Privacy Policy

Last updated: 7 September 2026.

1. What we collect

Account details (email, and profile info from Google if you sign in that way); the content of your trees (nodes, descriptions, chat messages, generated documents); usage and error events; and billing metadata from Stripe (we never see or store your card number). Browser analytics run only after you accept the cookie banner. Separately, we record a small set of server-side product events under your account id (for example sign-up, and that an AI action ran) so we can operate and bill the service; these are not gated by the banner.

2. Sub-processors

We use a small set of vetted providers to run the service: • Supabase — database, authentication, and storage for your account and tree data. • Stripe — subscription billing and payment processing. Stripe holds your payment details; Leefy never receives raw card numbers. • PostHog — product analytics, to understand feature usage and improve the app. • Sentry — error monitoring, to catch and fix bugs. • Vercel — hosts the application and serves every request. • Resend — delivers the emails Leefy sends you (waitlist, account, and billing notices). • Anthropic, OpenAI, and xAI — process the text of your AI requests (node content, prompts, chat) to generate AI responses, whether you use Leefy's included deliverables or your own API key (BYOK). Which provider handles a request depends on the provider you choose in Settings.

3. Bring-your-own API keys

If you provide your own Anthropic, OpenAI, or xAI API key, it is encrypted at rest with AES-256-GCM before it is stored. The encrypted key is decrypted in memory only at the moment an AI request is made on your behalf, and is never logged, displayed in full, or sent anywhere except directly to that provider's API.

4. Data access and deletion

Row-level security ensures your tree data is only ever readable by your own account through the app. Separately, when an AI action runs, we keep a copy of the assembled context it was given (node content, prompts, chat) for 30 days so staff can diagnose problems; staff, not RLS, gates access to those copies. You can turn this off at any time in Settings, or by contacting us. You can also request export or deletion of your account and its data at any time by contacting us at the address on your billing receipts.

5. Cookies

We use essential cookies for authentication (via Supabase) and, where enabled, analytics cookies (via PostHog) to understand product usage.

6. Changes

We may update this policy as the product evolves. Material changes will be communicated in-app or by email before they take effect.