Leonality Back to home

Draft — replace placeholders before publication. English launch version. Last updated: June 29, 2026.

Privacy Policy — Leonality

Status: Draft for launch review
Last updated: June 29, 2026
Language: English. This English version is intended to be the public launch version until a localized version is published.

Draft: Replace all placeholders before publication. This document does not replace legal advice.


1. Controller and Contact

Controller for the processing of personal data:

[Company or full legal name]
[Street and house number]
[Postal code] [City]
[Country]

Represented by: [Owner / managing director / authorized representative]

Contact:

  • Privacy: privacy@leonality.com
  • General support: hello@leonality.com
  • Imprint / legal notice: https://leonality.com/imprint.html

Data protection officer: [not appointed / details to be added if appointed]

Supervisory authority: [competent authority based on provider location]


2. Scope

This Privacy Policy explains how Leonality processes personal data when you use:

  • the Leonality mobile app,
  • cloud sync and account features,
  • AI features,
  • optional marketing and product emails,
  • the website at leonality.com,
  • support and privacy communication.

Leonality is an offline-first app. Some data remains only on your device unless you use account-based cloud features.


3. Important Safety and Sensitive Data Notice

Leonality is a tool for progress tracking, reflection, and personal organization.

Leonality does not provide medical, psychological, psychiatric, legal, financial, or other professional advice, diagnosis, or treatment.

Do not enter information that you do not want to store locally, sync to your account, or submit to an AI provider when using AI features. This is especially important for health data, crisis-related content, information about third parties, passwords, secrets, and highly sensitive personal details.

If you are in immediate danger, may harm yourself or others, or are experiencing an acute crisis, contact local emergency services immediately (for example 112 in the EU) or reach out to a trusted person or professional crisis service. Leonality is not an emergency service and is not monitored for crisis intervention.


4. Main Data Categories

Category Examples Storage / Recipient
Account data Email, OAuth identity, username, session metadata Supabase Auth
App content Goals, charts, tasks, routines, journal, diary, reviews, preferences Local device; Supabase if sync is used
AI requests Prompts, selected app context, generated responses Supabase Edge Function; Mistral AI
AI results Generated suggestions, summaries, insights, audits Local device; Supabase if saved/synced
Entitlements Premium status, AI counters, quota state Supabase
Analytics app_open, allowed feature_used IDs, platform, app version Supabase; no user ID in analytics event records
Error reports / feedback Voluntary reports, feedback messages, app version, platform Supabase
Marketing email consent Email, status, consent version, timestamps, DOI/unsubscribe tokens Supabase; Resend for email delivery
Website logs IP address, URL, user agent, timestamp, status code Website hosting provider
Support email Email address, message content, metadata Email provider
Purchases (planned) Store purchase status, transaction identifiers, entitlement state Apple / Google / RevenueCat / Supabase when IAP is active

5. Account, Authentication, and Sync

You can use Leonality locally. A registered account is required for cloud sync, account-based AI access, marketing email settings, and account deletion.

Login methods may include email/password, Sign in with Apple, Sign in with Google, and limited technical anonymous sessions.

Cloud data is hosted in Supabase. The current Supabase project is in Central EU (Frankfurt).

Legal bases may include contract performance, legitimate interests in security and service operation, legal obligations, and consent where required.


6. App Content and Local Data

App content is stored locally on your device. If you use cloud sync, app content is also stored in Supabase and linked to your account.

This may include sensitive reflections depending on what you choose to enter. You control the content you enter and should avoid unnecessary sensitive data.

Deleting local data or uninstalling the app does not necessarily delete cloud data. For full account deletion, use Account & Login → Delete account or contact privacy@leonality.com.


7. AI Features

Leonality uses generative AI via a server-side Supabase Edge Function. The AI provider is currently Mistral AI SAS.

AI requests may include the content needed for the selected feature, such as goals, journal entries, evening review notes, routine context, or other planning information. The exact context depends on the AI action you trigger.

AI outputs:

  • are automatically generated,
  • may be inaccurate, incomplete, unsuitable, or hallucinated,
  • are suggestions only,
  • are not professional advice,
  • must be reviewed by you before use.

Leonality does not use AI to make legally or similarly significant automated decisions about you.

7.1 Crisis and Health-Related Content

AI features are not designed to diagnose, treat, or detect medical or mental health conditions. They are also not designed to provide crisis intervention.

If you enter self-harm, suicide, abuse, violence, severe distress, medical, medication, addiction, eating disorder, or similar content, the AI may still fail to respond appropriately. Do not rely on Leonality for emergency support or professional care.

7.2 EU AI Act Transparency

The app includes:

  • a first-use AI transparency notice,
  • AI hints near AI actions,
  • labels for AI-generated or AI-suggested content.

Internal AI Act tracking is documented in docs/ai-act-internal-checklist.md.


8. Product Analytics

Leonality collects minimal product analytics to improve stability and usability.

Analytics events currently include:

  • app opens,
  • predefined feature usage IDs,
  • platform,
  • app version.

Analytics event records do not include:

  • user IDs,
  • device IDs,
  • location data,
  • journal/task/goal text,
  • analytics-specific IP storage in event records.

The legal basis is legitimate interest in product improvement and stability. Raw analytics events are retained for up to 24 months, then deleted or aggregated.

You may object to processing based on legitimate interests by contacting privacy@leonality.com.


