Privacy
Last updated: 15 September 2026
Lexo is built to do as little with your data as possible. This page explains what the Lexo iOS app collects, how it collects it, what it is used for, and who else receives it.
What stays on your device
- Your deck. Words, translations, example sentences, and review history are stored only on your device, in a database managed by iOS.
- App preferences. Language pairs, daily goal, reminder time, onboarding answers, and saved or hidden videos stay on your device.
- Reminders. Daily reminders are scheduled locally by iOS. No push notification service is involved.
- Voice and photos. Dictation uses Apple's Speech framework, which runs on your device whenever iOS supports it; otherwise Apple processes the audio under Apple's privacy policy. Scanning text from the camera or a photo uses Apple's Vision framework on your device. Lexo never uploads your recordings or photos. Only the text recognised from them is translated, and only if you choose to.
- Backups you choose to make. If you export a backup, the file goes wherever you send it. If you turn on iCloud backup in Settings, copies of your deck are saved to your own iCloud Drive, which Lexo's servers cannot access.
AI translation with Google Gemini
Lexo translates using the Gemini API, an AI service provided by Google. The app asks for your permission before it sends anything to Google, and explains what is sent and who receives it. You can allow or withdraw this at any time in Settings → Privacy → AI translation. If you don't allow it, translating and saving words from videos are turned off, and nothing is sent.
With your permission, the following is sent from the app to our server, which forwards it to the Gemini API:
- Text you translate, whether you type it, dictate it, scan it, or share it into Lexo from another app, together with the language pair.
- The subtitle line around a word you save from a video, so the translation matches how the word is used.
- Words you save and their meanings, so Lexo can write example sentences, and longer phrases you choose to break into cards, so they can be split.
Requests reach Google from our server, not from your device. Google receives the text and the language codes. It does not receive your IP address, your install ID, your Apple ID, your name, or your email address. Lexo uses Google's paid Gemini API service. Under the Gemini API Additional Terms of Service, Google does not use prompts or responses from paid services to improve its products, and keeps them only for a limited period to detect abuse and meet legal obligations. Google's handling is also covered by the Google Privacy Policy.
We use this data only to return translations, example sentences, and split phrases to you. To avoid sending the same text to Google twice, our server caches results for up to 30 days, stored under a one-way hash of the request. Cached results are stored without your install ID or IP address.
Other data sent to our server
Our server is a Cloudflare Worker that we operate. Besides the translation requests above, it receives:
- An install ID. The app creates a random identifier on first launch and keeps it in the iOS Keychain. It is not linked to your name or email. It is sent with requests so we can apply fair-use limits, measure the cost of running the service, and match a subscription to an install.
- Usage and cost records. For each translation, example, or split request, we record the install ID, which feature was used, the language pair, a one-way hash of the text, whether the result was cached, and how much the request cost. These records never contain the text itself. They are kept for up to three months.
- Onboarding and subscription events. The App Store version of Lexo sends a small set of events with your install ID: which onboarding pages were viewed or skipped, when onboarding finished, when the subscription screen was shown and from where, which plan was selected, and whether a purchase or trial started. They never include your words or translations. They are kept for up to three months and used to improve onboarding.
- Your IP address. Kept for up to 48 hours next to a daily character count, to enforce a fair-use limit, then deleted automatically.
- Translation reports. If you tap Report on a translation, we receive the original text, the translation, the language pair, any note you add, and your install ID. We keep reports for up to 90 days and read them to improve translation quality.
- Video reports. If you report a video, we receive its YouTube ID, title and channel, the language you are learning, the reason you picked, and your install ID. We keep reports for up to 90 days to review the video.
- Request logs. Cloudflare, our hosting provider, logs basic request details such as IP address, time, address requested, and status code, under Cloudflare's privacy policy. These logs don't include what you translate.
Watch and YouTube
The Watch tab uses YouTube API Services. By using Watch you agree to the YouTube Terms of Service, and Google's handling of your data is covered by the Google Privacy Policy.
- Search. Your search terms and learning language are sent to our server, which asks the YouTube Data API for results. Results are cached for up to 24 hours under a one-way hash of the search.
- Recommended videos and captions. The app asks our server for recommended videos in your learning language, and for saved captions by video ID.
- Playing a video. Videos play in YouTube's embedded player, and the app loads captions directly from YouTube. YouTube receives the usual information any browser sends, such as your IP address.
Lexo never signs you in to YouTube or Google.
Subscriptions
- Apple processes payments. Lexo never sees your payment details. Subscriptions are governed by Apple's Standard EULA.
- RevenueCat manages subscription status. It receives your install ID and your App Store purchase information, under RevenueCat's privacy policy. It does not receive your name, email, words, translations, or review history. RevenueCat tells our server whether an install's subscription is active, and our server keeps that status until the subscription expires.
- Sign in with Apple. Current versions of Lexo don't ask you to sign in. If you signed in with Apple in an earlier version, our server received only Apple's anonymous user identifier, never your name or email, and used it to issue a session token that expires after 30 days.
Who we share data with
We share data only with the service providers named on this page, and only so they can provide their part of Lexo: Google (Gemini API and YouTube API Services), Cloudflare (hosting), RevenueCat (subscription management), and Apple (payments, dictation, and iCloud). Each processes data under terms that protect it at least as well as this policy. We don't sell your data or share it for advertising.
What we don't do
- No accounts, and no names or email addresses collected in the app.
- No advertising, advertising SDKs, or crash reporters.
- No tracking across other companies' apps or websites.
Your choices
- Withdraw permission for AI translation in Settings → Privacy → AI translation. Nothing more is sent to Google afterwards.
- Delete everything stored on your device by deleting the app. iCloud backups can be removed in iOS Settings under your Apple ID's iCloud storage.
- To ask us to delete reports or other server records linked to your device, email privacy@getlexo.app.
Web fonts
This website loads two typefaces (Inter and Fraunces) from Google Fonts, so Google may see your IP address when you visit it. The Lexo app includes these fonts and never downloads them from Google.
Children's privacy
Lexo is not directed at children under 13 and does not knowingly collect personal information from them.
Changes to this policy
If we make material changes to how Lexo handles your data, we will update this page and the date above. If a change affects what is sent to an AI service or who receives it, the app will ask for your permission again.
Contact
Questions about privacy: privacy@getlexo.app.