Privacy Policy And Data Handling
Last Updated: July 2026
1. Introduction and Scope
This Privacy Policy and Data Handling Statement ("Privacy Policy") describes how Leanvera ("Leanvera," "we," "our," or "us") collects, processes, stores, and protects data in connection with the Leanvera AI Creative Director Platform ("Platform"). This Policy applies to all Agency Users, their personnel, and any data relating to their clients that is processed through the Platform.
Because Leanvera is a B2B platform, Agency Users act as data controllers with respect to any client data they input into the Platform. Leanvera acts as a data processor on their behalf for such data. Agency Users are responsible for ensuring they have the appropriate legal basis and client consents to input any third-party data into the Platform.
2. Data We Collect
2.1 Account and Subscription Data.
● Business name, primary contact name, and professional email address.
● Billing information (processed and stored by our third-party payment processor — Leanvera does not store raw payment card data)
● Subscription tier and account configuration settings.
2.2 Strategic Input Data (User-Provided)
When an Agency User generates a Strategy Blueprint, Hook Framework, or configures a Brand Voice Profile, they may provide:
● Product descriptions, campaign goals, and target audience parameters.
● Brand identity constraints, restricted keywords, and tonal guidelines.
● Competitive positioning information and market context.
This data is classified as Strategic Input Data. It is processed solely to generate the requested Platform output. It is not used to train, fine-tune, or augment Leanvera's AI models in a way that could influence outputs generated for any other user or workspace.
2.3 Platform Usage Data
● Log data, session timestamps, feature interactions, and error reports (used for platform stability and improvement);
● Device type, browser, and IP address (used for security and fraud prevention purposes).
3. Isolated Client Workspace Data Architecture — Zero Cross-Contamination Guarantee
This section constitutes Leanvera's formal data isolation commitment. The Platform is architected around the principle of complete logical segregation between Active Client Workspaces.
Specifically, Leanvera guarantees the following:
● Workspace Isolation: All Strategic Input Data, Brand Voice Profile configurations, generation history, and stored outputs within Workspace A are maintained in a logically
segregated data partition that is completely inaccessible to Workspace B, regardless of whether accounts are linked.
● No Cross-Training: A Brand Voice Profile saved in Workspace A (containing client-specific tone data and restrictions) cannot influence, inform, or contaminate the generation
environment of Workspace B. The context window draws exclusively from that isolated workspace's active configuration.
● No Cross-Retrieval: Platform queries, API calls to processing pipelines, and data search actions are structurally scoped strictly to the individual active workspace boundary. No
retrieval-augmented generation or semantic search mechanism queries across workspace boundaries.
● Logical Access Controls: Role-based account security permissions ensure that authorized agency personnel can only view or interact with active client workspaces they possess
explicit clearance to access.
4. Third-Party AI Inference Services and API Data Handling
To generate Platform outputs, Leanvera transmits Strategic Input Data to one or more third-party AI text inference API providers. The following data handling commitments apply to this process:
● Data in Transit: All data transmitted to secure third-party enterprise processing architectures is fully encrypted in transit using TLS 1.3 protections.
● Data at Rest: Stored configurations, Brand Voice Profiles, and active workspace parameters are secured natively using industry-standard AES-256 encryption keys.
● Zero Model Vendor Training: Leanvera enforces enterprise-tier data protection agreements with all infrastructure processing vendors. Input parameters are used strictly for
immediate generation execution and are contractually restricted from being retained or used for vendor model optimization training.
● Multi-Modal and Asset Pipeline Processing: For workflows utilizing automated asset pipelines (including native typography renders or AI voiceover generation modules), data arrays
remain subject to the exact same isolated encryption and non-retention commitments described across this policy.
5. Data Retention and Deletion
● Active workspace data is securely retained for the duration of an active user subscription. Following an explicit account termination or cancellation, data remains accessible within a
secure pool for thirty (60) days solely to enable historical export operations.
● Following the post-closure retention period, all Strategic Input Data, Brand Voice Profiles, and generation history associated with the account are permanently deleted from
Leanvera's systems.
● Users may request deletion of specific workspace data at any time by submitting a written request to the contact address in Section 9.
6. Dedicated Slack Support Channel — Data Handling
Agency Users on qualifying subscription tiers may receive support through a dedicated Slack channel. Users should not share sensitive client personal data, confidential client strategic data, or raw client brief contents within Slack support channels. Support interactions conducted through Slack are subject to Slack Inc.'s own privacy policy and terms of service in addition to this Policy.
7. Ad Platform Synchronization — Meta and TikTok
Higher-tier subscribers may connect Leanvera to their Meta Ads Manager and/or TikTok Ads Manager accounts for the purpose of direct output synchronization. The following applies to this feature:
● Leanvera accesses only the ad account permissions explicitly granted by the Agency User during the OAuth authorization flow;
● Leanvera does not access, store, or process raw audience data, pixel data, or individual consumer data from connected ad accounts;
● The connection is limited to the delivery of structured strategic output content (e.g., campaign hook copy and creative direction text) to the designated ad account;
● Agency Users are responsible for ensuring their use of this synchronization feature complies with Meta's and TikTok's respective platform policies and advertising terms.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, port, or request deletion of personal data held by Leanvera. To exercise any such rights, submit a written request to the contact address below. Leanvera will respond within the timeframe required by applicable law.
9. Contact
For privacy-related inquiries: support@leanvera.com