Legal

Privacy policy

Effective date
28 June 2026
Last updated
28 June 2026

Introduction

This Privacy Policy explains how www.lexipipsapp.com (“we”, “us”, “our”) collects, uses, stores, and protects personal information when users access our educational web application (the “Platform”).

Our Platform is designed for children and their parents or guardians.

We are committed to protecting children’s privacy and comply with:

  • UK GDPR
  • Data Protection Act 2018
  • ICO Children’s Code (Age Appropriate Design Code)

Who Uses Our Platform

Our Platform is intended for children aged approximately 4–17 years old, under the supervision of a parent or legal guardian where appropriate.

Account registration requires a parent or guardian email address.

Parents are responsible for ensuring children use the Platform appropriately.

Information We Collect

We collect only the minimum personal data necessary to operate the Platform.

Parent / Guardian Information

We may collect:

  • Email Address
  • Account credentials
  • Billing details (if and when the subscriptions are enabled)

Child Information

We may collect:

  • First name or Nickname
  • Age or School year
  • Learning progress
  • Lesson activity
  • Submitted answers

We do not require children to provide surnames, addresses, or phone numbers.

User Generated Content

Children may submit content within learning exercises, including:

  • Words
  • Sentences
  • Spelling answers
  • Grammar exercises
  • Writing practice

This content is considered user-generated content ("UGC").

UGC is processed only to provide educational feedback and improve user experience.

We strongly advise that children do not enter:

  • Home addresses
  • Phone numbers
  • Personal contact details
  • Sensitive personal information

AI Processing

We use AI-powered systems to support educational features such as:

  • Spelling correction
  • Grammar analysis
  • Sentence validation
  • Contextual word usage checks

Our AI functionality is restricted by design.

Children cannot use the Platform as a general-purpose AI chatbot.

The AI is not designed to:

  • answer arbitrary prompts
  • provide open-ended conversation
  • generate unrestricted content

This reduces the risk of unsafe or inappropriate outputs.

Submitted text may be processed by AI service providers including OpenAI.

We configure AI systems to minimise data exposure wherever possible.

We do not intentionally submit sensitive personal information to AI providers.

How We Use Data

We use personal data to:

  • create and manage accounts
  • deliver educational features
  • save progress
  • provide AI feedback
  • maintain security
  • detect abuse or misuse
  • support future subscription billing
  • comply with legal obligations

We do not sell personal data.

We do not use behavioural advertising.

We do not use children’s data for profiling or manipulative engagement.

Legal Basis for Processing

Under UK GDPR, our lawful bases include:

Contract

To provide the Platform.

Lgeitimate Interests

To:

  • secure systems
  • prevent abuse
  • improve reliability

Consent

Where required, including:

  • parental consent for child access
  • future marketing communications

Legal Obligation

Where required by law.

Parental Consent

Because our Platform is used by children, we rely on parental or guardian involvement during account creation.

A parent or guardian provides the registration email and accepts the Platform terms.

Parents may request:

  • access to child data
  • correction of inaccurate data
  • deletion of data
  • closure of the account

Data Sharing

We may share data only with trusted service providers such as:

  • cloud hosting providers
  • authentication providers
  • payment processors
  • AI providers

Examples may include:

  • Amazon Web Services
  • Stripe
  • OpenAI

These providers process data under contractual safeguards.

We do not sell or rent personal data.

Security

We use appropriate security measures including:

  • HTTPS encryption
  • secure password storage
  • access control
  • secure infrastructure
  • least-privilege access
  • monitoring and logging

No online system is completely secure, but we work to protect personal data.

Data Retention

We keep data only as long as necessary.

Typical retention:

  • active accounts: while active
  • inactive accounts: up to 12 months
  • security logs: up to 90 days
  • billing records: as legally required

Data no longer needed is deleted or anonymised.

Children’s Safety

Child safety is a core design principle.

We apply:

  • privacy by default
  • minimal data collection
  • no public profiles
  • no chat features
  • no targeted advertising

We may restrict or suspend accounts used in harmful or abusive ways.

Your Rights

Parents and eligible users may request:

  • access
  • correction
  • deletion
  • portability
  • restriction
  • objection

Requests can be made via: dutta.anuj@gmail.com

Future Subscription Services

If paid subscriptions are introduced, payment information may be processed by secure third-party payment processors.

We do not store full payment card details.

Changes to this Policy

We may update this Privacy Policy from time to time.

Material changes will be communicated through the Platform or email.

Contact