Privacy
What we hold, and what we do with it.
This describes how LEXICERA LLC handles information in the Lexicera platform. It is written to be read rather than to be survived, and where the honest answer is narrower than the reassuring one, the narrow answer is the one printed here.
Effective 14 September 2026.
Who we are
The entity behind this
LEXICERA LLC, 153 Tate Lane, Saint Johns, FL 32259. Questions about anything on this page reach a person at brad@lexicera.com.
Lexicera is a practice platform for litigation firms. A firm is our customer; that firm's clients are the firm's, not ours. Where this page says your, it means the firm — and where a firm's own client is meant, it says so.
The arrangement
Whose information this is
Two different things live in this platform and they are governed differently.
The firm's account. Names, work email addresses and roles of the people at the firm who use it; sign-in and second-factor records; billing details; what each person did and when. This is ours to hold as the operator of the service, and this page describes it.
The firm's case files. Documents, parties, deadlines, notes, and the firm's own clients' details. That material belongs to the firm and is handled on the firm's instructions. We process it in order to run the service the firm bought, and for nothing else — it is not sold, not rented, not used to market anything, and not pooled with any other firm's material to improve a product. There is no shared corpus that a matter quietly feeds.
Documents
How a case file is stored
Every document gets its own encryption key, wrapped by the firm's master key. The ciphertext goes to the firm's own bucket at our storage vendor, which holds bytes it cannot read; the master key sits on our server, root-owned, and is escrowed offline. A checksum of the original is recorded on arrival and verified on every download.
The narrower truth, stated here rather than left for an assessor to find: pulling text out of a document requires the document, so extraction writes a decrypted copy to a scratch directory readable only by the service account and deletes it when the extraction finishes. Database rows — extracted text, matter titles, party names, filenames, the audit trail — are ordinary rows and are not separately encrypted. The security page carries the rest of that list, at the same weight as the good news.
Artificial intelligence
What is sent to a model, and what comes back
Document text is sent to a commercial model API to do the reading, drafting and analysis the platform is for. It goes under terms that do not permit training on what is sent, and there is no training pipeline in this software — nothing collects, exports or retains a firm's material for model improvement. A document can be marked AI-excluded, after which it is never sent to a model at all.
Anything a model produces carries a review-required status until an attorney marks it reviewed. That is a platform ceiling rather than a setting.
Payments
Card and bank details
Bills are paid through a third-party payment processor. Card numbers and bank credentials are entered on the processor's own hosted pages and are held by the processor; what reaches us is the outcome of a payment and a token that stands in for the instrument. We hold no client trust funds of any kind, and the firm is always the merchant of record for its own clients' payments.
Text messages
The invoice texts, in detail
LEXICERA sends two kinds of text message and no others, and LEXICERA is the sender of both: every message begins "LEXICERA:" and comes from LEXICERA's own number. The first is a notice that a law firm billing through LEXICERA has issued an invoice to the recipient, carrying the secure link to view and pay it. The second is a one-off confirmation, the first text a number receives after its holder opts in, which says who is texting and why, that frequency varies, that message and data rates may apply, and how to stop or get help. Both are transactional. There is no marketing programme, no newsletter and no promotional send, and none is planned. The messaging programme page carries both messages word for word.
Who is texted, and on whose say-so
Only a person who has opted in, themselves, on a LEXICERA page. There are three such places: the client portal; an optional section on the page where an engagement letter is signed, which is separate from the letter and not needed to sign it; and an optional card on an invoice payment page. Each shows a box nobody has pre-ticked beside a sentence naming LEXICERA as the sender and carrying the disclosures below. Ticking it records the number, that exact sentence, the time and the IP address. A mobile number that is merely in a firm's records is never texted, and neither the firm nor anyone at LEXICERA can opt a client in on the client's behalf. We buy no numbers, rent none and import none.
Texting must also be switched on for the firm. It is off until the firm asks, and it is switched on by us, for that firm — there is no self-service control. That is a precondition and not consent: a firm with texting switched on still cannot cause a text to any client who has not opted in. A client who no longer wants the texts can reply STOP, or ask the firm to take the number off their record.
What the message says
"LEXICERA:", the name of the firm that issued the invoice, the invoice number, the link, and then the sentence Reply STOP to opt out. — which every message the platform composes carries, so no send of any kind can go out without it. The amount is deliberately absent: the sum is on the invoice behind the link, and a text naming a figure would put a client's bill on a lock screen.
Stopping them
Replying STOP ends the messages. The suppression is enforced by the messaging carrier at the profile the number sends from, so it takes effect against the number itself and does not depend on us processing anything. HELP and START are answered the same way, by the messaging platform. This number is outbound only — there is nobody reading replies at our end, which is exactly why the keywords are handled where they are. To reach a person, use the firm's own contact details or the address at the foot of this page.
We additionally read the carrier's opt-out list and record it against the client, so a client who has replied STOP is never queued for a message at all rather than having one attempted and refused. That record mirrors the carrier's list and never overrides it: it clears when the carrier's does, which is when the recipient texts START or UNSTOP. Neither the firm nor anyone here can clear it by hand.
Frequency, and cost
Message frequency varies: a text goes out when a firm issues an invoice to that client, so it follows the firm's billing activity and nothing else. Payment reminders are not texted at all — only the first notice for an invoice can be. The confirmation above is sent once to a number, before the first invoice text about that firm. Message and data rates may apply, from the recipient's own mobile carrier.
Where the numbers go
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. A mobile number is passed to our messaging carrier for the sole purpose of delivering the message described above, and to nobody else for any purpose. It is not sold, not licensed, not traded, and not used to build any audience, segment or list.
Vendors
Who processes information on our behalf
The complete list, rather than a representative sample. Each is bound to process only what is needed to provide its part of the service.
| Vendor | What it handles |
|---|---|
| Payment processor | Payment instruments and payment processing. Card and bank details are entered on the processor's hosted pages, never on ours. |
| Telnyx | Delivery of the invoice text messages, and the STOP handling described above. |
| SMTP2GO | Delivery of transactional email — invoices, notices, sign-in mail. |
| Cloudflare R2 | Encrypted document storage. What it holds is ciphertext. |
| Linode | The server the application and its database run on. |
| Anthropic | The model API that does the reading and drafting, under terms that do not permit training on what is sent. |
Everything runs in the United States.
Time
How long things are kept
A firm's case material is kept for as long as the firm keeps its account, because deciding when a client file may be destroyed is the firm's professional judgment and not a default we are entitled to set. On closing an account a firm takes a complete export, and the material is then deleted from live storage.
Two things are kept deliberately longer, and both are stated here because they are the exceptions. The audit trail is append-only and cannot be edited or deleted, by anyone, including us — that is enforced by the database rather than by policy, and it is the whole point of having one. Billing and messaging records — what was charged, what was sent, when, and whether it was delivered — are kept as long as tax and carrier-compliance obligations require, which is what lets us answer a question about a message a year after it went out.
Your part
Asking us about your information
A person at a firm using Lexicera can ask what account information we hold about them, ask for it to be corrected, or ask for it to be deleted when they leave — subject to the audit trail above, which is immutable by design and which we will explain rather than quietly work around.
Requests about a firm's client's information go to the firm, not to us. The firm decides what its file contains and what happens to it; we hold it on the firm's instructions and will help the firm act, but the instruction has to come from the firm.
If we ever change this page in a way that matters, the effective date at the top changes with it and firms are told before it takes effect.
Contact
Reaching a person
LEXICERA LLC, 153 Tate Lane, Saint Johns, FL 32259 — brad@lexicera.com. There is one person on the other end of that address and you will hear back from him.