Privacy Policy
How Lexmount handles account, service, website, and cloud-browser data
Version: 2026-09-11.8
This Privacy Policy explains how Lexmount collects, uses, discloses, stores, and protects personal information when you visit our websites or use our consoles, APIs, software development kits, Web Fetch, cloud browsers, support, and related services (collectively, the “Services”). It also explains the choices and rights available to you.
The Lexmount operator and contracting entity is the legal person identified on the applicable checkout page, order, agreement, or invoice. For public Lexmount Services, that entity is generally Beijing Zhuyue Technology Co., Ltd., unless the applicable transaction identifies another entity. Its business and privacy-contact address is Room 2108-B310, No. 9 North Fourth Ring West Road, Haidian District, Beijing, China. The privacy contact accepts questions and rights requests through Contact or support@lexmount.com.
Scope
This policy applies to Lexmount-operated websites and Services that link to it. It does not replace a customer's own privacy notice for data that customer chooses to process in a cloud browser, and it does not govern an independent third-party site merely because the Services access it. Third-party services apply their own terms and privacy policies.
An enterprise order, data-processing addendum, or region-specific notice may provide additional terms. If a translated version differs from a signed agreement, the signed agreement controls for its subject to the extent permitted by law.
Our roles
For account, billing, support, security, and website-operation data, the operator generally determines the necessary purposes and acts as controller or personal information processor. For data that you or your agent submits to or generates in a cloud browser, you determine the automation purpose, target sites, inputs, persistence, and recipients; Lexmount generally acts as processor or entrusted service provider on your instructions.
You are responsible for having a lawful basis, giving required notices, honoring relevant rights, and ensuring that your instructions comply with law and third-party terms. See the Browser Data Notice for the detailed division of responsibility.
Information we process
Depending on your use, we process the following categories:
- Account and profile data: name, email address, phone number, organization, avatar, language, account status, and third-party login identifiers;
- Authentication and security data: password-derived values, login state, verification and challenge results, device and risk signals, API-key identifiers, access permissions, and security events;
- Project and service data: Project ID, workspace or organization membership, selected region, plan, feature configuration, quotas, session and resource identifiers, and usage records;
- Transaction data: orders, prices, currency, payment status, provider transaction identifiers, billing contact, invoice information, refunds, and legally required financial records. Payment-card or wallet credentials are generally collected directly by the payment provider rather than stored by Lexmount;
- Device, network, and log data: IP address, approximate network location, browser and device characteristics, request time, referring page, diagnostics, error, audit, and performance logs;
- Support and communication data: tickets, messages, attachments, feedback, survey responses, and records of support interactions;
- Cookie and preference data: login cookies, security cookies, legal acknowledgement records, language, consent choices, and analytics identifiers when approved and consented; and
- Browser data processed on your instructions: automation instructions, navigation and browsing history, URLs, rendered page content and DOM or accessibility-tree data, network requests and responses, form and keyboard input, mouse or pointer interactions, cookies, localStorage and other context data, credentials you choose to supply, screenshots, recordings, uploads, downloads, extracted outputs, diagnostic files, and operational logs.
Some browser data may reveal credentials, communications, financial, location, biometric, health, children's, or other sensitive information. We do not require such data for general account setup. Do not submit or record sensitive or third-party information unless it is necessary, lawfully authorized, and protected with appropriate controls.
Sources of information
We obtain information:
- Directly from you or your organization, such as during registration, purchase, configuration, support, surveys, or rights requests;
- Automatically from devices and Services, such as cookies, security signals, usage, logs, diagnostics, and metered resources;
- From services you connect, such as identity, payment, messaging, storage, proxy, or target-site providers; and
- From administrators or authorized partners, where they create or manage your organizational account, purchase access, or lawfully refer you to the Services.
Browser data is generated when you or your agent instructs a browser session to interact with a site or connected service. Lexmount does not independently choose the target-site content you submit.
