Privacy Policy

LexFlow · Last updated 15 August 2026

This app holds a lawyer's diary: which cases you are running, for whom, when they are listed and when an order lapses. That is not ordinary customer data, and this policy is written on the basis that a leak is a professional-conduct problem for you, not merely an inconvenience for us. It says plainly what is collected, where it goes, who can see it, and how to get rid of it.

1. Who we are

LexFlow is operated by TechAIBd of 37/A, Sahara Centre, Level-10, VIP Road, Kakrail, Dhaka, Bangladesh. For anything in this policy, write to mdmzmoon@gmail.com.

2. What the app is for

The Supreme Court of Bangladesh publishes its daily cause lists on its own website. We read those published lists every evening, compare them against the case numbers you have saved, and tell you when one of your cases appears. You can also keep your own diary of Judge Court and tribunal hearings, which nothing scrapes — those dates exist only because you typed them.

3. What we collect

What you give us

AccountEmail address, and password (stored only as a one-way hash we cannot read). If you sign in with Google, your Google account email.
ProfileName, phone number, enrolment number, bar association, level of practice, place of practice, and a profile photograph if you upload one.
Your casesCase type, number, year, court, division, which side you represent, filing date, and any party names, client name and client contact details you choose to enter.
Your diaryHearing dates and their purpose, your notes on a case, tasks and their due dates, and orders such as bail, stay or status quo with their expiry dates.
DocumentsAny judgment PDF you upload.

What the court publishes

Cause list entries — court, bench, serial number, section, case number, party names, advocate names and posted results — are published by the Supreme Court and are public information. We store them and record which of them match your saved cases. We did not obtain them from you and they are not confidential.

What the app records by itself

4. What we do not collect

5. Who can see your data

Other users cannot

Every table is protected by row-level security inside the database itself, not merely by the app. Each request is filtered to the account that made it. A modified app, a copied access token or a hand-written request is filtered the same way.

What our office can see

Administration is restricted to a small list of accounts held on the server. Being signed in is not enough, and the list is checked on every privileged request.

An administrator can see, for support purposes:

An administrator cannot browse the app as you. There is no "view as user" function and we will not build one.

Printing your court list for you. If you telephone our office and ask, we can look up your account code and print your court list for that day — your Supreme Court listings, and your own diary hearings if you ask for those too. We keep a record of every occasion we do it: who looked, whose list, which date, and the reason given. That sheet is drawn only from the court's published list and your cases' own numbers. It never includes your case notes, your clients, your fees or your documents.

6. Companies that process data for us

We keep this list short deliberately, and it is complete as at the date above.

SupabaseDatabase, sign-in and file storage. Your data is held on their infrastructure in South Asia (Mumbai).
GitHubRuns the scheduled scraper, and stores the nightly backup as a private file.
ResendSends notification and alert emails.
GoogleFirebase Cloud Messaging delivers push notifications to your device. Google sign-in, only if you choose it.

We do not transfer your data to anyone else, and none of the above is permitted to use it for their own purposes.

7. Notifications

We send you an alert when one of your cases appears on tomorrow's list, a reminder the day before a diary hearing, and warnings before an order lapses. You control push and email separately in the app's settings, and turning them off stops them.

Alerts are a convenience and not a guarantee. The court can publish late, revise a list after publication, or change its website; delivery depends on your network and your device. Always check the court's own board. Nothing in this app displaces your own professional responsibility for a hearing date.

8. Calendar syncing

If you turn on calendar syncing, we give you a private web address that your calendar app reads. Anyone who has that address can read your hearing dates, so treat it like a password. You can regenerate it at any time in the app, which immediately stops the old one working.

9. Payments

There are no paid subscriptions yet and the app collects no payment information of any kind. Every feature described here is free at present.

When paid plans are introduced they will be taken by mobile money, and we will then record the plan, the amount, which wallet you used, the sending number and the transaction ID, so that a payment can be matched against the statement and credited. We will never see or store your PIN, and no card details will be held anywhere in this system. This policy and its date will be updated before any of that begins.

Your saved cases are never withheld or deleted because a subscription has lapsed. A lawyer's diary is not something to hold hostage over a payment.

10. How long we keep things

11. Deleting your account

You can do this yourself, from inside the app, and it takes effect immediately: Profile → Account and data → Delete my account. You will be asked to confirm your password and to type your email address, because this cannot be undone and we would rather it took a moment longer than happen by accident.

Deleting the account removes your profile, your cases, your hearing dates, notes, tasks, orders, matters and alert history, the notification tokens for your devices, your calendar feed link, and any files you uploaded — your profile photograph and any judgment PDF. Nothing of yours is kept back.

If you have already uninstalled the app, write to mdmzmoon@gmail.com from the address your account uses and we will do it for you, within 30 days and in practice much sooner. See delete your account for the full detail.

Backups already taken will still contain your data until they expire, at most 90 days later (section 10).

12. Your other choices

13. Security

Sign-in is handled by our database provider and passwords are stored only as one-way hashes. Access between accounts is prevented in the database rather than in the app. Uploaded files are private and are read through short-lived links rather than public addresses. Google sign-in is bound to the app's signing certificate, so a repackaged copy of the app cannot use it.

What we have not built yet, so that you can decide accordingly: the app has no PIN or fingerprint lock of its own, so anyone holding your unlocked phone can read your case list. Lock your phone.

If a breach ever affects your data, we will tell you plainly and directly. A quiet fix is not an acceptable substitute for telling the advocates whose client confidences are involved.

14. Children

This is a professional tool for practising advocates. It is not directed at children and we do not knowingly hold any child's data.

15. Changes

When this policy changes we will update the date at the top, and we will tell you in the app before any change that materially affects what we collect or who can see it.

16. Contact

TechAIBd
37/A, Sahara Centre, Level-10, VIP Road, Kakrail, Dhaka
Bangladesh
mdmzmoon@gmail.com

This policy is governed by the laws of Bangladesh.