Privacy at LxOS

Your information carries a duty of care.

This policy explains how LxOS protects client confidentiality and limits the collection, use, disclosure, and retention of personal information across our services.

Last updated 3 September 2026

Layered handmade paper and translucent vellum with subtle plum fibres
In plain language

Law firms control the matters and client information they place in LxOS. We treat that information as confidential and seek to collect and handle only what is reasonably necessary to provide, secure, and support the service, follow customer instructions, and meet legal obligations.

01

About this policy

This Privacy Policy describes how LxOS (referred to as “LxOS”, “we”, “us” or “our”) manages personal information. It applies when you visit our website, request a demonstration, create or use an LxOS account, access a client or collaborator portal, contact support, or otherwise interact with our services.

Our privacy program is being developed with reference to the Privacy Act 1988 (Cth), the Australian Privacy Principles, and US privacy requirements that apply to our activities. The law that applies can depend on location, the people whose information is involved, and how a customer uses LxOS. This policy does not replace a law firm’s own privacy notices, professional duties, or contractual obligations.

02

Our role and the role of your law firm

For account, website, commercial and service-administration information, LxOS generally determines why and how information is handled.

For information placed in a matter workspace by a customer—including client communications, documents, evidence, notes and billing information—the customer usually determines the purpose of the handling and LxOS processes the information to provide the service. Requests concerning matter information should ordinarily be directed to the relevant law firm first.

Privacy laws use different terms for these roles across jurisdictions. Any role allocation in an Order Form, data-processing agreement, or other signed customer agreement will govern to the extent it is more specific.

03

Information we collect

We apply a data-minimisation principle: we seek not to collect personal information merely because it may be useful later. Depending on how you use LxOS, the information reasonably required may include:

  • Identity and professional details, such as your name, email address, firm, role and contact information.
  • Account and authentication information, including account identifiers, role assignments, login records and security events.
  • Customer Content, including matters, documents, messages, requests, notes, deadlines, invoices, precedents and information about clients or collaborators.
  • Usage and device information, such as browser type, IP address, timestamps, pages or features used, diagnostics and performance data.
  • Commercial and support information, including demonstration requests, correspondence, feedback, support requests and contract administration.

Legal matters may contain confidential or sensitive information about health, finances, disputes, identity, criminal allegations or other private circumstances. Customers should only place information in LxOS when they have a lawful basis and appropriate authority to do so, and should avoid including information that is not necessary for the relevant work.

04

How we collect and use information

We collect information directly from users and customers, from people authorised to invite or communicate with them, automatically through service operation, and from service providers acting on our behalf.

We use personal information to:

  • provide, secure, maintain and improve LxOS;
  • authenticate users and apply matter, firm and role-based permissions;
  • enable documents, communications, client requests, drafting and collaboration;
  • respond to inquiries, provide support and administer customer relationships;
  • monitor reliability, investigate misuse and protect users, customers and LxOS;
  • comply with legal obligations and establish, exercise or defend legal claims; and
  • send service notices and, where permitted, relevant product communications.

We do not sell personal information, use Customer Content for third-party advertising, or collect Customer Content independently of what customers and authorised users provide or generate through their use of the service.

05

Google Workspace data

Connecting a Google account is optional. If an authorised LxOS user chooses to connect Gmail, LxOS requests access to the user’s Google account identity and the Gmail data needed for the features they use. Depending on those features, this can include the connected email address and profile details; messages, threads, headers, bodies, labels and attachments; and permission to send messages or change mailbox state.

LxOS uses Google Workspace data to provide user-facing email features within LxOS. These features include displaying and searching email, opening threads and attachments, marking messages read or unread, starring, archiving, restoring, reporting spam or moving messages to trash, sending messages that a user composes or approves, and running email-productivity workflows configured by the user or their law firm.

LxOS stores account-connection metadata and OAuth credentials so the connection can continue to work. Refresh tokens are encrypted at rest and access is limited to authorised server-side processes. Gmail data is processed only as needed to provide, secure and support the connected features. Where a user invokes an AI-assisted email feature, relevant Gmail data may be processed by service providers engaged to deliver that visible feature, subject to the user’s instructions and applicable contractual safeguards.

We do not sell Google user data, use it for advertising, or use it to determine creditworthiness or for lending. We do not permit humans to read Gmail data except with the user’s affirmative agreement for specific data, where needed for security or support, where required by law, or where the data has been aggregated for permitted internal operations.

Users can disconnect Gmail from LxOS at any time. Disconnecting revokes the provider credential where supported and removes active OAuth credentials from LxOS. Email content or work product that a user deliberately saved into a firm workspace may remain subject to the firm’s instructions, configured retention settings, backup cycles and legal obligations. Users may also request deletion as described under “Your choices and privacy rights”.

LxOS’s use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

06

Outlook and Microsoft 365 data

Connecting a Microsoft account is optional. LxOS connects to personal Outlook.com mailboxes and work or school Microsoft 365 mailboxes hosted in Exchange Online through Microsoft Graph. You sign in with Microsoft and grant access through its consent process; LxOS does not receive your Microsoft password. For work or school accounts, your organisation may require administrator approval or restrict the connection.

The connection requests delegated permissions to read your account profile, read and manage mail, send mail on your behalf, and maintain access using refresh tokens (User.Read, Mail.Read, Mail.ReadWrite, Mail.Send and offline_access). These permissions apply to the connected user's mailbox and are not limited to the inbox folder. This integration does not request application permissions to access every mailbox in an organisation, or permissions to read calendars, OneDrive files or Teams conversations.

