Legal
Privacy policy
- Effective date
- 28 June 2026
- Last updated
- 28 June 2026
Introduction
This Privacy Policy explains how www.lexipipsapp.com (“we”, “us”, “our”) collects, uses, stores, and protects personal information when users access our educational web application (the “Platform”).
Our Platform is designed for children and their parents or guardians.
We are committed to protecting children’s privacy and comply with:
- UK GDPR
- Data Protection Act 2018
- ICO Children’s Code (Age Appropriate Design Code)
Who Uses Our Platform
Our Platform is intended for children aged approximately 4–17 years old, under the supervision of a parent or legal guardian where appropriate.
Account registration requires a parent or guardian email address.
Parents are responsible for ensuring children use the Platform appropriately.
Information We Collect
We collect only the minimum personal data necessary to operate the Platform.
Parent / Guardian Information
We may collect:
- Email Address
- Account credentials
- Billing details (if and when the subscriptions are enabled)
Child Information
We may collect:
- First name or Nickname
- Age or School year
- Learning progress
- Lesson activity
- Submitted answers
We do not require children to provide surnames, addresses, or phone numbers.
User Generated Content
Children may submit content within learning exercises, including:
- Words
- Sentences
- Spelling answers
- Grammar exercises
- Writing practice
This content is considered user-generated content ("UGC").
UGC is processed only to provide educational feedback and improve user experience.
We strongly advise that children do not enter:
- Home addresses
- Phone numbers
- Personal contact details
- Sensitive personal information
AI Processing
We use AI-powered systems to support educational features such as:
- Spelling correction
- Grammar analysis
- Sentence validation
- Contextual word usage checks
Our AI functionality is restricted by design.
Children cannot use the Platform as a general-purpose AI chatbot.
The AI is not designed to:
- answer arbitrary prompts
- provide open-ended conversation
- generate unrestricted content
This reduces the risk of unsafe or inappropriate outputs.
Submitted text may be processed by AI service providers including OpenAI.
We configure AI systems to minimise data exposure wherever possible.
We do not intentionally submit sensitive personal information to AI providers.
How We Use Data
We use personal data to:
- create and manage accounts
- deliver educational features
- save progress
- provide AI feedback
- maintain security
- detect abuse or misuse
- support future subscription billing
- comply with legal obligations
We do not sell personal data.
We do not use behavioural advertising.
We do not use children’s data for profiling or manipulative engagement.
Legal Basis for Processing
Under UK GDPR, our lawful bases include:
Contract
To provide the Platform.
Lgeitimate Interests
To:
- secure systems
- prevent abuse
- improve reliability
Consent
Where required, including:
- parental consent for child access
- future marketing communications
Legal Obligation
Where required by law.
Parental Consent
Because our Platform is used by children, we rely on parental or guardian involvement during account creation.
A parent or guardian provides the registration email and accepts the Platform terms.
Parents may request:
- access to child data
- correction of inaccurate data
- deletion of data
- closure of the account
Data Sharing
We may share data only with trusted service providers such as:
- cloud hosting providers
- authentication providers
- payment processors
- AI providers
Examples may include:
- Amazon Web Services
- Stripe
- OpenAI
These providers process data under contractual safeguards.
We do not sell or rent personal data.
Security
We use appropriate security measures including:
- HTTPS encryption
- secure password storage
- access control
- secure infrastructure
- least-privilege access
- monitoring and logging
No online system is completely secure, but we work to protect personal data.
Data Retention
We keep data only as long as necessary.
Typical retention:
- active accounts: while active
- inactive accounts: up to 12 months
- security logs: up to 90 days
- billing records: as legally required
Data no longer needed is deleted or anonymised.
Children’s Safety
Child safety is a core design principle.
We apply:
- privacy by default
- minimal data collection
- no public profiles
- no chat features
- no targeted advertising
We may restrict or suspend accounts used in harmful or abusive ways.
Your Rights
Parents and eligible users may request:
- access
- correction
- deletion
- portability
- restriction
- objection
Requests can be made via: dutta.anuj@gmail.com
Future Subscription Services
If paid subscriptions are introduced, payment information may be processed by secure third-party payment processors.
We do not store full payment card details.
Changes to this Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated through the Platform or email.
Contact
Email: dutta.anuj@gmail.com