Privacy Policy

Effective date: October 2, 2026

This policy explains what Leap AI (“Leap,” “we,” “us,” or “our”) collects when you use our studio, API and MCP server, how we use it, who else processes it, and what rights you have. The short version: we use your content only to run Leap for you, we use Stripe for payments so we never see your card details, and we do not use your content to train AI models.

1. Information We Collect

Account information

When you sign up we receive your email address and, if you use Google, your name and a link to your Google profile picture. If you use an email link, we just have your email, and the name you give us. We do not collect a password.

Workspaces

We keep each workspace’s name, its members and their roles, and the email addresses of the people its members invite. Members of a workspace can see each other’s name, email address and picture.

Your content and results

When you run a model or a preset, we store:

  • What you asked for: your prompt, your settings, and the photos and other files you upload, with their file names.
  • The images and videos the model made.
  • A record of each run: the model or preset, its status, its timing, what it cost us and what we charged.

We store these so you can see your history and use your results.

Billing information

Payments are processed by Stripe. Your payment card and billing address are collected and stored by Stripe; we never see or store full card numbers. We receive from Stripe a customer ID, the amount and status of each top-up, and the brand and last four digits of a saved card, for your reference.

Technical information

We receive your IP address and basic request headers, which we use for rate limiting and abuse prevention.

We also keep the IP address and browser of each signed-in session, the IP address with which you accepted the Terms of Service, and IP addresses in our server logs. To give the welcome credit only once per person, we keep a one-way scrambled (hashed) form of your email address.

Cookies and analytics

We use a small number of strictly necessary cookies to keep you signed in, and one that remembers, for an hour, which Terms of Service the sign-in page showed you. We use PostHog for product analytics and error reports. PostHog sets a cookie and uses your browser’s storage to recognize your browser, records the pages you view and what you click, and may record your session on our pages to help us fix problems. When you sign in, we link this to your account. We do not use ad-tracking pixels.

2. How We Use Your Information

  • To provide the Service: to send your requests to the model that runs them, store the results and show you your history.
  • To process payments through Stripe and manage your credit.
  • To send transactional emails, such as sign-in links and workspace invitations, via Resend.
  • To improve the Service (for example, by reviewing anonymized aggregate metrics and debugging failures).
  • To prevent abuse, enforce rate limits, and keep the Service available.
  • To comply with legal obligations.

We do not use your content to train or fine-tune AI models, we do not use it in our marketing without asking you first, and we do not sell your personal information.

3. Third-Party Processors

We rely on the following processors. Each has its own privacy practices:

  • Vercel hosts the website and the API, stores your uploads and results, and runs Vercel AI Gateway, which sends each run to the model provider.
  • Model providers, through Vercel AI Gateway: Google, OpenAI, ByteDance, Black Forest Labs, Kuaishou (Kling), Alibaba, xAI, Recraft, MiniMax and Meta. The provider of the model you run receives your prompt and files for that run and sends back the result.
  • PlanetScale is our database, in the United States.
  • Stripe processes payments and refunds.
  • Resend sends our emails.
  • PostHog receives product analytics, error reports and server logs.
  • Upstash keeps short-lived counters for rate limits, and a short-lived cache.
  • Trigger.dev schedules long runs, such as videos. It receives only the identifier of a run, not your prompt or files.
  • Google provides sign-in with Google, only if you choose it.

These providers process data to provide their services to us. Some may keep it for a short time under their own terms for security and abuse monitoring. We will update this list when we add or change a provider.

4. Data Retention

  • Your content and results (prompts, uploads, results and run records): kept while your workspace exists, so you can come back to them. Deleting a workspace deletes its records. Email us to have its stored files deleted too.
  • Account information (email, name, top-up history): kept while your account is active, and for a reasonable period after closure for tax, billing, and legal compliance.
  • Payment records: kept for as long as tax and accounting law requires.
  • Terms acceptances and welcome credit records: kept after an account is closed, to show what was accepted and to give the welcome credit once per person.
  • Aggregate metrics (counts, timings, error rates with no prompts or files): kept indefinitely.

5. Your Rights

Depending on where you live (for example, under GDPR in the EU/UK or CCPA in California), you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or incomplete.
  • Delete your data (“right to be forgotten”).
  • Export a copy of your data in a machine-readable format.
  • Object to or restrict certain processing.
  • Opt out of any processing classified as a “sale” or “sharing” under your local law (we do not sell personal information).

To exercise any of these rights, email support@mail.tryleap.ai from the address tied to your account. We aim to respond within 30 days.

6. Deleting Your Data

The fastest way to delete your data is to email support@mail.tryleap.ai from your account email and ask us to delete your account. We will remove your account record, your content and results, and your billing metadata. Some records may be retained where required for tax, billing, or legal compliance, and aggregate metrics that no longer identify you are kept. A self-serve delete flow is on our roadmap.

The owner of a workspace can delete it in its settings, with its members, invitations, API keys, run records and credit history.

7. Photos of People

You can upload photos of people for presets such as portraits and headshots. We use them only to make the results you ask for, and the model provider receives them for that run. We do not create or keep a face template or faceprint, and we do not use your photo to work out who you are.

Upload a photo of a person only if you have the right to, as the Acceptable Use Policy describes. If you appear in a result someone else made, you can ask us to remove it even if you do not have a Leap account.

8. Security

We use HTTPS/TLS for all traffic between your browser and our servers. Sign-in links expire after ten minutes.

Your files are private. We deliver them through links that are hard to guess and expire after 24 hours, but anyone who has a link can open the file until then, so share links with care. We store API keys only in a scrambled (hashed) form and show each key once.

We rate limit our endpoints to prevent abuse. No system is perfectly secure, but we take reasonable measures to protect your information and continue to improve them.

9. Children

Leap is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has signed up, contact us at support@mail.tryleap.ai and we will delete the account.

10. International Data Transfers

Our infrastructure is operated primarily in the United States. If you use the Service from outside the United States, your data will be transferred to and processed in the US. Model providers may process it in the United States and other countries. By using the Service you consent to this transfer.

11. Changes to This Policy

We may update this policy as the Service evolves. If changes are material, we will notify you by email or with a notice in the app before they take effect. The “Effective date” at the top reflects the most recent update.

12. Contact

Questions about this policy or your data? Email us at support@mail.tryleap.ai.