Last updated: June 7, 2026
Almedeo Inc., doing business as LexTabs (“LexTabs,” “we,” “us,” or “our”), operates a cloud-based wire transfer verification and trust accounting platform designed for legal professionals. This Privacy Policy explains what personal data we collect when you use our website at lextabs.comand the LexTabs application (collectively, the “Services”), how we use it, and the rights you have regarding your data.
By accessing or using the Services you agree to this Privacy Policy. If you do not agree, please discontinue use of the Services.
LexTabs is operated by Almedeo Inc., a US company and the data controller for personal data collected through the Services. Questions about this policy may be directed to privacy@lextabs.com.
Our security program is designed with reference to the NIST Cybersecurity Framework (CSF) 2.0, GLBA safeguards principles, CCPA/CPRA, Nacha operating rules, and applicable state bar ethics rules and ABA cybersecurity guidance for legal technology platforms.
When you register or manage your account we collect your name, email address, password (stored as a salted hash), job title, and organization details. If you invite team members we collect the email addresses you supply.
To deliver trust accounting and wire transfer verification features you may upload or enter information about your clients, legal matters, payees, payors, contacts, and associated financial transactions. This data is processed on your behalf as a service provider and remains yours.
LexTabs integrates with Plaidto allow you to connect your trust accounts and operating accounts. When you link a bank account, Plaid provides us with account identifiers, routing numbers, balances, and transaction history necessary to reconcile your trust ledger and verify wire transactions. We do not receive or store your online banking credentials. Bank account numbers and routing numbers sourced via Plaid are never stored in plaintext; only tokenized or masked references are retained after a verification session is complete. Plaid’s use of your data is governed by the Plaid End User Privacy Policy.
Where identity verification is required, LexTabs uses Stripe Identityto verify counterparty identity. Identity document images are processed by Stripe and are not retained by LexTabs beyond the verification event; we retain only the verification outcome and associated metadata. Stripe’s practices are governed by the Stripe Privacy Policy.
You may upload documents (PDF, Word, images, etc.) for storage and OCR-based search. We store these files securely and process them solely to provide the document management features you request.
LexTabs uses AI models to assist with transaction categorization, compliance scoring, amount assessment, and client-name analysis. Transaction details and contextual metadata are sent to our AI processing pipeline. We do not use your client or matter data to train third-party foundation models without your explicit consent.
If you connect your Clio account, we receive OAuth tokens and sync clients, contacts, and matters from Clio to populate LexTabs. We access only the Clio data scopes you authorize and do not modify your Clio data without your instruction.
Subscription payments are processed by Stripe. LexTabs does not store full payment card numbers. We receive and retain a tokenized payment method reference, billing address, and subscription status from Stripe.
We support multi-factor authentication via authenticator app (TOTP) or hardware security key. SMS-based MFA is not used for production system access. We also support biometric authentication (passkeys / WebAuthn): biometric verification is performed on your device and we store only a public-key credential, never biometric templates. We maintain access logs (IP address, timestamp, user identity) for security auditing purposes, retained for 12 months.
We automatically collect log data such as IP address, browser type, pages visited, and feature interactions to operate, secure, and improve the Services.
We will not sell your personal data or your clients’ data to third parties, nor use it for targeted advertising.
If you are located in the European Economic Area or United Kingdom, our legal bases for processing personal data are:
We share personal data only as described below. We do not sell data.
We retain data only as long as necessary for the business purpose for which it was collected, or as required by law or contract. Retention periods run from the later of (a) the date the data was collected or (b) the date the underlying business purpose concluded. Our retention schedule is:
| Data Type | Retention Period | Basis |
|---|---|---|
| Wire verification audit logs | 7 years | Legal malpractice defense; Nacha; client contract |
| Identity verification records (Stripe) | 5 years | GLBA; AML obligations; fraud investigation |
| Bank account data (Plaid-sourced) | Duration of matter + 90 days | Contractual necessity; Plaid data agreement |
| Client matter data (law firm) | 7 years post-matter close | Legal malpractice standards; client contract |
| Authentication & access logs | 12 months | Security operations; incident investigation |
| Incident response records | 5 years | Regulatory investigation; insurance claims |
| Backup snapshots | 90 days rolling | Operational recovery; contractual SLA |
| Marketing / prospect data | 2 years from last contact | Legitimate interest; CCPA/CPRA |
Account termination. Upon termination of your account, we provide a 30-day window to export data you are entitled to retrieve, then initiate deletion within 30 days of the termination date or export window close, whichever is later. We retain only data required by applicable law or the minimum retention schedule above and issue a written deletion confirmation upon request.
Legal holds. If LexTabs becomes aware of actual or anticipated litigation, regulatory investigation, or audit, a legal hold may supersede the standard retention schedule for affected data until the matter is resolved.
Our security program is aligned with the NIST Cybersecurity Framework 2.0. Controls include:
No system is completely secure. If you believe your account has been compromised, contact us immediately at security@lextabs.com.
Upon detection of a security incident involving unauthorized access to Restricted data (bank account numbers, identity documents, wire transaction records) or a system compromise, LexTabs will:
Security incidents, suspected vulnerabilities, or security inquiries can be reported to security@lextabs.com.
LexTabs is designed for use by licensed legal professionals. We understand that client data you enter may be subject to attorney-client privilege and professional confidentiality obligations. We process such data solely as a service provider acting on your instructions and do not access it for any purpose beyond operating the Services. Our sub-processors are bound by equivalent confidentiality obligations.
We use session cookies and local storage to keep you authenticated and to remember your preferences. We do not use third-party advertising cookies. You can configure your browser to refuse cookies, but some features of the Services may not function correctly without them.
Depending on your location, you may have the right to:
To exercise these rights, email privacy@lextabs.com. We will acknowledge your request within 5 business days and complete it within 30 days (or as otherwise required by applicable law). We may need to verify your identity before processing your request. Deletion requests are assessed against applicable legal hold, retention, and contractual obligations before completion.
LexTabs operates in the United States. If you are located outside the US, your data will be transferred to and processed in the US. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) for transfers from the EEA or UK.
The Services are intended for legal professionals and are not directed to individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
The Services may contain links to or integrations with third-party websites and services (e.g., Clio, Plaid, Stripe). This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy policies before sharing information with them.
We may update this Privacy Policy from time to time. If we make material changes we will notify you by email or by posting a prominent notice in the application at least 14 days before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
Questions, concerns, or requests regarding this Privacy Policy should be sent to:
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.