---
title: How Lexpoint handles your data
description: Immigration work moves sensitive documents. This explains the exposure Lexpoint is built to remove, which third parties still touch your data, and what we are changing next.
doc_type: concept
canonical_url: https://docs.lexpoint.io/privacy/
last_verified: 2026-08-28
keywords: immigration document privacy, who can see my documents, data handling, Canadian data residency
license: Documentation © Lexpoint. Quote with attribution and a link to the canonical URL.
---
# How Lexpoint handles your data

You have one immigration reality: one identity, one history, one set of documents. The process
around it does not work that way.

## The exposure comes from copies

Say you speak to three consultants before choosing one. Each has an intake form, so you enter the
same date of birth, passport number, and address three times. Each asks for documents, so your
passport, your diplomas, and your bank statements are uploaded three times, into three systems you
cannot see. Each of those firms runs your files through their own tooling — conversion, compression,
bundling, storage — and you have no visibility into any of it.

Then your employer asks for proof you are authorized to work. HR asks for something to support a
family member's case. A school wants a document. Each request creates another copy, in another
system, held by another party, for an unknown length of time.

**Even doing it entirely yourself does not avoid this.** Assembling an application means bundling
PDFs, compressing files, converting formats — and the ordinary way to do that is to upload your
passport to a free website. That is often the least examined step in the whole process, and the
files are among the most sensitive.

So the exposure is not the result of anyone being careless, and it is not solved by hiring or not
hiring someone. It comes from a record being **copied** every time a new party needs to see part of
it. Nobody can realistically build private tooling for every step. Lexpoint's answer is to stop
making copies.

## One record, shared in a controlled way

Your profile lives once, in your account, and belongs to you. Other parties are given **a scoped
view of it**, not a copy of their own.

**Each party sees only its slice.** An employer connected to you sees agreed employment facts —
never your profile, ImmiReport, documents, or cases. A representative sees what you granted them. A
shared ImmiReport is a read-only report behind a PIN. A shared timeline carries milestones and
dates, no names and no documents.

**Access is explicit, listed, and revocable.** Who can reach your file is a set of decisions you can
read back in [Access and sharing](/individuals/account/access-and-sharing/), and withdrawing access
takes effect immediately. That is the part a copy can never offer: once a document is in someone's
inbox, it is theirs.

**One intake, not one per party.** Documents are uploaded to the requirement that asked for them,
once. They are not attachments in an inbox or messages in a chat app, so there is no copy sitting in
someone's downloads folder or a group thread.

**The processing stays inside.** Assembling a submission package — merging, generating, compressing
— runs on our own service, so the step that would otherwise send your passport to a free web tool
does not leave the platform.

**Your data is stored in Canada.** The database holding your profile, your case, and your history,
and the file storage holding every document you upload, both run in the **Canada (Central) region in
Montreal**. Your immigration file does not sit in another country's data centre.

:::note[What this does not cover]
Lexpoint can only govern what happens on Lexpoint. If you send a document to someone by email or a
messaging app, that copy is outside the platform and outside your control — that is precisely the
exposure worth avoiding.
:::

## Third parties, named

Any platform that says it uses no third parties is describing something that does not exist. What
matters is which ones, for what, and whether the list is getting shorter.

| What | Where it runs today |
|---|---|
| **Document assembly** — merging and generating the PDFs in a submission package | Our own service. Client documents are not uploaded to a third-party PDF API to be processed. |
| **AI features** — document analysis and Lexi | Content relevant to the task is sent to the model provider behind that feature. |
| **Database and file storage** — your profile, your case, and every document you upload | Managed infrastructure in the **Canada (Central)** region, Montreal. |
| **Web delivery, email and messaging** — serving pages, sending notifications | Managed providers under contract. Page delivery is distributed globally, as web hosting normally is; the data behind it stays in the Canadian region above. |

None of these are advertising networks or data brokers. Your file is not a product being sold on.

## What is changing

**Self-hosted AI inference in Canada, targeted for the end of 2026.** Today the AI features run on
models operated by third-party providers. We are working toward running inference on infrastructure
we control, hosted in Canada, so that content processed by AI features stays inside our own
boundary.

This is a stated plan with a target date, not a description of how the product works today. When it
ships it will be in the [changelog](/changelog/), and this page will say so.

:::note[If data residency is a requirement]
Some situations carry specific obligations about where personal information may be processed. That
is a question about your circumstances rather than about the product. Only a licensed professional
you retain can tell you what applies — not Lexpoint, and not the organization listed as your
[default servicing organization](/individuals/consultations/who-advises-you/).
:::

## Related

- [Access and sharing](/individuals/account/access-and-sharing/) — who can reach your file, and how to revoke it
- [Privacy and your data](/individuals/account/privacy/) — exporting your data, and deleting your account
- [Confirmations and limits](/individuals/lexi/approvals-and-limits/) — what Lexi does and does not do with your data

## Frequently asked questions

### Who can see my documents?

The people you are working with on a case, and no one else. Access is explicit, listed in your settings, and revocable. Nothing is shared with an employer, a partner organization, or another user unless you granted it.

### Does Lexpoint send my documents to other companies?

Document assembly runs on our own service rather than a third-party PDF API. Where you use AI features, the relevant content is sent to the model provider that powers them. Infrastructure providers host the platform. Those are the categories; none of them are advertising or data-broker services.

### Where is my data stored?

In Canada. The database that holds your profile and case, and the storage that holds every document you upload, run in the Canada (Central) region in Montreal. Self-hosted AI inference in Canada is on our roadmap for end of 2026.
