This notice covers the website/waitlist and mobile releases presenting this document version. It accompanies the Privacy Policy; older beta disclosures are archived.
Cookie, Storage and Analytics Notice
Necessary website and app storage, optional PostHog analytics and withdrawal.
Last updated:
Document version: leo-mobile-analytics-2026-09-v1
1. Website technologies
This static website does not intentionally set optional analytics, advertising or personalization cookies, pixels or browser-tracking storage. No optional-cookie preference banner is needed for its current configuration. If optional technology is introduced, the notice and required consent mechanism must be in place before it starts.
Vercel processes request metadata to deliver and protect the site; server logs are not cookies stored on your device. The waitlist form sends your chosen details to Supabase without creating a persistent browser login session. See the Privacy Policy for website data and rights.
2. Storage for requested app features
Leo stores authentication/session information, language and other settings, account-scoped cached records and offline queues using app storage and SQLite. Notification tokens and installation identifiers support requested notifications. Subscription services use account and purchase identifiers to recognize access. These functional purposes do not authorize optional product analytics.
Ordinary sign-out may preserve unsynced account work for the same owner's return. Account deletion triggers the applicable local purge; other offline installations finish on reconnect. Uninstalling or clearing app storage does not itself delete server records or cancel a store subscription.
3. Optional PostHog EU analytics
The analytics choice starts off. After explicit opt-in and current account/consent checks, a reviewed set of feature-use events passes through Leo's authenticated backend to PostHog EU. The backend checks each event again. No pre-consent interaction history is collected or replayed. Core access does not depend on opting in.
Events include the Leo account identifier, time, feature and limited properties such as input route, settings, bounded counts or subscription plan. They exclude health-entry values, chat/photo content, food descriptions and free-text answers. Feature names may still reveal health-related activities or interests. These are account-linked, pseudonymous events, not anonymous data.
No PostHog mobile SDK, advertising identifiers, session replay, automatic screen-content recording or geolocation enrichment are enabled. PostHog receives network information from Leo's backend connection; the capture payload does not forward your device IP.
4. Analytics storage and retention
The app holds pending event sends in memory only, without a persistent event queue, batching or automatic retries. Leo separately stores consent evidence and durable offline withdrawal requests. Closing the app does not erase events already delivered to a provider.
PostHog's current Free plan retains product events for up to one year, with earlier erasure when withdrawal or another erasure ground requires it. This provider period does not certify a tested physical purge of every copy. Limited coordination evidence remains while necessary to complete and verify cleanup or meet a specific obligation. Provider logs and recovery copies are distinct from a local event queue; see the Privacy Policy's retention criteria.
5. Choose, withdraw and check cleanup
Refuse analytics at onboarding or change it in Profile → Product analytics. Turning it off stops collection on that installation and cancels pending local sends. Offline withdrawal is stored and reaches the server on reconnect. Other signed-in installations receive or recheck the updated preference; the server independently checks new events. Already-admitted delivery may finish.
When the server receives withdrawal, it starts erasing identifiable analytics held solely on that consent without another request. Settings show cleanup status and let you refresh it. An asynchronous provider acceptance is not completed erasure. Analytics remains off during cleanup and can resume only after verified completion and a new explicit choice. Contact support@meetleo.app for help or request status.
6. Separate choices and changes
Browser settings, mobile analytics, marketing, health/AI choices and OS health/notification permissions have different effects. None substitutes for the others. The website waitlist and mobile account are separate. We do not use these technologies for advertising across other companies' apps or sites.
Material changes in purpose, information or provider arrangements are explained before affected collection and require a new consent when applicable. The exact notice version and language are recorded with your choice; prior versions remain accessible in the archive.