← Back to home

The mobile provisions apply to Leo releases that present this document version for acceptance. Section 14 also covers this website and its separate waitlist. Earlier beta disclosures remain in the archive.

Leo Privacy Policy

Your information, health and AI choices, optional analytics, retention and privacy rights in Leo.

Last updated:

Document version: leo-mobile-privacy-2026-09-v1

1. Who is responsible

PH Art & Culture Consulting SRL is the controller of the personal information described here. Our registered office is 80 Rue Alphonse Renard, 1180 Uccle, Belgium; enterprise number 1000.885.590; VAT BE1000.885.590. Contact support@meetleo.app or +32 491 37 55 57 for privacy, support or rights requests.

Leo supports everyday nutrition, activity and wellbeing. It is an AI wellness companion, not a clinician or emergency service. You must be at least 18 to use the mobile service. A declaration of age is not identity verification.

2. Information used by Leo

Account information includes your email, account identifier, authentication credentials and sessions, first name, self-entered date of birth, language, units, timezone and preferences. Supabase Auth handles account authentication.

Health and wellbeing information can include height, weight and goals, nutrition targets, meals, ingredients and nutrients, recipes, exercise, steps, active energy, fasting and progress. Diet, allergies, health-focus answers, pregnancy information and free text can reveal sensitive health information.

We also process messages and responses, selected quotations, conversation summaries and images you submit. Summaries can retain information from earlier chats. Purchases involve store/product/transaction identifiers and subscription status; we do not receive full payment-card details through store checkout. Support correspondence contains what you send us. Please avoid unnecessary information about another person.

Service information includes network addresses, request times, authentication/security events, errors, app/platform information, notification tokens, installation identifiers and delivery records. Consent records identify the account, choices, relevant document versions and language, time and available request network/platform information.

3. Purposes and legal grounds

We use basic account, settings and subscription information to perform our contract with you (GDPR Article 6(1)(b)). We process health information for tracking and personalization with your consent under Article 6(1)(a) and explicit health-data consent under Article 9(2)(a). Third-party AI processing has a separate explicit choice on those consent grounds where health data is involved.

Optional account-linked product analytics and promotional email each require a separate consent. Analytics feature names may reveal health-related activity, so its explanation covers that sensitive aspect. Consent is not inferred from accepting the Terms or acknowledging this policy.

Necessary account security, abuse prevention and technical investigation rely on our legitimate interests in a secure, reliable service (Article 6(1)(f)); this is not permission for unrelated health-content analytics. Specific legal obligations and rights requests rely on Article 6(1)(c). Restricted records needed for legal claims rely on the applicable legal ground, including Article 9(2)(f) where necessary for health data. Service notifications use the requested service basis and the relevant health/AI permissions for sensitive personalization.

6. Google processing and retention

The selected Gemini 2.5 Flash configuration uses the europe-west4 Vertex endpoint with supported EU machine-learning processing. This does not mean that every Leo provider, support operation or network hop is confined to one EU country. We have disabled Google's project memory cache and model request/response logging for this configuration.

We do not instruct Google to use private Leo health records, messages or images to train a general-purpose model. Google's managed-model terms restrict training or fine-tuning with customer data without prior permission or instruction. This is separate from security and abuse monitoring. Under Google's standard Cloud terms, suspicious prompts can be retained for up to 90 days and reviewed by authorized staff. We do not claim an exemption or zero retention. Withdrawing in Leo cannot instantly recall a request already received by Google.

Google data retention informationGoogle abuse monitoring

7. Optional analytics and marketing

If you separately opt in, Leo sends reviewed product events through its authenticated backend to PostHog EU. They include an account-linked identifier, event time, the feature used and limited bounded properties such as input method, a setting or subscription plan. They exclude health-entry values, chat text, photos, food descriptions and free-text answers. Feature use can nevertheless reveal health-related activities or interests; the information is pseudonymous, not anonymous.

There is no PostHog mobile SDK, session replay, advertising identifier collection, automatic screen-content capture or geolocation enrichment. The backend checks current consent before forwarding an event. PostHog receives the backend connection's network information; the event payload does not forward your device IP. See the Tracking and Analytics Notice for storage and withdrawal. Declining analytics does not remove core app access.

Optional Leo news and offers by email require the separate marketing choice. You can ask support@meetleo.app to withdraw it. Account, security and transaction communications are separate. We do not sell personal information or use health records for targeted advertising.

8. Recipients and locations

Supabase provides authentication, database, uploaded-file storage and backend processing; the primary project is in Frankfurt, Germany. Google Cloud Vertex AI receives the task-specific AI input above. PostHog EU receives opted-in analytics. RevenueCat administers purchase validation and subscription access. Apple and Google operate the stores and process transactions under their own roles and terms.

Open Food Facts receives search terms or barcodes through Leo's backend; we do not deliberately attach an account identifier or forward your device IP, although a search term itself may identify someone. Expo, Apple Push Notification service and Firebase Cloud Messaging process notification tokens, routing details and message payloads. Personalized notification text may be visible in device previews. Our support email service processes correspondence you send. Authorized personnel access information as needed for the relevant purpose.

Some providers, support teams and subprocessors operate outside the EEA. EU hosting is not an assurance that all processing stays in the EEA. You can obtain information about the applicable recipient arrangements and international-transfer safeguards, including relevant contractual terms, from support@meetleo.app. We may disclose information where law requires it or for a necessary legal claim, with the protections applicable to sensitive data.

9. Changing choices and withdrawing consent

Use Profile → Health and AI choices to change or withdraw either purpose. Health withdrawal also stops AI and starts erasure of the health profile, health logs, imported health records and AI history held for those purposes. Account controls and your subscription remain. AI-only withdrawal stops AI functions and starts erasure of AI chat history and unconfirmed photo entries waiting to sync; manually tracked health records remain when health consent is on.

