Security and privacy at Lexy
What Lexy collects when someone plays, what you see, and how accounts, widgets, scores and payments are protected.
When you put Lexy on your pages, your readers' trust comes with it. This page explains what Lexy collects when someone plays, what you see, what never leaves Lexy, and how accounts, widgets and scores are protected.
For the full legal terms, see the Privacy Policy and Terms of Service.
What your readers share
Anyone can play a Lexy game without an account, a sign-up form or a consent screen. A play records the game, the answers, the score, the page it was played on, and the kind of device. That is what powers your stats.
- Readers stay anonymous to you. In My Players and the CSV export, each player is an anonymous player number. You never see a reader's name, email address or phone number, even when they're signed in to a Lexy account.
- No third-party cookies. Lexy's widget sets no cookies on your pages and doesn't track readers from site to site.
- No ad tracking in your widgets. Lexy's own site analytics runs only on lexy.fm, never inside the widget on your pages.
- Your analytics get no personal data. The game events the widget sends to your page describe the game, never the person.
- Lexy doesn't sell personal information. It isn't used to market anyone else's products.
Reader accounts
Readers can sign in from a widget with a free Lexy account, to keep their scores. See Let readers sign in on your site.
- Your page never handles the sign-in. Sign-in happens in Lexy's own window, or in Lexy's own frame on your page. The key that keeps a reader signed in is stored where only Lexy's frame can read it, so scripts on your page can't see it.
- Sign-in is limited for safety:
- In apps, readers sign in with a six-digit code sent by email. A code works once, for 10 minutes, and allows five tries.
- Sign-in with Google, Apple and Microsoft checks each provider's identity token, and joins an existing account only when the provider confirms the email address.
- Passwords are never stored. Lexy keeps only a hashed form of each password, salted and hashed many times over, for readers and publishers alike. A password reset link works once and expires after an hour, and the reset page never says whether an email address has an account.
- Repeated attempts are slowed down. Signing in, signing up, password resets and email codes are limited per connection and per address, to stop guessing.
Phone calls and texts
- Consent comes first. Before Lexy calls a reader on a schedule, they verify their number with a code and agree to the exact wording of that call program. Lexy stores the sentence they agreed to, word for word, with when they agreed.
- STOP works. Replying STOP to a Lexy text withdraws that number's consent and stops Lexy's scheduled calls to it, until it replies START.
- Answers on a call are recorded by Lexy's phone provider, turned into text, and matched to the answer options. See the Privacy Policy for how long recordings are kept.
Answering out loud on the web
When a reader answers out loud in their browser, the browser's own speech recognition turns their voice into words. Lexy receives the words, never the audio. When Lexy needs help matching the words to an answer option, it sends them, with the question and its options, to an AI model.
Your widgets
- Lock a widget to your sites. Add your domains under Allowed Domains, and the widget shows only on those sites and their subdomains. Copied onto any other site, it doesn't display. See Match the widget to your site.
- The widget only listens to Lexy. It ignores messages from anything that isn't Lexy, and sends a reader's sign-in only to Lexy's own pages.
- No outside code. The widget loads its code from Lexy alone, not from other companies' servers.
Scores you can trust
In online play, Lexy's server decides whether each answer is right and signs the running score, so a reader can't change their score in the browser. A signed score works for one play and expires after a day.
Payments
Card details go straight from your browser to Stripe, Lexy's payment provider. Card numbers never pass through or are stored on Lexy's servers.
Connections
Every Lexy page and widget is served over HTTPS, and browsers are told to use HTTPS only.
Services Lexy uses
Lexy relies on these companies to run the service. Each gets only what its job needs.
| Service | What it does | What it receives |
|---|---|---|
| Twilio | Phone calls and texts | Phone numbers, and the recording of answers on a call |
| Deepgram | Turns call answers into text | The recording of the answer |
| OpenAI | Writes and checks questions, and matches spoken answers | Your page's text when it makes a game, and the words of an answer |
| SpeechGen | Lexy's voice | The text she reads |
| Amazon Web Services | Stores and delivers audio, images and Lexy's code | Audio and files, no player records |
| Stripe | Payments | Your billing and card details |
| Abstract | Checks that a phone number or email address is real | The number or address being checked |
| Hostek | Hosts Lexy's website, database and email | What Lexy stores |
| PostHog, Google Analytics | Measure how lexy.fm itself is used, never inside your widgets | Visits to lexy.fm, and a signed-in publisher's name and email |
| Google, Apple, Microsoft | Sign-in, when a reader chooses it | What the reader agrees to share at sign-in |
Common questions
Can a reader ask what Lexy holds about them, or have it deleted?
Yes. Readers and publishers can ask for a copy of their data, a correction or deletion. Email privacy@lexy.fm.
Do you offer a data processing agreement?
Yes, for publishers who need one. Email privacy@lexy.fm.
Where do I report a security problem?
Email privacy@lexy.fm with what you found and how to reproduce it. Please don't post it publicly while it's being fixed.
Thanks for letting us know.
Thanks. Write to support@lexy.fm with what you were looking for, and we will answer and improve this page.