (CCPA), including:
- The right to access a copy of the personal data we hold about you.
- The right to correct inaccurate data.
- The right to delete your data ("right to be forgotten").
- The right to data portability (we will export your data in a machine-readable format on request).
- The right to object to or restrict certain processing.
- The right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at the email below. We will respond within 30 days.
6. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it.
The Service is rated 4+ in the App Store. Users under 17 should obtain parental consent before creating an account.
7. International Users
We are based in the United States, and the data we collect is processed and stored in the United States (specifically, AWS US-East). If you access the Service from outside the U.S., you understand and agree that your information will be transferred to, stored in, and processed in the United States, which may have data protection laws different from those in your country.
For users in the European Economic Area or the United Kingdom, we rely on the Standard Contractual Clauses approved by the European Commission as the legal basis for these international transfers.
8. Security
We use industry-standard safeguards to protect your information:
- Encryption in transit. All connections to our backend use HTTPS / TLS.
- Encryption at rest. DynamoDB and S3 storage are encrypted by AWS.
- Authentication. Sessions use AWS Cognito's authenticated token flow; passwords are hashed.
- Access control. Our team and the admin dashboard use IAM-controlled access. No personal data is exposed publicly.
That said, no system is 100% secure. If we become aware of a security incident affecting your data, we will notify you within 72 hours where required by law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated policy here with a new "Last updated" date. If the changes are material (for example, a new category of data we collect, or a new third-party processor), we will notify you in-app the next time you open LexSee.
Continued use of the Service after a policy update constitutes acceptance of the updated policy.
10. Contact Us
For any questions about this Privacy Policy, to exercise your rights under it, or to report a privacy concern, contact us at:
Email: <TODO: insert dedicated legal/privacy email — e.g. privacy@lexsee.app or your designated Gmail>
In-app: open the Contact form via Settings → Contact, category "Privacy."
Postal address (on request): Nashville, Tennessee, USA. Send your privacy request via email first; we will share a postal address if required for a formal request.
LexSee is operated by Leo Yang as a sole proprietor based in Nashville, Tennessee.
© LexSee. Contact support@lexsee.app.