LEXA

LEXA

Privacy Policy

Last updated: September 6, 2026

Version: 1.3

LEXA ("the App") is an iPhone app that helps users review English before opening selected apps or websites. The App provides learning and app-blocking support features.

This Privacy Policy explains how user information is handled in the App.

Operator: LEXA Operator Contact: [email protected]

1. Basic Policy

The App respects user privacy and does not collect information beyond what is necessary to provide its features.

Core data such as learning data, review history, card information, blocking settings, and unlock history is generally stored on the user’s device. However, when a user connects cloud backup with Sign in with Apple, the learning data and settings needed for restoration are also stored in the cloud.

The App does not sell users’ personal information, learning data, or blocking target information to third parties. The App also does not use such information for advertising, ad tracking, or provision to data brokers.

2. Information We Collect and Use

The App may store and process the following information on the user’s device in order to provide its features: - App settings - Display language and learning language settings - Information about apps, categories, and web domains selected as blocking targets - Temporary unlock status - Learning cards, user-created cards, and card display settings - Review history, review status, and learning progress - Unlock session history - Learning continuity information such as streaks - Information necessary to confirm access to paid features

This information is used for English learning, review scheduling, app blocking, unlock sessions, re-blocking, learning progress display, settings management, and paid feature access.

The App may use a pseudonymous local user ID generated for each installation for product analytics, crash diagnostics, and purchase-status confirmation. It is not an account ID and is replaced when local data is reset or the App is reinstalled.

2.1 Cloud Backup

When a user connects cloud backup with Sign in with Apple, the App sends and stores authentication information based on the account identifier provided by Apple and App data needed for restoration on Supabase servers. This enables device replacement, reinstallation, and restoration with the same account.

Stored data may include learning profiles and settings, review history, card review state, favorite, known, and study-selection settings, deck and Pack settings and progression, completed unlock sessions, and user-created decks and cards. For user-created cards, this may include user-entered prompt text, answer text, notes, pronunciation, romanization, and other card content.

The App does not send selected blocking apps, categories, web domains, or Screen Time tokens to cloud backup. Cloud data is used only for authentication, backup, synchronization, restoration, and account deletion for the authenticated user, and not for advertising or advertising tracking.

3. Information Sharing Between the Main App and Extensions

The App shares the minimum information necessary between the main app and related extensions in order to use Apple’s Screen Time-related features.

The shared information may include selected blocking targets, unlock status, state information necessary for usage monitoring, and information necessary for error recovery.

This information is stored in the iOS App Group shared container and is used by the main App and its related extensions.

4. Use of Screen Time / Family Controls

The App uses Apple-provided features such as Screen Time, Family Controls, Managed Settings, and Device Activity based on the user’s permission.

These features allow the App to apply restrictions to apps, categories, and web domains selected by the user, temporarily unlock them after learning is completed, and apply restrictions again after a certain amount of use.

The App is not intended to collect the user’s entire Screen Time history. It is also not intended to collect a full list of all apps installed on the device. The App uses only the targets explicitly selected by the user for the purpose of providing the blocking feature.

5. Background Processing Through DeviceActivity

The App may perform background processing initiated by iOS in order to monitor usage after unlocking and to re-apply blocking.

This processing is used to re-apply restrictions when the user reaches the usage allowance they configured. It is not intended to collect or analyze detailed Screen Time history.

6. Purchase and Subscription Information

The App may offer paid features, subscriptions, one-time purchase plans, or other paid plans.

Payments are processed through Apple’s in-app purchase system on the App Store. The App also uses RevenueCat, Inc. as a purchase management service to confirm purchase status, restore purchases, manage access to paid features, and prevent fraudulent use.

The App operator does not directly collect users’ credit card numbers, bank account information, Apple ID passwords, or other payment credentials.

The App or RevenueCat may process information necessary to provide paid features, including anonymous user IDs, purchase history, product IDs, subscription status, information required for purchase restoration, app version, and device or operating system information.

This information is used to confirm access to paid features, check subscription status, restore purchases, prevent fraudulent use, and investigate purchase-related issues.

7. Information Collected When You Contact Us

If a user contacts us by email or another method, we may collect the following information: - Email address - Inquiry content - Screenshots, logs, device information, or other information voluntarily provided by the user - App version, OS version, and other information necessary to investigate issues

This information is used for responding to inquiries, investigating bugs, and improving quality.

