Privacy Policy – LexCH
Last updated: August 2026
1. Data Controller
The data controller is:
Aaron Boccadamo
Danijel Balcakovic
Via Carona 38
6900 Paradiso, Ticino – Switzerland
Email: info@lexlegal.ch
LexCH is not currently registered in the Swiss Commercial Register.
For any questions regarding data protection or to exercise your rights, please contact us at the address above.
2. Scope of Application
This policy applies to the processing of personal data carried out through:
- the LexCH app
- any web pages connected to the service
- registration, login, AI chat, document archive, legal cases, notifications and user preferences features
- communications between the user and LexCH
3. Personal Data Processed
We process data provided directly by the user, data generated during use of the service, and technical data collected automatically.
3.1 Account Data
- email address
- name
- password (hashed, never in plain text)
- profile picture
- login method (email/password, Google, Apple)
- subscribed plan, billing period, activation and expiry date
- preferred language
- email verification status and date
- date of acceptance of terms and newsletter consent
3.2 Access and Technical Data
- IP address
- user-agent and browser
- operating system
- device type, manufacturer, model
- screen resolution
- time zone
- approximate geolocation (country, city)
- date and time of access
3.3 AI Chat Data
- messages submitted
- AI responses
- conversation title
- technical data (date, time, IP, conversation ID)
3.4 Uploaded Documents
- uploaded files
- file name, type, size
- extracted content and text
- metadata and AI information (deadlines, categories, classifications)
3.5 Personal Document Archive
- uploaded documents
- title, description, category, notes
- extracted text
- linked AI information
3.6 Settings, Preferences and Consents
- language and theme
- preferred canton and municipality
- notification preferences
- AI preferences (tone, style, level of detail)
- cookie or equivalent technology consents
3.7 Push Notifications
- device token
- device name
- platform
3.8 AI Usage Data
- tokens consumed
- date and time of each request
3.9 Temporary Verification and Security Data
- verification or reset codes/tokens
- validity periods and expiry
3.10 Device Permissions
LexCH requests the following device permissions, only if the user explicitly grants them and only when the related feature is first used:
- Camera (
CAMERA): used exclusively for (a) taking a profile photo, (b) scanning paper documents for AI analysis, (c) capturing images to attach to a conversation. Images remain on the device and are uploaded to our servers only if the user confirms sending. No background access and no video recording. - Gallery / Storage (
READ_MEDIA_IMAGES/READ_EXTERNAL_STORAGE): to allow the user to select existing images or documents for analysis or attachment. - Notifications (
POST_NOTIFICATIONS): to receive push notifications (e.g. AI response completed, legal updates, deadlines). Can be disabled at any time from the operating system or app settings. - Internet (
INTERNET): required to communicate with LexCH servers (legal APIs, authentication, AI).
The user may revoke permissions at any time from the operating system settings. Revocation does not result in data loss but may limit certain features.
4. Purposes of Processing
Personal data is processed to:
- create and manage the account
- provide secure access to the app
- deliver service features, including AI features
- analyse content submitted by the user
- generate responses, summaries, classifications, estimates and suggestions via AI
- store and organise documents in the personal archive
- manage the subscribed plan
- send service communications and verifications
- send newsletters (with consent only)
- improve performance, security and stability
- prevent abuse, fraud and unauthorised access
- fulfil legal obligations or defend rights
5. Use of Artificial Intelligence
LexCH uses artificial intelligence systems to process user-submitted content and provide:
- analysis
- summaries
- classifications
- suggestions
- drafts
- estimates
- identification of relevant elements
AI outputs serve an informational and support purpose and do not constitute legally binding decisions or professional legal advice.
AI Provider: LexCH uses the Google Gemini (Google LLC) API. To generate responses, conversation content and shared documents are transmitted to Google over an encrypted connection (TLS 1.2+). Under the Google Gemini API Terms of Use, these data are not used by Google to train its models and are not shared with third parties. Google LLC maintains internationally certified security standards (ISO 27001, SOC 2 and SOC 3).
Users are advised to avoid entering unnecessary personal data of third parties.
6. Source of Data
Data is collected:
- directly from the user
- automatically from the device or browser
- from internal technical systems for security and service management
If the user enters third-party data, they are responsible for complying with applicable law.
7. Legal Basis for Processing
We process personal data:
- to provide the requested service
- to manage the relationship with the user
- for legitimate interests (security, stability, abuse prevention, service improvement, legal defence)
- on the basis of consent, where required
- to fulfil legal obligations
8. Disclosure to Third Parties
We may disclose personal data to providers who process data on our behalf, including in particular:
- hosting and cloud infrastructure providers
- AI service providers (e.g. Google Gemini)
- email service providers (SMTP)
- push notification and authentication providers (Firebase – Google LLC; used for push notifications and social authentication via Google Sign-In and Apple Sign-In)
- subscription and payment management providers (RevenueCat Inc.; payment processing is carried out via Google Play Store or Apple App Store – LexCH does not receive or store payment card data)
- analytics or crash reporting service providers
- technical support, maintenance and security providers
Such providers are selected and contractually bound to ensure processing in compliance with applicable law.
