This is an archived version. It is the text of LEXUN’s Privacy Policy as published on 1 September 2026, kept unchanged so that anyone can see what the policy said on that date. It is not the policy in force. The current version is at lexun.co.uk/privacy. Only the words of the policy are preserved here; the surrounding page furniture is not part of the policy.

Skip to content

Archived: Privacy Policy

Last updated: 1 September 2026 · Written against the live codebase on this date
Changed since 13 August 2026: a sixth form — the organisations request form on the organisations, packages, pilot, Decision Audit and procurement pages — is added to section 3(h), the retention table and the processor list; nothing else about how data is handled has changed. Changed since 29 July 2026: the company number and registered office are published in full, and the dormant third-party analytics loader was deleted from the bundle. The 29 July version is kept unchanged at privacy-2026-07-29.
Plain-English summary: the decisions you analyse never leave your browser — there is no upload and no server copy of them. The only personal data we ever receive is an email address or a message you deliberately type into one of six forms: the waitlist, the quick contact form (your email and message), the full contact form (your name, email and what you wrote), the organisations request form on the organisations pages (your name, work email, organisation, role, team size, decision type, preferred next step and an optional message), the accuracy-record notification form on /accuracy (your email address), or the LEXUN Key sign-up on the dashboard (your email address and whether you ticked the marketing box). There is one exception to "nothing leaves your device", and we would rather you heard it here than found it later: the optional assistant on the dashboard sign-in screen sends the messages you type to Anthropic's API to produce its reply. Nothing else on this site does that, your decisions are never part of it, we keep no copy, and you never have to use it. It is set out in full in section 3(g). A LEXUN Key is not an account: your passcode is never sent to us, we cannot sign you in, and your decisions stay encrypted on your own device. Running a decision needs no Key; the dashboard asks for one at the point you save that decision to your record; /accuracy, /reproduce and /verify stay open to everyone with no account. Everything below tells you exactly what happens to those, how long we keep them, who else touches them, and how to make us delete them. We do not sell data, run advertising trackers or profile you. This policy describes only what the code actually does today; anything not yet built is labelled as such.

1. Who we are and how to reach us

This Privacy Policy explains how LEXUN ("LEXUN", "we", "us") handles personal data in connection with the website and application at lexun.co.uk (the "Service"). LEXUN is the data controller for that personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

Contact for any privacy matter, including a request to exercise your rights: privacy@lexun.co.uk. General contact: hello@lexun.co.uk.

Legal entity. LEXUN is a service of CA Capital Limited, a company registered at Companies House in the United Kingdom. CA Capital Limited is the data controller for the personal data described in this policy, which means it decides why and how that data is processed and is the organisation accountable to you and to the ICO for it. It is registered in England and Wales, company number 10848369, registered office 320 Firecrest Court, Centre Park, Warrington, United Kingdom, WA1 1RG — the record at Companies House. In practice the founder remains the only person who handles personal data. Legal notices should be sent to hello@lexun.co.uk.

ICO registration. Most UK organisations that process personal data must pay the ICO's annual data protection fee and appear on the ICO's public register of fee payers. CA Capital Limited's registration is not yet in place; it will be completed and the registration number published here at that point. We are not claiming an exemption, and we are not going to print a number we do not hold. Nothing about that pending status limits your rights below or your right to complain to the ICO today.

2. What the Service does by default: your decisions never leave your device

The decision engine runs entirely in your browser. The questions you type, the assumptions and figures you enter, the simulated probabilities the engine produces, the outcomes you later report and your personal track record are written to your browser's own local storage on your own device. They are not transmitted to us, we hold no copy, and we could not produce them if we were asked to.

This is a design constraint, not a promise about intent: there is no account system, no upload endpoint and no decision database. A consequence worth stating plainly is that we cannot recover your data for you — if you clear your browser storage, that data is gone. Export before you clear.