Data accessed can include your Microsoft account identifier, email address and profile details; message identifiers, subjects, sender and recipient details, timestamps, bodies and conversation threads; mailbox folders, categories and read or flag status; and attachments. LxOS uses this data to display and search mail, open messages and attachments, mark messages read or unread, flag, archive, move or delete messages, and send messages, replies and forwards with attachments as instructed through the features you use.

LxOS also processes relevant email content and instructions when you or your law firm enable email-productivity workflows or AI-assisted email features. This may include processing by hosting and AI service providers engaged to deliver those features, subject to applicable customer instructions and contractual safeguards. The sections on AI-assisted features, disclosure and overseas processing also apply. We do not sell Microsoft account or mailbox data, or use or transfer it for advertising or marketing.

LxOS stores connection metadata, granted scopes and OAuth credentials to maintain the connection, including while you are not actively using LxOS. Refresh tokens are encrypted at rest and used by server-side processes. Email content and workflow outputs may be processed or stored where needed for the connected features and your firm's work, subject to the security and retention provisions of this policy.

You can disconnect Outlook in LxOS to disable the connection and clear its active stored OAuth credentials. Disconnecting in LxOS does not itself remove the consent recorded by Microsoft. You can also manage or revoke LxOS's access through your Microsoft account settings; for an organisation-managed account, contact your administrator if you cannot revoke access yourself. Disconnecting does not delete messages from your Microsoft mailbox. Content or work product already saved in a firm workspace may remain under the firm's instructions, retention requirements, backup cycles and legal obligations. You can request deletion as described under Your choices and privacy rights.

Our use of Microsoft Graph is subject to the Microsoft APIs Terms of Use. Microsoft's handling of information within its own services is described in the Microsoft Privacy Statement.

07

AI-assisted features

Some LxOS features use artificial intelligence to assist with research, drafting, summarisation, classification or other legal workflows. When a user invokes one of these features, relevant instructions and Customer Content may be processed by AI infrastructure and model providers engaged to deliver that feature.

AI-generated material may be incomplete or incorrect. LxOS is designed around visible review: professional judgment remains with the user, and lawyers remain responsible for deciding whether an output is appropriate for a matter.

Specific model providers, retention settings and processing arrangements may vary by feature or customer agreement. Material changes that affect the handling of Customer Content will be communicated through product, contractual or privacy notices as appropriate.

08

When we disclose information

We may disclose personal information:

  • to the firm, users, clients and collaborators authorised within the relevant workspace;
  • to hosting, infrastructure, authentication, communications, support and AI service providers that help operate LxOS;
  • to professional advisers, auditors, insurers and prospective transaction counterparties under appropriate obligations;
  • where required or authorised by law, court order or a regulatory authority; or
  • where reasonably necessary to protect safety, rights, property or the integrity of the service.

Customer Content is treated as confidential. Service providers are permitted to handle information only for the services they provide to us and subject to applicable contractual and legal safeguards. We do not disclose client information simply because it may have commercial value.

09

Overseas processing

Technology and support providers may store or process information outside Australia or make it accessible to personnel in other countries. The locations involved depend on the services, infrastructure region, customer configuration and providers used at the relevant time.

Where cross-border disclosure rules apply, we take reasonable steps appropriate to the circumstances, including contractual, access-control and vendor-review measures. Customers with specific data-location requirements should confirm those requirements with LxOS before placing regulated information in the service.

10

Security and retention

We use technical and organisational safeguards intended to protect information against misuse, interference, loss, and unauthorised access, modification or disclosure. Product controls include role and matter-scoped access, bounded external sharing, and accountable activity records. Our security and privacy program is being developed with reference to recognised frameworks, with current controls, work in progress, and independent assurance reported separately in our Trust Center. No system can guarantee absolute security.

We retain information for as long as reasonably necessary to provide the service, comply with customer instructions and legal obligations, resolve disputes, maintain security and enforce agreements. Retention periods vary by information type, contract, workspace configuration, backup cycle and legal requirement. Information is deleted, de-identified or securely isolated when it is no longer required, subject to lawful retention and technically necessary backup periods.

11

Your choices and privacy rights

Depending on your location, relationship with LxOS, and applicable law in Australia or the United States, you may have rights to ask for access, correction, or deletion of personal information; withdraw consent; object to or limit certain handling; opt out of certain communications; or raise a concern about how information is handled. These rights are not absolute and may be subject to lawful exceptions.

If your request concerns information held in a law firm’s LxOS workspace, contact that firm first. We will support customers in responding to valid requests where required. We may need to verify your identity and may decline or limit a request where the law permits or requires us to do so.

You may unsubscribe from non-essential marketing communications using the link in the message. Essential account, security and service communications cannot be opted out of while the relevant service relationship continues.

12

Contact, complaints and changes

Questions, access or correction requests, and privacy complaints can be sent to team@rune-ai.co. Please provide enough information for us to understand the issue without sending unnecessary confidential matter content.

We will acknowledge and investigate privacy complaints within a reasonable period. If you are not satisfied with our response, you may be entitled to contact the Office of the Australian Information Commissioner, a relevant US state authority, or another regulator with jurisdiction over the matter.

We may update this policy as the service, our providers or applicable requirements change. The “last updated” date records the latest revision. If a change materially affects how we handle existing Customer Content, we will provide additional notice where appropriate.