Use Profile → Product analytics to turn analytics off. Collection stops on that installation and pending local sends are cancelled. When the server receives withdrawal, it starts erasing identifiable analytics held solely on that consent without a second request. Cleanup status is shown in settings. Re-enabling the affected purpose requires completed cleanup and a new choice.

Offline withdrawal is retained locally for reconciliation when online. Other offline devices finish local cleanup on reconnect. Work already admitted to an external service may finish; provider processing can be asynchronous. Withdrawal does not make earlier lawful processing unlawful. Stopping Health Sync alone prevents future imports; it does not erase saved Leo records or revoke OS permissions. Store subscriptions do not automatically end when a consent is withdrawn.

10. Retention

Profile, health records, conversations, summaries and uploaded files are kept for the relevant account purpose until applicable erasure or consent withdrawal. There is no general automatic expiry solely because an account becomes inactive. Consent records are kept with the account to apply and demonstrate choices; account erasure removes those account consent rows. Minimal erasure-coordination evidence remains while needed to complete or verify removal, resolve failures or meet a specific obligation or claim.

PostHog's current Free plan retains product events for up to one year, with earlier erasure when withdrawal or another erasure ground requires it. This provider period does not certify a tested physical purge of every copy. Unresolved provider requests remain blocked pending verified completion. Disabled push registrations and eligible terminal delivery records normally become cleanup candidates after 90 days; active registrations and still-relevant check-in records follow their functional lifecycle.

We keep support correspondence and attachments for resolving the request, necessary follow-up or an identified dispute, and remove them when no longer needed for those purposes. Transaction and subscription records may remain after account deletion for reconciliation, accounting obligations or disputes; this is not a reason to retain the full health profile. Security and provider operational records follow their specific protection, investigation and recovery purposes.

The current primary project has no scheduled customer database backup plan. This does not mean no provider recovery copy or independent export can exist. Restricted recovery copies and authorized exports must respect the same purpose limits; restoration must reapply earlier erasure requests. We do not promise immediate removal of every provider log or backup. Ask us for the applicable retention criteria or the status of a particular request.

11. Security and local storage

We use authenticated access, owner-based data restrictions, protected network transport and provider security controls. No service can guarantee absolute security. Leo uses local storage and SQLite for supported offline records, settings and pending changes. These rely on the device's application sandbox and platform protections; we do not claim application-managed or end-to-end encryption. Protect your device with a screen lock.

Signing out may preserve account-scoped unsynced work for the same owner's return. Confirmed account deletion triggers local purge; other offline installations complete cleanup when they reconnect. Uninstalling is not a substitute for a server deletion request. Shared exports leave Leo's control. We assess breaches and notify the authority or affected people when legally required.

12. Deletion and export

Use Profile → Delete account to request account deletion, or contact support if you cannot access the app. The process records the request, restricts normal account activity and coordinates removal across the account and relevant services. Acceptance of a request does not mean all asynchronous provider erasure has finished. We erase information as required without undue delay and explain any lawful retention or restriction.

Deletion does not cancel your Apple or Google subscription, erase the originals in Apple Health or Health Connect, remove files you shared elsewhere or automatically identify a separate waitlist address. Tell us if your request should cover the waitlist too.

Profile → Export my data supplies a JSON export of supported server-held records, including consent and privacy status and uploaded-file metadata. It does not include every file's bytes, unsynced local change or independent provider dataset. This does not limit your right to request a more complete response.

13. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or portability, object to legitimate-interest processing and direct marketing, and withdraw consent. Applicable protections against solely automated decisions with legal or similarly significant effects remain. Contact support@meetleo.app; we may proportionately verify identity where there is reasonable doubt.

We normally respond without charge within one month. A legally permitted complexity/volume extension can add up to two months; we explain it within the first month. This response deadline is not a universal physical-deletion deadline. You may complain to Belgium's Autorité de protection des données / Gegevensbeschermingsautoriteit or another competent supervisory authority, including where you live or work in the EEA.

Belgian Data Protection Authority

14. Website and separate waitlist

This static website is hosted by Vercel, which processes technical request information to deliver and secure it. The site does not intentionally deploy optional cookies, advertising pixels or browser analytics. Supabase stores waitlist email, page language, signup source and consent/creation timestamps in the EU project. We do not intentionally collect health information through the waitlist.

Waitlist launch and early-access email relies on the consent you give on the form. You may withdraw through support@meetleo.app; this does not prevent visiting the site or independently creating an eligible mobile account. Waitlist data is kept while relevant updates are sent, until withdrawal or it is no longer needed; a minimal suppression record may remain to respect an opt-out. Necessary site security metadata serves our legitimate interest in reliability and abuse prevention. Provider operational and transfer considerations in this policy also apply.

The online contract-withdrawal function collects your name, account email, contract details, language, request identifier and submission time to record and handle your declaration and supply its receipt. This serves our consumer-law obligations (Article 6(1)(c)). We keep the declaration and handling evidence for the applicable obligation and any identified dispute or claim; access is restricted and information is removed when no longer required. Do not include health information, passwords or full payment-card details.

15. Age, versions and changes

The mobile service is for adults aged 18 or over. We do not present self-declared age as verified identity. If we learn that an ineligible person's information was collected, we assess and restrict or erase it as required; contact support with concerns.

This policy is identified by its document version and date. It applies to mobile processing when this version is presented in Leo. Material changes are explained before the affected processing begins; a new purpose requiring consent needs a new choice. Continuing to use Leo alone is not new health, AI, analytics or marketing consent. Archived versions remain available through the links below.