Lexicase is built and operated by Yakup Çağlan, an individual developer. This policy explains what data the app collects, why it is collected, and who else can see it.
1. Who is responsible for your data
Lexicase is developed and operated by Yakup Çağlan, an individual developer based in Türkiye. There is no company entity behind the app.
For any question about this policy or your data, write to info@lexicase.app.
2. What Lexicase collects
Account information
When you create an account, Lexicase stores your email address and, if you provide one, a display name. This is required to sign you in and to keep your learning progress attached to you rather than to a single device.
Passwords are never stored by Lexicase in readable form. Authentication is handled by Supabase, which stores passwords as salted hashes.
Learning data
Lexicase stores the data your study sessions produce: which words you have seen, how you rated them, review schedules, daily goals, streaks, quiz results, and the stories generated for you. This is the core of the product — without it the spaced repetition engine cannot decide when to show you a word again.
Purchase information
If you subscribe, purchase processing is handled entirely by Apple. Lexicase never receives your payment card details. Subscription status is managed through RevenueCat, which receives your account identifier and the state of your subscription so the app knows whether your access is active.
Diagnostics and usage
Lexicase collects basic usage information — which screens are opened, which features are used, whether a study session was completed. This is used to understand which parts of the app are worth improving. When you are signed in, these events are linked to your account, and your email address and display name are sent along with them. If you use Lexicase without an account, they are linked only to a random identifier generated on your device.
Lexicase does not run its own crash reporting. Crash reports reach the developer only through Apple, and only if you have chosen to share them in your iPhone settings.
This data is not used for advertising, and Lexicase does not track you across other companies' apps or websites.
What Lexicase does not collect
- Your location
- Your contacts, photos, calendar, or microphone
- Advertising identifiers (IDFA)
- Health, financial, or biometric data
3. Why each type of data is collected
| Data | Purpose |
|---|---|
| Email address | Sign-in, account recovery, essential service messages |
| Display name | Addressing you inside the app |
| Learning data | Running the spaced repetition engine; syncing progress across your devices |
| Subscription status | Determining whether your paid access is active |
| Crash reports (via Apple only) | Diagnosing and fixing failures |
| Usage data | Understanding which features are used, so the app can be improved |
4. Who else processes your data
Lexicase relies on a small number of service providers. Each one receives only what it needs to do its job.
| Provider | Role | What it receives |
|---|---|---|
| Supabase | Authentication and database | Email address, display name, learning data |
| Apple | App distribution and payment processing | Purchase transactions; crash reports if you have opted into sharing them with developers |
| RevenueCat | Subscription management | Your account identifier and your subscription status |
| Mixpanel | Product analytics | Your account identifier, email address and display name, plus in-app events such as which screens you open and when you finish a study session. Processed on Mixpanel's servers in the European Union. |
| Anthropic | AI story generation | The vocabulary words a story is being generated from |
5. AI-generated stories
Lexicase can generate short stories built from the words you are currently studying. Depending on your device, this happens in one of two ways:
- On your device. On newer iPhones, stories are generated by Apple's on-device foundation model. Nothing leaves your phone.
- Through Anthropic. On devices without on-device generation, the words are sent to Anthropic's Claude API to produce the story.
When the Anthropic path is used, only the vocabulary words themselves and the parameters needed to shape the story are sent. Your email address, name, and account identifier are not included. Anthropic does not use data submitted through its API to train its models.
AI-generated text can occasionally be inaccurate. Stories are a learning aid, not a reference source.
6. Where your data is stored
Your account and learning data are stored on Supabase infrastructure, which may be located outside Türkiye and outside the European Economic Area. Where data is transferred internationally, it is protected by the contractual safeguards those providers offer.
7. How long data is kept
- Account and learning data are kept for as long as your account exists.
- Generated stories are kept for 90 days and then removed automatically.
- Crash and usage data are kept according to the retention periods of the providers listed above.
8. Your rights
You can request access to your data, correction of inaccurate data, or deletion of your account and everything attached to it.
You can delete your account at any time from inside the app: open Profile → Delete Account. Deletion happens immediately and removes everything attached to the account — profile, learning progress, review schedules, custom decks, quiz results, generated stories and subscription records. Deletion is permanent; learning progress cannot be recovered afterwards. If you cannot reach the app, write to info@lexicase.app from the email address registered to the account.
Depending on where you live, you may also have the right to object to certain processing, to request a copy of your data in a portable format, or to lodge a complaint with your local data protection authority.
9. Children
Lexicase is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child under 13 has registered an account, write to info@lexicase.app and the account will be removed.
10. Security
Traffic between the app and its servers is encrypted in transit. Database access is restricted by row-level security rules, so one account cannot read another account's data. Authentication tokens are stored in the iOS Keychain.
No system is perfectly secure, and no absolute guarantee can be given — but the app is built so that a failure in one layer does not expose other users' data.
11. Changes to this policy
This policy may be updated as the app changes. The date at the top of this page always reflects the current version. Material changes will be announced inside the app.
12. Contact
Questions, requests, or complaints: info@lexicase.app