Inquiry information is generally stored for three years after the response is completed, and is then deleted or anonymized. However, we may retain it for a longer period if necessary for legal compliance, dispute resolution, fraud prevention, or similar purposes.

8. Information During TestFlight Use

If the App is used through TestFlight, Apple may collect and process crash logs, device information, and usage-related information.

This information is used for beta testing, bug fixing, and quality improvement.

9. Information the App Does Not Collect

In normal use, the App does not currently collect the following information: - Name - Address - Phone number - Contact list - Photo library - Camera images - Audio data - Precise location information - Health information - Biometric information - Face data - Fingerprint information - A full list of all apps installed on the device - Browsing history outside the App - Tracking information using advertising identifiers

However, if a user voluntarily sends any of this information when contacting us, it may be temporarily processed for the purpose of responding to that inquiry.

10. External Transmission and Third-Party Services

The App does not use third-party advertising networks, advertising-identifier tracking, or advertising tracking across other companies’ apps or websites.

Information may be sent to the following external services in connection with providing the App: [PostHog (EU region)] Information That May Be Sent: Pseudonymous installation-local user ID, explicit usage events, app version, language, feature state, and minimum technical information Information Not Sent: Learning-card or answer content, Screen Time selections or tokens, exact learning performance, exact blocking-target counts, or location Purpose: Product analytics and feature improvement Retention: Generally one year [Firebase Crashlytics] Information That May Be Sent: Crash information, limited diagnostic codes, technical information about the App, OS, and device, and the pseudonymous installation-local user ID Purpose: Issue investigation and quality improvement Retention: Generally 90 days [Apple Inc.] Information That May Be Sent: Purchase information, purchase status, crash logs, diagnostic information, App Store usage information, device and OS information Purpose: App distribution, in-app purchases, purchase restoration, quality improvement, beta testing [Apple iCloud] Information That May Be Sent: Part of the App data stored on the device Purpose: Backup and restoration when the user has enabled iCloud Backup [RevenueCat, Inc.] Information That May Be Sent: Pseudonymous installation-local user ID, purchase history, product IDs, subscription status, information required for purchase restoration, app version, device and OS information Purpose: Purchase status confirmation, purchase restoration, paid feature management, fraud prevention, investigation of purchase-related issues [Email service provider] Information That May Be Sent: Email address, inquiry content, attachments, sending date and time Purpose: User support, inquiry handling, bug investigation

[Supabase] Information That May Be Sent and Stored: Authentication information based on the account identifier provided by Apple, learning profiles and settings, review history, review state, deck and Pack settings and progression, completed unlock sessions, user-created decks, and user-created card content including user-entered prompts, answers, notes, and pronunciation information Information Not Sent: Screen Time selections or tokens Purpose: Authentication, cloud backup, synchronization, restoration, and account deletion Storage Region: Tokyo

If we materially change our use of external services, we will update this Privacy Policy to specify the recipient, information transmitted, and purpose of use.

10.1 Product Analytics and Crash Diagnostics

The App uses PostHog in the EU region for product analytics. It may receive a pseudonymous installation-local user ID, explicit usage events, app version, language, feature state, and minimum technical information. It does not receive learning-card or answer content, Screen Time selections or tokens, exact learning performance, exact blocking-target counts, or location. PostHog data is generally retained for one year.

The App uses Firebase Crashlytics for crash diagnostics. It may receive crash information, limited diagnostic codes, technical information about the App, OS, and device, and the pseudonymous local user ID. Crashlytics data is generally retained for 90 days.

Product analytics and crash diagnostics are enabled by default in the current release. The current release does not provide an in-app setting for users to disable these services. Information already transmitted remains subject to the provider’s retention period. RevenueCat purchase processing and Apple App Store processing are separate from product analytics and crash diagnostics.

RevenueCat may receive the pseudonymous local user ID, purchase history, product IDs, subscription status, restoration information, and app, device, or operating-system information to provide purchase confirmation, restoration, paid feature management, fraud prevention, and purchase-related support.

11. iCloud Backup

The App’s data is generally stored on the user’s device.

However, if the user has enabled iCloud Backup, some App data stored on the device may be included in Apple’s iCloud Backup.

The management, storage, restoration, and deletion of iCloud Backup data are subject to Apple’s services and the user’s Apple ID settings.