The LEXUN Key does not change any of that. The dashboard asks you to create a Key before it will save a decision, and before it will show you your saved record. That Key is a passcode which encrypts the record on your own device with AES-256-GCM, under a key derived from your passcode by PBKDF2-HMAC-SHA256 at 600,000 iterations. The passcode is never transmitted, never stored and never recoverable — there is no reset link because there is nobody on our side to reset anything. The only thing that leaves your device when you create a Key is the email address you type in, plus a yes/no marketing choice, and that is described in section 3(b) below. Running a decision works without a Key — see the next paragraph.

Where the Key is asked for, and how that line has moved. You can frame and run a full decision with no Key: the engine writes nothing while it runs, so there is nothing to encrypt. The Key is asked for at the moment you press save, because that is the first action that puts a decision into storage, and a record saved without a Key would sit in your browser unencrypted. Between 30 July and 5 August 2026 a Key was required to run a decision as well. Both changes are recorded here rather than quietly deleted, because the first reversed something this page had promised and the second reversed the first. What did not change across either is the architecture: the maths has always happened entirely in your browser, and nothing about your decision has ever been transmitted. And the pages that let you check our claims without taking our word for anything — accuracy, reproduce, verify and trust — remain open to everyone with no Key, no email and no account, because a claim you cannot check is not a claim.

The one exception to "nothing leaves your device": the assistant. The dashboard's sign-in screen carries a small text assistant that helps turn a vague worry into a question the engine can actually score. It is the only feature on this site that transmits anything you type. When you send it a message, that message and the assistant's previous replies in the same conversation are sent to Anthropic PBC, whose model produces the reply. Nothing else goes with them: not your email, not your Key, not your passcode, not your encrypted record, not any decision, figure, assumption or result. We do not store the conversation — it is held in your browser's memory for the length of the visit and is gone when you close the tab — and we do not write it to any database, log or file of ours. It is described in section 3(g) below, and the assistant itself carries the same warning above the text box, before you type. If you would rather nothing at all left your device, do not use it: every other part of LEXUN works without it.

Every key we write, what it holds and how to delete it is listed in full on the Cookies & local storage page, which also carries a control that erases all of it in two clicks. There are no cookies of any kind on this site.

3. The personal data we actually receive

There are exactly seven ways personal data can reach us or a processor acting for us. Nothing else on this site collects anything.

a) The waitlist form

If you submit the form at /join we receive the email address you type, and nothing else. We use it to email you when a named feature ships (sync, exports, reminders). We do not add it to any other list, and every email carries a one-click unsubscribe.

b) The LEXUN Key sign-up

When you create a LEXUN Key on the dashboard we receive two things: the email address you type, and whether you ticked the marketing box (recorded literally as "yes" or "no"). That is the entire transmission. Specifically, we do not receive your passcode, any key derived from it, the encrypted record, or anything you have analysed — the browser sends the email address and the marketing flag and nothing else, which you can confirm in your browser's network inspector.

The email address is held so that we can reach you about the Key itself: to warn you before anything changes that could affect a locally encrypted record, and to answer you if you contact us about it. We will only send you product or launch marketing if you ticked the box, and the box is never pre-ticked. You can withdraw that consent at any time using the unsubscribe link in any email or by emailing privacy@lexun.co.uk, and withdrawing it does not disable your Key or touch your data — the two are unconnected, because there is no account linking them.

If the sign-up request fails (you were offline, for example) your browser keeps the email address and the marketing choice in local storage and tries once on your next visit, then deletes them whether or not that retry worked. It is not a queue that holds your email address indefinitely. The key it uses is listed on the cookies page.

Because your Key is not an account, deleting your email address from our side is straightforward and has no side effects: email privacy@lexun.co.uk from the address in question, or ask from any address and tell us which one to remove, and we will delete it from the form store and from the mailing list. Your decisions are unaffected either way, since we never had them. To erase the encrypted record itself, use "Delete all data" in the dashboard's Settings, or the erase control on the cookies page — both act only on your device.

c) The contact form

If you submit the form at /contact we receive the fields you complete: first name, last name, work email, job title, company, team or function, company size, what you want to analyse, how you decide today, and your free-text message. We use these solely to answer you. Only first name, last name and email are required; the rest you may leave blank and the form will still send.

