Privacy Policy
Last updated: September 8, 2026
Lexxio is made by Trisdia, LLC (“Trisdia,” “we,” “us”). This policy explains what we collect through this website, the Lexxio app on desktop and mobile, Lexxio Verbs, and the Lexxio Lens browser extension when it is available; what stays on your device; which companies process data on our behalf; and how you can see, export or delete what we hold. Trisdia, LLC is the data controller for everything described here.
The short version: your books, translations, vocabulary, progress and recordings live on your device. We keep an account for you only if you make one, and it holds your email, your plan, and (on Pro) your synced progress. Text you ask the AI to work on is sent to a model provider to produce the answer and is not stored by us. Your voice, for pronunciation checks, is scored by a speech service and not kept. We do not sell personal data, and we do not use it for advertising.
1. This website
- Waitlist. If you join, we store your email address, the language you signed up in and the time, in a database hosted by Upstash, and send you a launch email through Resend when Lexxio is ready. We do not send a confirmation email when you sign up. Every email has an unsubscribe link.
- Contact form. We store your name, email, topic, message, the time and your IP address (for rate limiting and abuse prevention) in Upstash, and email the message to ourselves through Resend. We do not send you an automatic receipt.
- Bot protection. Both forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script. It runs invisibly, with nothing for you to click. To do that check, Cloudflare receives your IP address, browser and device signals, and issues a token we verify on our server. See Cloudflare’s Turnstile Privacy Addendum.
- Analytics. We use Vercel Analytics, which counts page views and referrers in aggregate. It does not set cookies, does not fingerprint you, and does not follow you across sites. We run no advertising trackers.
- Hosting logs. Vercel, which hosts this site, keeps standard request logs (IP address, user agent, URL, time) for security and debugging for a limited period.
- Cookies. One functional cookie remembers the site language you chose. That is all.
2. What stays on your device
Lexxio is a local-first app. The following lives in the app’s own database on your computer or phone and is never uploaded to us:
- Your library: every book you import or download, its text, its translations at every level, its audio, covers and highlights.
- Reading progress, notes, saved words, flashcard history, Basics and verb-lesson progress, Coach state, and usage tallies (these are also synced to your account on Pro; see section 3).
- Dictionaries, voices and speech-recognition models the app downloads so it can work offline.
- Recordings you make for pronunciation practice. They are processed and discarded; the app does not keep them.
- Backups you create, which are files you control.
- Supervised-mode settings, the PIN (stored as a hash), and the progress reports you print. Reports are generated on the device.
Speech recognition for Talk and for reading your pronunciation runs on the device on Apple platforms. Read-aloud with the standard voices runs on the device. Moving a book from your desktop to your phone happens directly between the two over your own network; no book bytes pass through our servers, ever.
3. Your account
Much of Lexxio works with no account. If you create one, it is held in Supabase, our authentication and database provider, and contains:
- Identity. Your email address, a hashed password or the identity from a sign-in provider you chose, and session tokens.
- Plan and balance. Which plan you are on, its status and billing cycle, and a ledger of the allowance granted to you and drawn down by AI requests.
- Devices. A record that a device of a given platform (desktop or phone) has been set up with your account, so the app can offer per-device settings. It deliberately stores no device name, model, IP, locale or push token.
- Request metadata. For every AI request: which provider and model answered, how many tokens went in and out, what it cost against your allowance, and when. Not the text of the request or the answer.
- Originals you have borrowed, so the borrow limit can be enforced.
- Synced progress (Pro). Saved words and their review schedule, Basics lesson progress, Coach plans and activity, favourites, notes and usage tallies, so your phone and desktop match. Row-level security means only your account can read your rows.
4. AI features
When you ask for a translation, an explanation, a definition, a quiz, a Coach plan, or you speak with a character in Talk, the app sends the relevant text (the passage, the word, the sentence, your message or your transcribed speech, and a little context such as the book’s title, language and your reading level) to our server, a Cloudflare Worker, which checks your plan and forwards it to a large language model through OpenRouter. OpenRouter routes to the model provider we have configured for that task (currently models from Google, Amazon and Anthropic, and this can change). The answer is streamed back to your device and cached there.
- We do not store the text you send or the answer you get on our servers. We record only the metadata described in section 3.
- One exception: for the Lexxio Originals, whose text is the same for every reader, some generated material (such as chapter discussion questions) is cached on our server for up to 180 days so the next reader gets it instantly. That cache is keyed by the book, chapter and language, not by you.
- OpenRouter and the model providers process the text to generate the answer under their own terms. We do not use your text to train models, and we choose providers whose API terms restrict use of inputs to providing the service.
- Rate limiting runs per account on our server and keeps a rolling count of requests, nothing more, which expires within a day.
5. Pronunciation
When you use pronunciation check, the recording of the word or sentence you said, together with the reference text, is sent through our server to Microsoft Azure Speech (Pronunciation Assessment), which returns per-sound scores. The audio is used to produce the score and is not retained by us. Some checks (for example Spanish b/v, and Mandarin tone check) are scored entirely on the device and never leave it. Pronunciation check is capped per user per day.
