Lexiara — Privacy Notice
Last updated: 1 September 2026 (analytics processor added)
Who we are
Lexiara is operated by Taliara Limited, a company registered in England and Wales (company number 17228820), registered office 167-169 Great Portland Street, London, W1W 5PF — the controller of the personal data described here. Contact: in writing to the registered office.
What we collect, and why
We collect only what operating a metered API and understanding aggregate use of the Service require:
- Account details — the name and email address associated with an API key. Basis: performance of our contract with you.
- Sign-in profile — if you sign in with Google or Microsoft, we receive and store the account identifier that provider gives us, your email address and your display name. We never receive your password. That account identifier (not your email) is what identifies you to us, so changing your email address does not create a second account. You may add a second sign-in method to an account you are already signed in to; we never join two accounts together because they share an email address. Basis: performance of our contract with you.
- Connected applications — if you authorise an application (for example a Claude or ChatGPT connector) to read Lexiara on your behalf, we record which application it is, when you connected it and when it last read, so that you can see and end the connection from your account. Requests it makes are metered against your allowance exactly as your own browsing is. Basis: performance of our contract with you.
- Credentials — a cryptographic hash of your API key. We cannot recover the key itself. Basis: our legitimate interest in securing the Service.
- Usage records — per-key request counts by endpoint and period, used for quotas, rate limits and (where applicable) billing. Basis: performance of the contract, and our legitimate interest in metering and abuse prevention.
- Preview records — if you use the Service without signing in, we store a random identifier in a cookie, a count of the requests made against it, and a salted one-way hash of your IP address. The hash lets us cap how many preview sessions one origin may start per hour; it is not reversible into an address, and we hold no IP address in the clear for this purpose. The same salted hash appears in the traffic analytics described below, for the same purposes of abuse prevention and aggregate measurement. Basis: our legitimate interest in preventing scraping and in keeping the free preview available to everyone.
- Traffic analytics — for each request we record a classification of the client (crawler, browser, preview visitor, signed-in user, API key), the country and network it arrived from (the autonomous system number and its operator's name), the user-agent string your software sends, the response status, and a salted one-way hash of your IP address. For requests made while signed in or with an API key, we also record a pseudonym derived from your account — never your email, your name or the key itself. This is how we tell a crawler enumerating the corpus from a person reading it, and which legislation people are actually interested in. It is held by Cloudflare Workers Analytics Engine for approximately 90 days and then discarded; beyond that we keep only aggregate daily counts of reads per provision by client class, which identify nobody.
- Search text, only when a search finds nothing. When a search returns no result we record the words you searched for, so that we can see what the corpus is missing and go and get it. This is kept in the same Cloudflare Workers Analytics Engine store for approximately 90 days and then discarded, and it is not sent to PostHog or to any other third party. **When a search succeeds we do not record what you typed at all** — only its length, how many terms it had, and whether it looked like a reference to a numbered provision. We record no search text of any kind against your account or your IP hash in a way that would let us reassemble one person's searches. Basis: our legitimate interest in knowing which law our users need and we do not yet hold.
- What we send to PostHog. The per-request record above — **excluding requests we classify as crawlers, which are not sent at all, excluding the words of any search, and excluding the content of any request body** — is also sent to PostHog, an analytics service hosted in the EU acting as our processor, where we view it as charts and, for requests made while signed in or with an API key, as a timeline under the pseudonym described above. We review that copy and prune it at least annually. **No cookie is involved: the preview cookie is never read for analytics**, so an anonymous reader is measured by class, origin and software, and by nothing that follows them between visits. Basis: our legitimate interest in operating, securing and improving the Service.
- **Why a malformed request still tells us something, without telling us what it said.** When a request to our machine interface cannot be read at all, we record how long it was, the content type it declared, and which of a fixed list of shapes it had — empty, whitespace, a byte-order mark, truncated JSON, markup, form-encoded, or other text. We do not record any part of the body itself. Basis: our legitimate interest in diagnosing clients that cannot reach the Service.
- Server logs — transient operational logs (including IP addresses) kept by our hosting infrastructure for security and debugging, distinct from the traffic analytics above. Basis: legitimate interest in running a secure service.
We do not sell personal data, use it for advertising, or use it to train machine-learning models. The legislative texts the Service serves are public documents and contain no data about you.
Cookies
The Service sets three cookies, all of them strictly necessary to provide what you asked for. **We set no analytics, advertising or tracking cookies, and no third party sets cookies through the Service.**
- lx_session — keeps you signed in. Expires after 30 days, or immediately when you sign out.
- lx_visitor — identifies your free preview and how much of it remains, so one visitor's use does not exhaust another's. Expires after 180 days.
- lx_oauth — holds the security values for a sign-in in progress. Expires after 10 minutes.
All three are HttpOnly (scripts on the page cannot read them), SameSite=Lax and, over https, Secure. Each contains a random identifier only: no personal data is stored in the cookie itself. The traffic analytics described above are measured without cookies, and lx_visitor is never read for that purpose — it meters your preview and nothing else.
Where it lives
The Service runs on Cloudflare (edge) with data stored on Neon (PostgreSQL, EU region). Both act as our processors; the traffic analytics described above live in Cloudflare's Workers Analytics Engine and, for requests we do not classify as crawlers, in PostHog (hosted in the EU), also our processor. If you subscribe to a paid plan, payment is processed by Stripe as our processor — we never see or store your card number. If you choose to sign in with Google or Microsoft, that sign-in is handled by that provider, whose own privacy notice governs it; we disclose to them only that a sign-in was requested. We use no third-party identity or authentication vendor beyond the provider you chose. Requests reaching the Cloudflare edge may transit outside the UK/EEA; contractual safeguards (including standard contractual clauses in those providers' terms) apply.
How long we keep it
Account details and usage records: for the life of the key and up to 24 months after revocation, for billing and audit. Sign-in profiles: until you ask us to delete the account. Preview records (identifier, request count and hashed IP): up to 180 days from last use. Traffic analytics: approximately 90 days, after which only aggregate daily counts by client class remain, and those identify nobody. The copy held in PostHog is reviewed and pruned at least annually. Operational logs: short rotation set by the infrastructure provider.
Your rights
UK GDPR gives you rights of access, rectification, erasure, restriction, portability and objection. Write to the registered office to exercise them. You may complain to the Information Commissioner's Office (ico.org.uk).
Changes
We will notify key holders of material changes to this notice, and the version served at lexiara.org/privacy is the current one.