d) Email you send us

If you email hello@ or privacy@lexun.co.uk we hold that correspondence in our mailbox in order to reply, and to keep a record of requests we are obliged to log — for example a rights request under section 10 below.

e) Server request logs

Our hosting provider records standard web-server information when a page is requested — IP address, timestamp, the URL requested, user-agent and referrer — for security, abuse prevention and availability. These logs sit with the host under its own retention policy. We do not copy them into any analytics tool, join them to anything else, or use them to identify individuals.

f) Payments — not yet active

When paid plans launch, card details will be handled entirely by Stripe and will never reach us or be visible to us. At the date above no payment processing is live: the payment links on the pricing page are empty and no payment has ever been taken. This paragraph is here so the disclosure is ready, not because it is operating.

g) The assistant on the dashboard sign-in screen

The sign-in screen at /platform carries a text assistant. It is optional, it is the only feature on LEXUN that transmits anything you type, and it says so above its own text box before you use it.

What is sent. The message you type, plus the earlier messages and replies in that same conversation so the assistant can follow the thread. They go to Anthropic PBC (San Francisco, USA), which runs the model that writes the reply, acting as our processor. What is not sent: your email address, your Key, your passcode, your encrypted record, and any decision, figure, assumption, simulation or result — none of these are available to that request, and you can confirm it in your browser's network inspector.

What is kept. By us: nothing. The conversation lives in your browser's memory for the length of the visit and is discarded when you close or reload the tab; it is never written to your device's storage, to our forms store, or to any log of ours. The only thing our server records is that a request happened and how long it took — not its contents. By Anthropic: their API terms provide that inputs and outputs submitted through it are not used to train their models, and they retain them only briefly for abuse monitoring. We link to their terms in section 8.

Because you can type anything into a free-text box, treat it like an email to a stranger: do not paste bank details, passwords, medical information or anyone else's personal data into it. The assistant is instructed to refuse financial, legal, medical and investment advice and never to invent a figure, but it is a language model and it can still be wrong — the numbers on LEXUN come from the engine, which is reproducible, not from the assistant, which is not.

A count of how many free messages you have used is kept in your own browser (lexunp.ask.count.v1) and nowhere else. It is not sent to us, and it identifies nothing about you.

What we do not have. No analytics or measurement provider — the site ships an analytics loader that is disabled in code with an empty domain, so it makes no external request and never runs. No advertising or cross-site tracking. No third-party scripts, fonts, pixels, embeds or CDNs of any kind: every asset on this site is served from lexun.co.uk. No data broker relationships. No sale or rental of personal data, ever, including in an insolvency.

h) The organisations request form

If you submit the request form on /organisations, /packages, /pilot, /decision-audit or /procurement we receive the fields you complete: your name, work email, organisation, role, team size, the type of decision you have in mind, your preferred next step, an optional message, and your consent tick. The form also records which page and button it was sent from, the page that referred you, and any campaign (utm) codes in the address you arrived on, so we know which route brought the request; it never records anything about a decision you may have analysed. The same answers are packaged into a single structured field so the request can be moved into a customer-relationship tool without retyping; no such tool is connected today — requests sit in the hosting provider’s form store and are read by the founder. We use these details solely to respond to the request you chose. Submitting the form books nothing: a pilot, an audit or a call starts only when we have confirmed it with you in writing. To have a request deleted, email privacy@lexun.co.uk; it is removed from the form store within 30 days and confirmed to you.

4. Our lawful bases for processing

UK GDPR Article 6 requires a lawful basis for every processing activity. Ours are:

