Privacy Policy

Last updated: August 4, 2026

This policy explains what data the Lexa app and website collect, why, where it is stored, and the choices you have.

Contents
  1. Who we are
  2. The short version
  3. What we collect & why
  4. Legal bases (GDPR)
  5. Who we share data with
  6. Where your data is stored
  7. How long we keep it
  8. Accessing & deleting your data
  9. Your privacy rights
  10. Security
  11. Children
  12. Changes to this policy
  13. Contact

1. Who we are

Lexa (the “app”) is a vocabulary-learning app for iOS and Android. This policy also covers our websites, mylexa.app and help.mylexa.app. The app, the websites and their servers are operated by Oleksandr Myroshnychenko, an independent developer based in Ukraine (“we”, “us”, the “data controller”).

For any privacy question, email privacy@mylexa.app.

2. The short version

3. What we collect & why

Account & identity

You sign in with Apple or Google. Through that sign-in we receive your email address and name, which we use to create and secure your account. If you use Sign in with Apple, you may choose to hide your email, in which case we only ever see Apple’s private relay address.

Inside the app you can pick an avatar icon from a built-in set. This is a simple graphic you choose — it is not a photo of you and contains no personal information. We never request access to your camera or photo library.

Your learning content & progress

The words, categories, attached media, and study progress you create are stored on our servers so they stay in sync across every device you sign in on. This content belongs to you; we use it only to provide the learning features of the app.

“Watch in context” video clips

When you watch a video clip in the “Watch in context” feature, the clip is streamed directly from YouTube in reduced-cookie mode (youtube-nocookie.com). Playing a clip sends your IP address and device information to YouTube/Google, under their own privacy policy — see section 5.

Subscriptions

If you buy Lexa Pro, the purchase is processed by the App Store or Google Play, and subscription status is managed for us by RevenueCat. We receive only your subscription status (e.g. active / expired) so we can unlock Pro features. We never see or store your card or payment details.

Diagnostics & crash reports

To find and fix crashes, we use Sentry (EU region). When the app hits an error it may send a diagnostic report — the device model, the operating-system and app version, and a technical stack trace. We turn off Sentry’s personal-data collection, so these reports are not tied to your identity and do not include your IP address.

Usage analytics

To understand how Lexa is used and where to improve it, the app sends anonymous product-analytics events to our own servers — for example which features you open, how you interact with the Lexa Pro screen, when you reach a free-plan limit, and a snapshot of your app settings (such as theme and chosen languages). These events are linked to your account but contain no sensitive content: never the words you study, your media, file contents, or message text — only identifiers, counts, and settings values. We also generate a random device identifier so we can tell your devices apart; this is not an advertising identifier, and we never use it for advertising or sell it.

Your choice

Crash diagnostics and usage analytics are optional. You can switch them both off at any time in Settings → Privacy → “Help improve Lexa”. With it off, no diagnostic or analytics data leaves your device.

Website visits

Our website, mylexa.app, counts how many people open it and which channel they arrived from — for example a link we posted on YouTube or Reddit. A visit records four things: the channel, which language version of the page was opened, whether this browser has been to the site before, and, separately, whether the App Store or Google Play button was pressed. That is the whole list.

The site sets no cookies and uses no third-party analytics service. These counts contain no IP address, no user-agent and no identifier, so two visits cannot be linked back to the same person. To tell a first visit from a return, your browser keeps a single yes/no flag in its own local storage and sends only that yes/no — never anything that identifies you or your device. Like any website, our host sees your IP address in order to deliver the page; it is not added to these counts. You can clear the flag at any time by clearing site data for mylexa.app in your browser.

This is separate from the in-app setting above: it concerns the website only, and none of it is connected to your Lexa account.

If you are in the European Economic Area or the UK, we rely on these legal bases:

5. Who we share data with

We do not sell your data. We share it only with the service providers (“processors”) that make the app work, each under their own privacy terms:

We may also disclose data if required by law, or to protect the rights, safety, or property of our users or ourselves.

6. Where your data is stored

Your account and learning data are stored on Microsoft Azure servers in the European Union (Poland). Some of our providers (Apple, Google, RevenueCat, Sentry) may process limited data in the United States or other countries. Where data leaves the EEA, those transfers are covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. How long we keep it

We keep your account and learning data for as long as your account exists. When you delete your account, we delete that data from our active systems; residual copies in encrypted backups are removed on a rolling cycle. Diagnostic data in Sentry is retained for a limited period (by default around 90 days) and then deleted automatically.

8. Accessing & deleting your data

You are always in control of your data:

9. Your privacy rights

EEA & UK (GDPR)

You have the right to access, correct, delete, export (portability), restrict, or object to our processing of your data, and to withdraw consent at any time. You may also lodge a complaint with your local data protection authority. (In Ukraine, this is the Ukrainian Parliament Commissioner for Human Rights.)

California (CCPA/CPRA)

California residents have the right to know what personal information we collect, to access and delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under California law.

To exercise any of these rights, contact privacy@mylexa.app.

10. Security

All traffic between the app and our servers is encrypted with HTTPS/TLS. Sign-in tokens are stored in the device’s secure storage (Apple Keychain / Android Keystore). We restrict server access and rely on Microsoft Azure’s infrastructure security. No method of transmission or storage is ever 100% secure, but we work to protect your data using industry-standard measures.

11. Children

Lexa is not directed to children. We do not knowingly collect personal data from children under 13 (or under the minimum age required in your country). If you believe a child has provided us data, contact privacy@mylexa.app and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and for significant changes we will provide notice in the app or by email. Continued use of the app after a change means you accept the updated policy.

13. Contact

Questions or requests about your privacy? Email privacy@mylexa.app and we’ll be glad to help.