Privacy Policy
Last updated 22 September 2026
Draft. Highlighted items are placeholders for your company’s details. Have a lawyer review this page before launch.
Leonard reads your code and your team’s requests so that he can do the work. This page explains what that means for personal information: what we collect, why, who else sees it, and what you can ask us to do with it.
1. Who we are and what this covers
“Leonard”, “we” and “us” mean [Company legal name], a [state] [entity type] located at [address]. This policy covers our website, the Leonard web app, the Leonard GitHub App, the Leonard Slack app, and the account, billing and support around them (together, the “Service”).
When a company signs up, that company is the controller of the code, issues and messages it connects to Leonard, and we process them on its behalf. If your company has a signed agreement with us, that agreement governs where it differs from this policy.
2. What we collect
- Account information: name, work email, company, role, and sign-in details from GitHub, Slack or another identity provider.
- Repository content: the source code, commit history, issues, pull requests and comments in the repositories you grant Leonard access to.
- Requests and messages: Slack messages that mention Leonard, the thread they sit in, GitHub issues assigned to Leonard, and requests made in the web app, including the names and handles of the people who wrote them.
- Work records: what Leonard understood, assumed, ran and changed for each task: commands, test results, build logs and the resulting pull requests.
- Billing information: plan, invoices and payment status. Card details are held by our payment processor, not by us.
- Usage and device data: IP address, browser, pages viewed, and error and performance logs.
- Support communications: anything you send us by email or chat.
Code sometimes contains personal information or secrets by accident. Leonard never fetches
.env files or anything listed in .gitignore, but we ask that you keep personal data
and credentials out of repositories you connect.
3. What Leonard can and cannot reach
Leonard only sees what you connect, and only with the permissions you approve on GitHub and Slack.
- GitHub: reads contents and metadata, and reads and writes issues and pull requests. He
has no access to administration, members, secrets, workflows or deployments. His commits are authored as
leonard[bot], never as a person. - Slack: reads messages only in channels he has been added to, and acts only when mentioned. He does not read direct messages or private channels he isn’t in, and he doesn’t read files or email addresses.
- Merging: Leonard opens pull requests. He never merges them; a person does.
4. How we use it
- To run the Service: understand requests, work in your code, run your tests, and open issues and pull requests.
- To keep the record of each task that your team can review.
- To create and secure accounts, and to prevent abuse and fraud.
- To bill you and provide support.
- To fix problems and improve the Service, using usage and error data.
- To meet legal obligations and enforce our terms.
5. AI models and training
Leonard uses large language models from third-party providers to understand requests and write code. Your content is sent to those providers only to complete your tasks, under terms that do not allow them to train on it.
We do not use your code, issues or messages to train AI models, ours or anyone else’s, unless your company opts in in writing. We may use aggregated, de-identified usage statistics (for example, how long tasks take) to run and improve the Service.
6. Who we share it with
We do not sell personal information and do not share it for cross-context behavioural advertising. We share it only with:
- Service providers who help us run the Service: cloud hosting, AI model providers, payment processing, email, and error monitoring. The current list is at [subprocessors URL].
- Your own team: people in your organisation can see the tasks, messages and records inside it.
- GitHub and Slack: whatever Leonard posts is stored there under their own policies.
- Authorities or counterparties when the law requires it, to protect people’s safety or our rights, or as part of a merger, acquisition or asset sale, with notice to you.
7. Cookies
We use cookies needed for sign-in and security, and a small number for product analytics. Where the law requires consent for non-essential cookies, we ask first.
8. How long we keep it
- Working copies of your repositories are deleted within [24 hours] of a task finishing.
- Task records are kept while your account is active so your team can refer back to them, and deleted within [30 days] of account closure.
- Billing records are kept as long as tax and accounting law requires.
- Backups roll off within [35 days].
9. Security
Each task runs in an isolated container that is destroyed afterwards. Data is encrypted in transit and at rest, and access by our staff is limited and logged. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, and to object to or restrict some processing. Workspace admins can delete tasks and disconnect GitHub or Slack at any time from settings. For anything else, email [privacy@leonard.dev]. We will verify the request and reply within the time the law allows. We will not treat you differently for exercising these rights.
California residents have the rights above under the CCPA and CPRA, including the right to know the categories listed in section 2, the purposes in section 4 and the recipients in section 6. We do not sell or share personal information as those laws define it.
11. International transfers
We are based in the United States, and our providers may process data in other countries. Where the law requires it, we use approved transfer safeguards such as Standard Contractual Clauses.
12. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children.
13. Changes
If we make a material change, we will update the date above and tell workspace admins by email before it takes effect.
14. Contact
[Company legal name], [address]. Email [privacy@leonard.dev].
i think since friday. a couple of customers have emailed us about it