Every processing activity we carry out, and the Article 6 basis it relies on.
WhatPurposeLawful basis
Waitlist emailEmailing you when a feature shipsConsent — Article 6(1)(a). You give it by submitting the form having read the wording beside the button; you can withdraw it at any time via the unsubscribe link or by emailing us. Regulation 22 of the Privacy and Electronic Communications Regulations 2003 also requires consent for this kind of email, which is why the waitlist is opt-in and never pre-ticked.
LEXUN Key sign-up emailContacting you about the Key itself — chiefly to warn you before a change that could affect a locally encrypted recordLegitimate interests — Article 6(1)(f): telling someone who has encrypted data under our software about a change that could cost them that data. We have weighed your interests: it is one address, given deliberately, used for a message you would want to receive, and removable on request in one email.
LEXUN Key marketing boxSending you product and launch emailConsent — Article 6(1)(a), and Regulation 22 PECR. The box is unticked when the page loads and the Key is created whether or not you tick it, so ticking it is a positive act. Withdrawable at any time under Article 7(3) via unsubscribe or email, without affecting your Key or your data.
Contact formAnswering the enquiry you sentLegitimate interests — Article 6(1)(f): replying to someone who has deliberately contacted us. Where your enquiry concerns taking a plan, Article 6(1)(b) — steps at your request prior to a contract — also applies.
Email correspondenceReplying, and logging rights requestsLegitimate interests — Article 6(1)(f) for replies; legal obligation — Article 6(1)(c) for the record of a rights request or a breach.
Server logsSecurity, abuse prevention, availabilityLegitimate interests — Article 6(1)(f). We have weighed your interests: the data is transient, is not used to identify anyone, and no service can be operated safely without it.
Assistant messagesSending what you type to Anthropic's API so a reply can be produced, and only thatLegitimate interests — Article 6(1)(f): delivering the feature you have just deliberately used, in the only way it can be delivered. We have weighed your interests: the assistant is optional, it warns you before you type, it is not used for anything except answering you, no copy is kept by us, and you can simply not use it without losing any other part of the Service. If you object under Article 21, the answer is immediate — stop using the box, and there is nothing left to object to.
Local storage on your deviceMaking the application work and remembering your preferencesNo Article 6 basis is engaged, because none of it reaches us. The separate Regulation 6 PECR question of storing information on your device is dealt with on the cookies page.
Payments (when live)Taking payment; keeping tax recordsContract — Article 6(1)(b); and legal obligation — Article 6(1)(c) for the retention of financial records.

Where we rely on legitimate interests you have the right to object under Article 21, and we will stop unless we can demonstrate compelling grounds that override your rights. Where we rely on consent you can withdraw it at any time under Article 7(3), which does not affect processing already carried out.

5. Special category and criminal offence data

We do not ask for, and have no use for, the special categories of data listed in Article 9 — health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation — or criminal offence data under Article 10.

The free-text boxes on the contact form will accept whatever you type. Please do not put special category data in them. If you do, we will use it only to answer you and will delete it as soon as that is done. If your enquiry genuinely requires it, email us first and we will agree a safer route.

The same applies inside the application, with one difference that works in your favour: text you type into the decision engine never reaches us at all, so it cannot be disclosed by us even in error.

6. Automated decision-making and profiling (Article 22)

Article 22 gives you the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. A product that produces probabilities should be explicit about where it stands, so:

  • LEXUN's engine runs a simulation over figures you supply and returns a probability band for you to act on. It does not make any decision about you: it does not score you, rank you, grant or refuse you anything, price anything by reference to you, or pass a judgement about you to anyone.
  • It produces no legal effects and nothing similarly significant in the Article 22 sense. The consequential decision is always yours, taken by you, after reading the output.
  • We do not profile you. There is no behavioural model of any user, because there is no user record — the engine has no memory of anyone beyond the browser it is running in.
  • The processing happens in your browser, on your device, on data we never receive.

Even though Article 22 is not engaged, we have built the safeguards it contemplates anyway, because they are the point of the product: every output states its drivers and assumptions, labels what is fact and what is assumed, shows the random seed and the model version, and links to a reproduction of the same run. If a result looks wrong to you, you can see why it came out that way and challenge it — and you can email privacy@lexun.co.uk to have a human explain it.

