Privacy Policy

Effective 20 July 2026

Lexcade uses account and learning data to provide synced language practice across the web and iOS app. We do not sell personal data or use it for behavioral advertising.

Data we process

Purposes and legal bases

We process account, learning, preference, and social data because it is necessary to provide the Lexcade service you request, including authentication, synchronization, adaptive practice, progress views, recovery, and account controls. We process limited security and operational data for our legitimate interests in preventing abuse, protecting accounts, diagnosing faults, and keeping the service available. Those interests must not override your rights and freedoms.

Advertising and analytics

The current Lexcade release does not include advertising SDKs, tracking SDKs, or third-party behavioral analytics. If that changes, this policy and the relevant consent controls will be updated before release.

Sharing and processors

We do not sell personal data. Service infrastructure processes data only to operate Lexcade. The final production processor list, hosting provider, and processing region are release requirements and will be published here before public App Store distribution.

Storage and security

Passwords and recovery codes are stored as salted hashes. The only record made when you confirm saving recovery codes is a timestamp, not a code or copy of a code. Network requests use TLS. Native session tokens are stored in the iOS Keychain. Exported files never contain password hashes, raw session tokens, or recovery-code hashes. Access to server data is restricted to service operation and support. No internet service can guarantee absolute security.

Retention and deletion

Account and learning records are retained while your account exists. Sessions expire after 30 days unless securely renewed through use. Recovery-code records remain until a code is used, the set is replaced, or the account is deleted. The recovery-code saving confirmation remains until the account is deleted. You can delete the account from Settings after confirming your password; this removes the active profile, learning records, friendships, recovery records, confirmation timestamp, and sessions. Access-restricted operational logs and backups may retain a copy for a limited period. The final production log and backup retention windows must be published here before public App Store distribution.

Download your data

Open Settings and choose Download my data to receive a portable JSON file containing your profile, onboarding timestamps, sanitized security metadata including recovery-code confirmation timing, learning history and state, preferences, daily activity, and friendships. Authentication secrets are deliberately excluded. Operational logs are not part of this self-service file; contact support for a broader access request.

Children

Lexcade is not directed to children under the minimum digital-consent age that applies in their country. A parent or guardian can contact support about an account created by a child.

Your rights

Depending on applicable law, you may request access, rectification, erasure, restriction of processing, data portability, or object to processing based on legitimate interests. You may also lodge a complaint with the supervisory authority where you live or work. In the Netherlands, this is the Dutch Data Protection Authority; the European Data Protection Board lists other EU authorities.

We aim to answer a valid request without undue delay and generally within one month. We may need to verify that the requester controls the account. Support will never ask for a password, session token, or recovery code.

Controller and contact

The final legal name and postal address of the Lexcade controller are a release requirement and will be added before public App Store distribution. For current privacy or support requests, email support@e-cormerce.com or visit the support page.