How and why we use information
We use personal information only for identified and compatible purposes, including to:
- create, authenticate, administer, and secure accounts and API access;
- deliver browser sessions, Web Fetch, storage, recordings, downloads, proxies, support, and other requested features;
- meter usage, process orders and payments, issue invoices, prevent duplicate or fraudulent transactions, and keep required financial records;
- communicate about service operation, billing, security, support, policy changes, and requested information;
- diagnose faults, maintain availability, measure performance, plan capacity, and improve product reliability;
- detect, investigate, and prevent fraud, abuse, security incidents, policy violations, and unauthorized access;
- comply with law, lawful requests, sanctions, audits, disputes, and enforcement of agreements;
- personalize language, region, and product preferences; and
- perform website analytics, support, or marketing only where the relevant processing has been approved and any required consent has been obtained.
Depending on the applicable law and context, our legal bases include performance of a contract, steps requested before entering a contract, compliance with legal obligations, protection of users and the Services, legitimate interests that do not override individual rights, and consent. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
Browser data and session recording
Cloud-browser features process data on your instructions. Screenshots and session recordings may capture mouse movement, clicks, keystrokes, form entries, credentials, messages, page views, and content displayed by third-party sites. DOM snapshots, network traces, downloads, and automation logs may contain the same or additional sensitive content. Lexmount uses that data only to provide the configured feature, secure or diagnose the Services, provide support you request, or comply with law, unless a separate agreement and valid authorization permit another purpose.
Customers must decide whether recording is necessary, notify affected people, obtain required consent, minimize or mask sensitive fields, restrict access, and select the shortest practical retention. Detailed categories, region behavior, deletion controls, and current recording periods are in the Browser Data Notice.
Cookies, website analytics, and similar technologies
We use necessary cookies and local storage for authentication, security, language, legal acknowledgement, and privacy preferences. Optional analytics, support, affiliate, or marketing scripts load only after the processing has been approved for the release and you make the required affirmative choice.
You can review or withdraw optional choices through “Cookie preferences” at the bottom-left of the website. Browser blocking or deletion may affect necessary login and preference functions. Details about categories, current providers, identifiers, domains, and retention are in the Cookie Policy. A browser “Do Not Track” signal is not treated as consent to optional processing; where law requires recognition of another opt-out signal, we will apply the required mechanism.
How we disclose information
We disclose personal information only where necessary for the following recipients and purposes:
- Service providers and subprocessors supporting cloud infrastructure, selected regions, authentication, payments, messaging, customer support, security, storage, proxies, or consented analytics, subject to contractual and access restrictions;
- Your organization and administrators where they manage accounts, permissions, usage, billing, security, or support;
- Connected and target services when you direct the Services to authenticate, request, upload, download, or submit data to them;
- Professional advisers, auditors, insurers, and financing parties under appropriate confidentiality obligations;
- Authorities or affected parties when reasonably necessary to comply with law or lawful process, protect rights and safety, investigate fraud or abuse, respond to an incident, or enforce agreements; and
- Transaction participants in a financing, merger, acquisition, reorganization, insolvency, or sale of assets, subject to applicable notice, confidentiality, and continued protection obligations.
We may use or disclose aggregated or de-identified information that cannot reasonably identify a person. We do not attempt to re-identify it except to verify the effectiveness of de-identification or as permitted by law.
The Cookie Policy identifies the website vendors approved for the current release, including their purposes, data, domains, regions, and retention. Service subprocessors and regions can vary with the selected product region, connected services, payment method, and enterprise deployment. Current information relevant to an enterprise order or data-processing addendum is available through Contact.
Sale, advertising, and model training
We do not sell personal information or browser data, and we do not share it for cross-context behavioral advertising. Unless you explicitly opt in through a separate written agreement and all required authority and consent have been obtained, we do not use customer content, browser sessions, navigation history, page or DOM content, inputs, credentials, cookies, screenshots, recordings, downloads, outputs, or automation instructions to train, fine-tune, or evaluate any general-purpose or generative AI model. We do not use browser data to build advertising profiles. If our practices change in a way that creates a legal right to opt out, we will provide the required notice and control before that processing begins.
International and cross-region processing
Account, transaction, and website-operation data may be processed where the operator and its service providers operate. Browser data is generally processed in the product region you select or that the console displays. Your use of cross-region resources, target sites, proxies, troubleshooting, or vendor support may cause data to cross borders.