7. How long we keep things

Retention periods. Where a period depends on a third party's own policy we say so, rather than inventing a number.
DataKept for
Waitlist emailUntil you unsubscribe or ask us to delete it, or 24 months after the last launch email we send you — whichever comes first. Then deleted from the form store and the mailing list.
LEXUN Key sign-up emailUntil you ask us to delete it, or 24 months after the last email we send you — whichever comes first. Deleting it does not lock, unlock or erase anything on your device, because nothing on our side is joined to it.
Failed sign-up held on your deviceUntil the single retry on your next visit, then deleted from your browser whether or not the retry succeeded.
Contact submission24 months from our last correspondence with you, then deleted. Sooner on request, unless we need it for a legal claim.
Organisations request24 months from our last correspondence with you, then deleted; where the request leads to a contract, for the life of the contract and six years after it ends, as UK law on business records requires. Sooner on request where no contract exists.
Email correspondence24 months from the last message in the thread. Records of rights requests and of any breach are kept longer, where we are obliged to be able to demonstrate compliance.
Server logsHeld by the hosting provider under its own retention policy. We do not extend it, export the logs, or retain a separate copy.
Assistant conversationNot kept by us at all. It is held in your browser's memory for the length of the visit and is discarded when you close or reload the tab. It is never written to your device's storage or to any store of ours. Anthropic retains inputs and outputs only for the limited period set out in its own policy for abuse monitoring; we do not extend that and hold no copy.
Assistant free-message countUntil you clear your browser data. It is a single number in your own browser, never transmitted, and identifies nothing.
Data on your deviceUntil you erase it. Nothing expires it for you, and nothing on our side can reach it. See the cookies page for the erase control.
Payment records (when live)Six years from the end of the financial year they relate to, as UK tax law requires.

8. Who else processes your data

We use a small number of processors. Each acts on our documented instructions under a contract meeting Article 28 UK GDPR. This is the complete list at the date above.

Processors and recipients. Nobody else receives personal data from us.
WhoWhat they doWhere
Netlify, Inc.Hosts the site and its CDN; receives and stores submissions from the waitlist form, both contact forms, the organisations request form, the accuracy-record notification form and the LEXUN Key sign-up; keeps the server request logsUnited States
Mailbox providerDelivers and stores email sent to and from our @lexun.co.uk addressesNamed on request
Anthropic PBCRuns the model behind the optional assistant on the dashboard sign-in screen. Receives the messages you type into that box and the replies in the same conversation, and nothing else — no email address, no Key, no passcode, no decision data. Used only to produce the reply. Under its API terms, inputs and outputs are not used to train its models.United States
Stripe (not yet active)Will process card payments when paid plans launch. No payment has been taken and no payment data exists.United States / Ireland

We do not use an analytics provider, an advertising network, a customer-data platform or a chat widget. We do use one AI vendor, Anthropic, and only for the assistant described in section 3(g) — it receives what you type into that one box and never receives your decision data, which does not leave your device for any purpose. We may disclose personal data where we are legally required to — for example in response to a valid court order — and we will tell you when that happens unless we are prohibited from doing so.

9. International transfers

Our hosting provider is headquartered in the United States, so form submissions and server logs may be processed outside the UK. The same is true of the assistant: messages typed into it are sent to Anthropic PBC in the United States. Where that happens we rely on the transfer safeguards permitted by Article 46 UK GDPR — the ICO's International Data Transfer Agreement, or the ICO's Addendum to the EU Standard Contractual Clauses — and, where it applies to the recipient, the UK Extension to the EU–US Data Privacy Framework. You can ask us which mechanism is relied on for any specific transfer and we will tell you.

None of this applies to your decision data, which is not transferred anywhere, because it never leaves your device.

10. Your rights

Under UK GDPR and the DPA 2018 you have the following rights over personal data we hold about you. Where the data is on your device you can exercise most of them yourself, immediately, without asking us.

Your rights, and the fastest route to using each one.
RightWhat it meansHow to use it
Access
Art 15
A copy of your personal data, and information about how it is usedEmail us; or for on-device data, export it yourself from the app
Rectification
Art 16
Correction of data that is inaccurate or incompleteEmail us; on-device data you can edit directly
Erasure
Art 17
Deletion of your data, where we have no overriding reason to keep itEmail us; or erase everything on your device from the cookies page
Restriction
Art 18
Freezing our use of your data while a dispute about it is resolvedEmail us
Portability
Art 20
Your data in a structured, machine-readable formatExport from the app as JSON; email us for form data
Object
Art 21
Objecting to processing based on legitimate interestsEmail us, telling us what you object to
Object to marketing
Art 21(2)
An absolute right to stop direct marketing — we cannot refuse it or ask you to justify itUnsubscribe link in any email, or email us
Withdraw consent
Art 7(3)
Withdrawing consent as easily as you gave itUnsubscribe link, or email us
Automated decisions
Art 22
Not being subject to solely automated decisions with legal or similar effectsSee section 6 — we make none. Ask us anyway if you want that in writing
Complain
Art 77
Complaining to the ICO, whether or not you have complained to us firstSee section 16