12. Disclosure to Third Parties

The App does not provide users’ personal information to third parties except in the following cases: - When the user has given consent - When external services are used within the scope necessary to provide App features, handle inquiries, process purchases, or investigate issues - When required by law - When a lawful disclosure request is made by a court, administrative agency, police, or other public authority - When necessary to protect the rights, property, or safety of the App, users, or third parties

The App does not sell user information to third parties.

13. Data Retention and Deletion

Learning data, review history, card information, settings, blocking settings, unlock history, and other data stored on the device are retained until the user deletes or resets them in the App, or uninstalls the App.

However, due to the specifications of iOS, the App Group shared container, or iCloud Backup, some data may remain on the device or in iCloud Backup even after the App is uninstalled.

If the App provides a reset feature, users can delete learning data, settings, history, and related information from within the App.

If you wish to delete information processed outside the device, such as inquiry information or purchase-related information, please contact us using the contact information at the end of this Policy. However, certain information may need to be retained for legal, accounting, tax, fraud prevention, dispute resolution, or similar purposes.

Usage data is generally retained for one year and Crashlytics crash and diagnostic data is generally retained for 90 days.

Cloud-backup data is retained until the user deletes the cloud account from within the App. Deleting the cloud account deletes the Supabase authentication account and the cloud-backup data associated with it, and requests revocation of the Apple authentication token. Deletion may take a reasonable period to propagate where required for legal obligations, security, or rotation of disaster-recovery backups. Data remaining on the device or in iCloud Backup is governed by the applicable deletion method and Apple’s services.

14. Security

The App takes reasonable security measures to prevent leakage, loss, alteration, unauthorized access, and other risks related to user information.

The App’s core data is stored in the iOS app container, in a dedicated shared area used by the App and its related extensions, or, when cloud backup is connected, on Supabase servers. Access to cloud data is restricted to the authenticated user.

However, no method of storage, communication, or electronic processing can be guaranteed to be 100% secure. Users should also take care to manage their own devices, including using device lock features, keeping the OS updated, and avoiding suspicious apps.

15. Use by Minors

The App is not primarily directed at children under the age of 13 in Japan.

If a person under the age of 13 uses the App, they should do so with the consent and supervision of a parent or legal guardian.

If different standards apply to the handling of minors’ personal information in the European Economic Area, the United Kingdom, the United States, or other regions, applicable laws will be followed.

If the Operator becomes aware that personal information has been collected from a minor in violation of applicable law, the Operator will take reasonable steps to delete or otherwise address such information promptly.

16. User Rights

Users may have the right, within the scope of applicable law, to request access, correction, suspension of use, deletion, or other handling of personal information held by the Operator.

Learning data and settings for a device that is not connected to cloud backup remain on that device, and the Operator cannot directly access that on-device data. When cloud backup is connected, data needed for restoration is stored on Supabase.

Data stored on the device should be deleted through the App’s delete or reset functions, or by uninstalling the App.

Purchase-related information may be processed through Apple and RevenueCat. If you wish to confirm or request deletion of such information, please contact us using the contact information at the end of this Policy. However, some information may need to be retained for a certain period for purchase history, accounting, tax, fraud prevention, dispute resolution, or similar purposes.

Users in the European Economic Area or other regions with applicable data protection laws may also have rights to data portability, restriction of processing, objection to processing, and lodging a complaint with a supervisory authority, where such rights apply.

17. Changes to This Privacy Policy

The App may update this Privacy Policy as necessary.

Minor changes, typo corrections, and clarifications will become effective when posted on this page.

If there are material changes to user rights, purposes of data use, external recipients, third-party disclosure, retention periods, or similar matters, we will notify users through the App, website, App Store description, or another appropriate method.

18. Revision History

September 6, 2026 — Version 1.3 corrected the description of analytics controls to match the implementation and clarified optional Cloud Backup and cloud-account deletion.

August 22, 2026 — Version 1.2 added cloud backup, user-created card content, storage location, and deletion information.

July 29, 2026 — Version 1.1 added product analytics, crash diagnostics, and retention information.

June 8, 2026 — Version 1.0 created.

19. Contact

For questions about this Privacy Policy, the handling of user information, data deletion, access requests, or other privacy-related matters, please contact: Operator: Takuto Hizawa

Email: [email protected]