We use contractual, security, consent, assessment, filing, or other transfer mechanisms required by applicable law. Available regions and vendors vary by plan and deployment. An enterprise order or data-processing addendum may provide additional region commitments.
Retention and deletion
We retain information only as long as reasonably needed for the stated purposes:
- Account and project data is retained while the account is active and for the period needed to close the relationship, resolve disputes, and meet legal obligations;
- Orders, invoices, payment evidence, and tax or accounting records are retained for applicable legal and audit periods;
- Screenshots, recordings, downloads, diagnostic files, and other saved browser artifacts follow the period shown in the console, API response, selected region, or agreement; temporary instance data enters cleanup when the instance ends, while explicitly persistent contexts remain until deletion or the agreed expiry;
- Security, operational, automation, and support logs are retained only for the period needed for service operation, troubleshooting, abuse prevention, contractual commitments, and legal obligations;
- Registration acknowledgement records may be retained for up to three years to document the agreement and meet compliance obligations. Hashed identifiers remain pseudonymous personal data while retained; and
- Browser-data periods vary by type, region, product setting, console display, API response, and agreement. See the Browser Data Notice.
At expiry, information is deleted or de-identified unless a legal hold, security incident, payment dispute, or legal obligation requires restricted retention. Deletion from active systems may take reasonable processing time; restricted backups are not restored for ordinary use and are overwritten through their normal rotation. Product controls may delete one artifact without deleting a separate persistent context, account record, invoice, or backup copy, so select each relevant item or identify all Services in a rights request.
Security
We use measures appropriate to the service and risk, including access controls, least privilege, tenant separation, encryption in transit, secret handling, logging, and audit controls. We review access and respond to qualifying incidents as required by law and contract. No system is completely secure, and transmission over the Internet carries risk.
You also play a role: use strong authentication, restrict and rotate API keys, avoid secrets in logs or support messages, configure retention and sharing carefully, and notify us promptly of suspected compromise. Security reports may be submitted through Contact.
Your choices and rights
Subject to applicable law and exceptions, you may request access, confirmation, correction, a copy or transfer, deletion, restriction, objection, withdrawal of consent, account closure, or an explanation of processing. You may also complain to the competent privacy authority and, where provided by law, appeal our decision.
Because Lexmount does not currently sell personal information or share it for cross-context behavioral advertising, there is no such sale or sharing to opt out of. You may nevertheless ask us to confirm this treatment. If that practice changes, we will provide any legally required “Do Not Sell or Share” control before the change takes effect.
Submit a request through Contact or support@lexmount.com. Describe the account, information, and right involved. We may verify identity and authority and may ask for information reasonably necessary to locate records. An authorized agent must provide evidence of authority where required. We will respond within the period required by applicable law and explain any lawful denial or extension. We do not discriminate against users for exercising privacy rights, although deleting data needed to provide a feature may make that feature unavailable.
If Lexmount processes browser data solely for a customer, we may direct the request to that customer or assist it under the applicable agreement. The customer remains responsible for responding as controller or personal information processor.
You may update common profile information in account settings and control optional website processing through Cookie preferences. Closing a LexHome account disables linked API access and removes or schedules deletion of account-level records, but persistent browser contexts and stored artifacts may have separate deletion controls or legally required retention. Delete those items through the relevant product controls or submit a request that expressly covers all Services.
Children
The Services are designed for business and developer users with legal capacity and are not directed to children under 14. We do not knowingly solicit children's personal information for account creation. If you believe a child provided account data without appropriate authorization, contact us so we can investigate and take required action. Customers must not use the Services to process children's data unless legally authorized and appropriately protected.
Changes to this policy
We may update this policy as the Services, vendors, or law change. We will publish the new version and effective date and provide prominent advance notice of material changes through the website, console, email, or another appropriate channel. Where renewed consent or agreement is required, we will obtain it before the relevant processing begins. Prior release records are retained as an immutable compliance archive.
Contact
For privacy questions, rights requests, complaints, or security concerns, use Contact or support@lexmount.com. Please do not include passwords, API keys, session cookies, or unrelated sensitive information in the request.