How we handle a request. Email privacy@lexun.co.uk. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months under Article 12(3), and we will tell you within the first month if we do, and why. There is no charge. We will ask for proof of identity only where we have a real doubt about who you are, and only so far as that is proportionate — we will not use an identity check to slow you down. If we refuse a request we will tell you why, and tell you that you can complain to the ICO and seek a judicial remedy.

11. Security

We take technical and organisational measures appropriate to the risk (Article 32). Rather than assert good practice in the abstract, here is what is actually in place and independently checkable:

  • The site is served only over HTTPS, with HTTP Strict Transport Security, so a browser will not fall back to an unencrypted connection.
  • A Content-Security-Policy is enforced, alongside X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy. You can verify these in your browser's network panel or with any public header scanner.
  • There is no server-side store of decision data to breach, because there is no server-side store of decision data.
  • No third-party script runs on this site, so there is no supply-chain route into your session. Fonts are self-hosted for the same reason.
  • Form submissions and email are held by the providers named in section 8, protected by their own controls and by multi-factor authentication on our accounts.

No system is perfectly secure, and we will not pretend otherwise. If you believe you have found a vulnerability, please tell us at privacy@lexun.co.uk before disclosing it publicly, and we will work with you.

12. Children

The Service is not directed at children. Under section 9 of the DPA 2018 the age at which a child can consent to an online service in the UK is 13, and we do not knowingly collect personal data from anyone under that age. If you believe a child has sent us personal data, email privacy@lexun.co.uk and we will delete it.

13. If something goes wrong: personal data breaches

If a personal data breach occurs we will assess it immediately. Where it is likely to result in a risk to your rights and freedoms we will report it to the ICO within 72 hours of becoming aware of it (Article 33). Where it is likely to result in a high risk to you we will also tell you directly, without undue delay and in plain language, along with what we are doing about it and what you should do (Article 34). We keep a record of every breach, including those we decide are not reportable, and our reasons.

14. Data Protection Officer

We have not appointed a Data Protection Officer, and we are not required to: we are not a public authority, and our core activities do not consist of large-scale regular and systematic monitoring, or large-scale processing of special category data. Privacy requests are handled by the founder, reachable at privacy@lexun.co.uk. If that position changes, this section changes with it.

15. If you are outside the UK

The Service is offered from, and aimed at, the United Kingdom. We have not appointed a representative in the EU under Article 27 of the EU GDPR, because we do not target the EU market or monitor behaviour there. You are welcome to use the Service from anywhere — the engine runs in your browser regardless — but this policy is written to UK law, and if you contact us from the EU we will handle your request to the same standard set out above.

16. Complaints, and the ICO

If you are unhappy with how we have handled your personal data or a request, tell us first at privacy@lexun.co.uk — we would rather fix it than have you chase it. But you do not have to come to us first, and nothing in this policy requires you to. You have the right under Article 77 to complain directly to the UK's supervisory authority at any time:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113 · ico.org.uk

You may also seek a remedy through the courts.

17. Changes to this policy

We will update this policy when what we do changes. The honest version of that promise is a specific one: this policy is re-read against the codebase whenever a release changes what data is collected, stored or sent, and the date at the top records when that last happened. If a change materially affects your rights we will say so prominently rather than quietly moving the date. Previous versions are available on request.

Related pages: Cookies & local storage — every key this site writes to your device, why, and a control that erases them. Terms — the contract, including your consumer rights. Security — the technical detail behind section 11.

Archived by LEXUN · CA Capital Limited, registered in England and Wales, company number 10848369. Current Privacy Policy · lexun.co.uk