9. Error Reports and Feedback

You may voluntarily send feedback or error reports. These may include a user ID, message text, app version, platform, and technical context.

Feedback and error reports are used for support, product quality, bug fixing, and security. They are not used to train external AI models.

Retention:

  • individual error reports: up to 12 months after handling or until account deletion,
  • aggregated error issues: until resolved plus up to 6 months,
  • user feedback: up to 24 months or until account deletion.

10. Local Notifications

Leonality may schedule local reminders on your device if you enable them. These are local notifications and are not sent through our servers.

You can disable reminders in the app or through your operating system settings.


11. Export, Reset, and Deletion

The app may offer JSON export and chart export features. Exported files are under your control.

Reset all data removes local app data from the device. It does not delete cloud data.

Full account deletion is available in the app under Account & Login → Delete account and can also be requested by email. Cloud records linked to your Supabase user are deleted according to database deletion rules, subject to backups and legal retention obligations.

Backups may retain deleted production data temporarily until backup rotation. Exact backup retention depends on Supabase and hosting provider policies.


12. Marketing and Product Emails

Marketing and product emails are optional and require double opt-in.

If you opt in:

  • your email address and consent status are stored in Supabase,
  • a confirmation email is sent via Resend from Leonality <info@leonality.com>,
  • emails are sent only after confirmation,
  • you can unsubscribe via an email link, app settings, or privacy@leonality.com.

Consent data is not automatically deleted on a fixed schedule while there is a legitimate need to retain proof of consent or unsubscribe status. It is deleted or restricted when required by law, account deletion, or valid deletion request.


13. Premium and Purchases

Premium in-app purchases are currently planned / store-controlled. If IAP is not active, no payment is processed.

When IAP is active, Apple and Google process payments. RevenueCat may be used for entitlement management and purchase validation. We do not receive full payment card details.

The final IAP data flow, product identifiers, transaction retention, and RevenueCat setup must be confirmed before paid launch.


14. Website

The website at leonality.com is a static marketing website. It does not provide app login or access to your app content.

The website may process server logs through the hosting provider, including IP address, user agent, requested URL, timestamp, and status code.

Current website pages may load Google Fonts and Tailwind CDN. Before publication, the website should either self-host fonts/CSS or document and implement any required consent solution.

Website hosting provider: [provider, region, and DPA to be added]

Email provider: [provider and DPA to be added]


15. Processors and Recipients

Current or planned recipients include:

Provider Purpose Notes
Supabase, Inc. Auth, database, Edge Functions, RPCs Central EU (Frankfurt) project region
Mistral AI SAS AI inference DPA / retention details to be added
Resend, Inc. Double opt-in and marketing email delivery; internal digest emails DPA to be added
Apple Inc. Sign in with Apple, App Store distribution, IAP Independent controller for store account/payment areas
Google LLC Sign in with Google, Google Play, website fonts if used Independent controller for store/account areas
RevenueCat Purchase entitlement management, if IAP is active DPA/setup to be confirmed
Website host Static website delivery and logs Provider details to be added
Email provider Support and privacy email Provider details to be added

We do not sell personal data.


16. International Transfers

Some providers are based outside the EEA or may allow access from outside the EEA. Where required, we rely on Data Processing Agreements, Standard Contractual Clauses, adequacy decisions, EU-US Data Privacy Framework certification where applicable, and technical safeguards such as TLS and data minimization.

DPA/SCC links for Supabase, Mistral, Resend, website hosting, and email provider must be added before publication.


17. Your Rights

Depending on applicable law, you may have the right to:

  • access your data,
  • correct inaccurate data,
  • delete data,
  • restrict processing,
  • object to processing based on legitimate interests,
  • withdraw consent,
  • receive data portability where applicable,
  • lodge a complaint with a supervisory authority.

Contact: privacy@leonality.com

We may need to verify your identity before responding to requests.


18. Security

Leonality uses technical and organizational measures such as HTTPS/TLS, Supabase Row Level Security, server-side API keys, role-based access, and data minimization.

No system is perfectly secure. You should protect your device, keep your operating system updated, and avoid entering unnecessary sensitive data.


19. Children

Leonality is not directed at children. The current launch documents set the minimum age at 16 years. Users below that age should use Leonality only with parental or guardian consent.

The app store age rating must be aligned with this statement before launch.


20. App Store Privacy / Data Safety

Apple Privacy Nutrition Labels and Google Play Data Safety forms must match this Privacy Policy.

Current working assumptions:

  • contact info: collected for accounts and email communication,
  • user content: collected for app functionality and sync,
  • identifiers: collected for accounts,
  • usage data: collected minimally and not linked in analytics event records,
  • diagnostics: collected for voluntary reports,
  • purchases: collected only once IAP is active,
  • tracking: no advertising or cross-app tracking.

See also docs/app-store-privacy-checklist.md.


21. Changes

We may update this Privacy Policy when the product, legal requirements, providers, or processing practices change. Material changes may be communicated in the app, by email, or on the website.


22. Open Launch Items

Before publication, complete:

  • controller identity and imprint details,
  • supervisory authority and DPO status,
  • website host and email provider,
  • DPA/SCC links for providers,
  • self-hosting or consent decision for website fonts/CDN,
  • IAP/RevenueCat details if premium purchases go live,
  • final App Store / Google Play privacy forms.

Terms of Service · Imprint · Home