6. Narration and read-aloud
Standard read-aloud voices run on your device; the text is not sent anywhere. Recorded narration on selected Originals is delivered with the book. Cloud text-to-speech is not currently enabled; if we turn it on, this policy will say so and describe it first.
7. Crash and error reports
The app and our server send crash and error reports to Sentry so we can fix what breaks. A report contains the error, a stack trace, the app version, the operating system and device model, and a random installation identifier. We do not attach your name, email or the contents of what you were reading, and we do not record your screen or session. Reports are held by Sentry for a limited period (by default 90 days). Crash reporting is off in development builds.
8. Payments
- Lexxio plans are billed on the web by Stripe. Stripe collects and stores your card details; we never see them. We receive your Stripe customer and subscription identifiers, plan, status, and billing period, and Stripe may share limited details (such as the card brand and last four digits) for your billing portal.
- Lexxio Verbs and any other app-store purchase is made with Apple or Google. We receive a purchase receipt or entitlement, not your payment details.
9. Downloads the app makes
To work offline, the app fetches things from public hosts. Each of those hosts sees your IP address and the request, as any download does, and nothing else about you:
- Public-domain books from Project Gutenberg (gutenberg.org).
- Definitions from the public Wiktionary API when the offline dictionary has no entry (the single word is sent).
- Dictionary packs, voices and speech models from GitHub, Hugging Face and our own storage on Cloudflare.
- App updates for the desktop app from our storage on Cloudflare. The update check sends the app’s version and platform.
10. Lexxio Lens
Lexxio Lens is a browser extension that is not yet released. When it is, it will save words and settings locally in your browser, may let you send a selection to an AI assistant you choose (which then handles the text under its own policy), may let you connect an AI provider key of your own, and will download dictionaries and voices as the app does. We will update this section to match the release before it ships.
11. Children and families
Accounts are for people 13 and over. A parent or guardian may use Lexxio with a younger child through the adult’s own account; supervised mode was built for that. In that case the account and everything in it belong to the adult, the child’s reading and progress stay on the device (and in the adult’s synced progress on Pro), and progress reports are generated locally. We do not knowingly collect personal data from a child under 13 directly. If you believe a child has created their own account, tell us and we will delete it.
12. How long we keep things
- Waitlist emails: until launch and the launch email, or until you unsubscribe, whichever is first.
- Contact messages: until resolved, and no more than twelve months.
- Account data: while your account exists.
- After you delete your account: your login, profile, devices, borrows and synced progress are deleted immediately. Billing and usage records (subscription and purchase history, allowance grants and charges, and the metadata of AI requests) are kept for accounting, tax and dispute purposes but are severed from your account so they no longer identify you. Database backups roll off within 30 days.
- Server-side caches and rate-limit counters: rate-limit counters expire within a day; the shared Originals cache expires within 180 days.
- Crash reports: about 90 days at Sentry.
- Everything on your device: until you delete it. Deleting the app, or using the app’s wipe option, removes it.
13. Who processes data for us
These companies handle data only to provide the part of the Service named, under contracts that limit what they may do with it:
- Supabase: accounts, plan state, synced progress (USA).
- Cloudflare: our API server, rate limiting, the shared cache, file storage, app updates, and Turnstile bot protection on this site’s forms.
- OpenRouter and the model providers it routes to (currently Google, Amazon and Anthropic): generating AI answers.
- Microsoft Azure Speech: pronunciation scoring.
- Sentry: crash and error reports.
- Stripe: subscription billing on the web.
- Apple and Google: app distribution and app-store purchases.
- Vercel: hosting and aggregate analytics for this site. Upstash: waitlist and contact storage. Resend: transactional email.
Trisdia is based in the United States and these providers operate there and in other countries. If you are in the EEA, UK or Switzerland, transfers rely on the providers’ standard contractual clauses or equivalent safeguards.
14. Why we are allowed to process it
Where a legal basis is required: performing our contract with you (running your account, plan and the features you use); our legitimate interests (keeping the Service secure, preventing abuse, fixing crashes, understanding aggregate use of the site); your consent (the waitlist, and any optional feature that asks first); and legal obligations (tax and accounting records).
15. Your rights and choices
- Delete your account from Settings in the app, at any time, without asking us.
- Export your library and progress with the app’s backup feature, at any time.
- Access, correct, restrict or object: email us and we will act within 30 days. We may need to verify that the request comes from the account holder.
- Unsubscribe from the waitlist with the link in any email.
- Complain to your data-protection authority if you are in the EEA or UK. We would rather hear from you first.
- California residents: we do not sell or share personal information as those terms are defined in the CCPA, and we do not use it for targeted advertising. You have the rights to know, delete, correct and not be discriminated against, exercised as above.
16. Security
Traffic to our servers and providers is encrypted in transit. Account data is protected by row-level security so each account can only reach its own rows. Certain Originals are delivered encrypted. Your device database is protected by your device’s own security, and supervised mode’s PIN is stored as a hash. No system is perfectly secure; if we learn of a breach affecting your data we will tell you and the relevant authorities as the law requires.
17. Changes
We will update this page when our practices change and update the date at the top. For material changes we will give notice in the app, on this site or by email to account holders before they take effect.
18. Contact
Trisdia, LLC
hello@trisdia.com
or the contact form on this site.