Privacy notice
Draft pending counsel review · Updated October 8, 2026
Who we are and scope
Leash operates Leash, a local agent proxy and optional workspace control service. Contact hello@useleash.dev about personal data. This notice covers Leash accounts, metadata synchronization, reports, payments and support. Your AI provider, employer and tools have their own policies. The operator is based in Israel; the operator must identify its legal entity and hosting locations before public launch.
Data we process
Accounts contain name, email, identity-provider identifiers, organization membership and roles. Local authentication stores salted password hashes; API and CLI credentials are stored as hashes, with expiry and revocation records. Usage metadata includes model/provider, token counts, estimated API cost, timestamps, session IDs, request hashes, repository hashes, branch names and kill reasons. Branch names may reveal project information: choose non-sensitive names. Settings include budgets, invitation email addresses, subscription state and encrypted webhook destinations.
Leash does not persist prompts, response text, tool arguments or source code. The proxy handles request/response content in memory to forward traffic, extract usage and compute loop fingerprints. Provider keys in local mode remain on your machine and are forwarded to your selected provider. Hosted mode forwards prompts in memory. BYOK passthrough keys are not saved; when you explicitly save a provider credential in Settings, Leash stores an encrypted envelope and a last-four-character identifier. Revocation removes the encrypted credential and invalidates its associated virtual keys. Your agent may independently write conversation logs; a requested Burn Report scan reads those files and retains numeric aggregates, not their conversation contents.
Local and synchronized operation
SQLite accounting stays on the machine running the proxy. Metadata synchronization is optional and can be disabled with LEASH_SYNC=0 or LEASH_OFFLINE=1. A configured DATABASE_URL enables metadata sync in the local stack. Inspect the payload with leash sync --dry-run. When you configure a remote database or control service, the selected metadata is transferred there. Do not share a database administrator credential with ordinary workspace members.
Why we use data
We process account and usage data to provide the service, authorize access, maintain budgets, generate reports and fulfill subscriptions. Where applicable, performance of our contract is the basis for service processing; legitimate interests support security, abuse prevention and service reliability, subject to your rights. Legal obligations may require payment or dispute records. Optional public sharing requires your affirmative action. We do not sell personal data or use prompts to train models.
Services and transfers
When enabled, Clerk processes identity and organization information for authentication. When paid checkout is enabled, Polar acts as merchant of record for purchases made through it and processes payment, tax and buyer information under its own terms; Leash receives transaction/subscription identifiers and status, not card numbers. A configured Slack or Discord webhook receives usage/kill notifications. Your AI provider receives proxied requests directly. Hosted PostgreSQL (including Neon), the dashboard host and reverse proxy may process service metadata and connection logs. These services may process data outside Israel or your country; the operator must document regions and any required contractual transfer safeguards for its deployment.
Relevant provider documents: Clerk data processing terms, Polar privacy notice. Marketing tracking is not enabled by Leash. When application email is configured, its provider processes the delivery data described below.
Account emails and requested reports
When the operator enables transactional email, the configured provider (such as Resend) processes the recipient address and the content needed to deliver account confirmations, local password-reset links, workspace invitations and requested reports and opted-in safety alerts. Weekly usage summaries require opt-in and a verified address; disable them in Settings or through the unsubscribe link. Reports contain aggregate usage estimates, not prompts or conversations. Email open and click tracking are disabled by Leash. Clerk manages its own authentication emails when Clerk is configured.
Pending email content is encrypted in the delivery queue. Content is removed after confirmed provider acceptance, except confirmation links retained until their short expiry to validate the recipient. Other queued or uncertain content expires after its operational lifetime. Delivery status metadata remains subject to the operator’s retention policy. Provider acceptance does not guarantee inbox delivery.
Enterprise enquiries
When you submit an Enterprise enquiry, we store your name, work email, company, team size, number of devices and message to respond to your request. When configured, Resend delivers the enquiry to hello@useleash.dev. Otherwise it remains in the operator’s local database for follow-up. Please do not include credentials, prompts or customer data. Contact us to request removal.
Cookies and sharing
The application uses necessary authentication cookies. Local session cookies are HttpOnly and SameSite=Lax, and Secure in staging/production. Clerk manages its own necessary identity cookies when configured. No advertising cookies are included. Public report links expose aggregate numbers only after explicit sharing; recipients can copy them. Revoke a link in the report gallery to stop future access, but revocation cannot erase copies already made.
Retention, deletion and security
Local data remains until the machine owner deletes it. Synchronized records remain until the workspace owner or operator deletes them under the deployment’s retention policy. Plan history windows restrict visibility; they do not automatically erase database records. Workspace archival retains accounting history and revokes access tokens. Request deletion or an export by contacting us or your workspace owner. Backups may retain deleted records until their configured expiry; legally required payment records may be retained longer. We use access controls, RLS-scoped requests, hashed credentials and encrypted webhook storage. No system is immune to compromise.
Your choices and rights
Depending on your location, you may have rights of access, correction, deletion, portability, restriction or objection, and a right to complain to your local privacy regulator. Contact us to exercise them; we may verify your identity and coordinate with your workspace owner. Business customers control their workspace metadata; contact us for applicable data-processing terms. The service is for adults and professional users, not directed to children. Material changes to this notice will be communicated through the application or account contact details before taking effect where required.