Data may also be disclosed to authorities or advisors when required by law or necessary to protect legal rights or interests.
We do not sell personal data.
9. International Data Transfers
Data may also be processed outside Switzerland.
If the destination country does not provide an adequate level of protection, we put in place appropriate safeguards (e.g. standard contractual clauses), subject to exceptions provided by law.
Reference: FDPIC – Transfer of personal data abroad.
10. Retention Period
We retain data for as long as necessary for the purposes stated and, thereafter, for legal obligations or defence of rights.
In particular:
- account data: for the duration of the account
- access and security data: for as long as necessary for security
- chats, documents, archive and legal cases: while the account is active or until deletion
- temporary data: only for as long as necessary
- consents and preferences: retained for documentation
11. Data Security
The protection of our users' data is an absolute priority for LexCH. We apply the highest industry security standards to ensure that your personal information, your AI assistant conversations, and your documents remain private, confidential, and accessible to you alone.
Our technical and organisational measures protect personal data from:
- unauthorised access
- loss
- misuse
- alteration
- unlawful disclosure
Measures include access controls, credential protection, strict internal access restrictions, security event logging, continuous monitoring, and further measures proportionate to the risk.
11.1 Zero-knowledge architecture – not even we can read your data
LexCH is designed according to a zero-knowledge architecture: personal data and the content you generate are encrypted using AES-256-GCM – the same standard used by banks, governments and military institutions – before being saved to the database.
The encryption key is held exclusively on our application server, isolated from the database. This means that:
- We at LexCH cannot read the content of your AI conversations.
- We cannot read the documents you upload to your personal archive.
- We cannot read the notes you enter.
- Even if a hosting provider, system administrator or malicious actor were to gain physical access to the database, they would see only encrypted data, unusable without the key.
Scope of zero-knowledge encryption: the protection described above applies to data stored in LexCH systems. By their nature, AI features require that conversation content be transmitted to the provider (Google Gemini API) in readable form to generate a response – an inherent characteristic of any AI service, managed with the safeguards described in §5.
Data protected with AES-256-GCM encryption
User profile
- email address
- name
- preferred canton and municipality
AI assistant conversations
- conversation titles
- full content of each message (user questions and AI responses)
Personal document archive
- document title, description, notes
- original file name
- extracted text and document content
- the binary file itself, encrypted directly on disk
Notifications and devices
- device token (FCM)
- device name
Security logs
- IP address, user-agent, screen resolution, time zone, country, city, device name (used exclusively for account security and also encrypted)
Credential protection
- Passwords are never stored: transformed using Argon2id (the algorithm recommended by OWASP 2024 and winner of the Password Hashing Competition), they cannot be reconstructed – not even by us.
- Session tokens, email verification and password reset tokens are protected using cryptographic hashing.
- Email lookup at login uses a blind-index HMAC-SHA256, which verifies identity without exposing the email address in plain text.
11.2 End-to-end protected transmission
All communications between the app, the website and our servers take place exclusively over HTTPS with TLS 1.2 or higher, with a valid certificate issued by a recognised certification authority. Data is therefore protected both in transit and at rest.
11.3 Our commitment
We consider the privacy of our users a core value. LexCH has been built so that your legal data, your AI questions and your documents remain exclusively yours.
12. Newsletter and Communications
If you have given your consent, we may use your contact details to send:
- newsletters
- updates
- informational or promotional communications relating to LexCH
You may withdraw your consent at any time via:
- the unsubscribe link
- the app settings
- email to info@lexlegal.ch
13. Push Notifications
If you enable push notifications, we may send you operational, informational or service-related communications to your device.
You may disable them at any time from the app or device settings, using the available options.
14. User Rights
To the extent permitted by applicable law, you have the right to:
- know whether we process personal data relating to you
- obtain information about the data processed
- request correction of inaccurate data
- request deletion of data, where permitted
- withdraw consents for the future
- object to or restrict certain processing, where applicable
- request information about the existence of automated individual decisions
To exercise your rights: info@lexlegal.ch
Swiss law (FADP) provides:
- right of access with a response, as a rule, within 30 days
- duty to inform in the event of automated individual decisions, in the cases provided by law
15. Automated Decisions
LexCH uses automated tools and AI systems to provide support to the user.
Unless expressly stated otherwise, the service is not intended as a system that makes legally binding automated individual decisions without human involvement.
If a specific feature were to involve an automated individual decision within the meaning of applicable law, the user will be informed as required by law.
16. Minors
LexCH is intended for individuals capable of using the service independently and responsibly.
Those using the app represent that they have the capacity required to do so under applicable law.
If we become aware that personal data has been processed in a manner inconsistent with applicable age or consent rules, we will take reasonable measures to limit or discontinue such processing.
17. Changes to this Policy
We may update this privacy policy at any time, in particular in the event of:
- changes to the service
- changes to AI features
- changes in the providers used
- new applicable legal obligations
The updated version will be published in the app and/or on relevant channels, with an indication of the last update date.
18. Contact
For questions about this policy or to exercise your rights, contact us at:
Aaron Boccadamo
Danijel Balcakovic
Via Carona 38
6900 Paradiso, Ticino – Switzerland
Email: info@lexlegal.ch