LEAK Privacy Policy
Last updated: September 13, 2026
This Privacy Policy explains what information LEAK (“LEAK,” “we,” “us”) collects when you use the LEAK application (the “Service”), why we collect it, who we share it with, and the choices available to you. It applies to visitors, account holders, and the businesses they represent.
1. Information we collect
We collect the following categories of information:
- Account information: your name, email address, business name and industry, and a bcrypt-hashed password. We never store or log your password in plain text.
- Connected business data: if you connect QuickBooks Online, the customer, vendor, invoice, estimate, and expense records made available through that connection. If you import a CSV file, the invoice, expense, job, and estimate rows contained in that file. LEAK only receives what the source you connect actually provides — the in-app “Data Coverage” view shows exactly what LEAK currently has for your business.
- Findings and derived data: the leaks, calculations, drafted follow-up actions, and recovery outcomes LEAK produces from your connected data.
- Billing information: your subscription status and Stripe customer/subscription identifiers. LEAK does not receive or store your full payment card number — card details are entered directly into Stripe's hosted checkout and billing portal.
- Usage and log data: basic application and error logs (for example, when a scan or sync ran, whether it succeeded, and diagnostic messages) needed to operate, secure, and support the Service.
2. Why we collect it
We use the information above to:
- authenticate you and operate your account;
- sync and analyze your connected business data to generate findings and drafted follow-up actions;
- let you review, approve, or dismiss any finding or drafted action;
- send you account, billing, and (if you have not turned it off in Settings) Daily Brief emails;
- send messages to your own customers, but only for a specific action you have explicitly reviewed and approved (see Section 4);
- process subscription payments through Stripe;
- maintain the security, integrity, and reliability of the Service; and
- provide customer support and respond to your requests.
We do not use your business data to train third-party AI models, and we do not use it for any purpose unrelated to providing you the Service.
3. How we handle your QuickBooks connection
If you connect QuickBooks Online, the OAuth authorization takes place directly between you and Intuit; the resulting access tokens are handled entirely server-side, encrypted at rest, and are never exposed to your browser or to any other user. Tokens are used only to sync the categories of data described above on your behalf, on a schedule or when you manually trigger a sync. You can disconnect QuickBooks at any time from Data Sources — doing so stops future syncing and revokes LEAK's access at Intuit, but does not by itself delete data already synced (use Delete financial data in Settings for that). Your use of QuickBooks itself is governed by Intuit's own privacy policy and terms, separate from this one.
4. Automations and messages to your customers
Some LEAK features can draft a message intended for one of your customers (for example, an invoice payment reminder). LEAK only sends such a message after you have reviewed and explicitly approved that specific message — there is no bulk-send and no automatic sending. Where a feature is currently limited to simulating a send rather than delivering a real message, the product tells you so at the time. When a real message is sent, it is delivered through our transactional email provider, Resend, using the recipient address on file in your connected data; the recipient's email address and the message content are shared with Resend solely to deliver that message.
5. Cookies and authentication
LEAK uses a single essential session cookie to keep you signed in; it is required for the Service to function and is not used for cross-site tracking or advertising. LEAK does not currently use third-party analytics or advertising cookies or trackers.
6. Who we share information with
We do not sell your personal or business data to anyone. We share information only with the service providers below, solely to the extent necessary to run LEAK, and with your connected QuickBooks provider where applicable:
- Intuit (QuickBooks Online) — only if you choose to connect it, governed by Intuit's own terms.
- Stripe — processes subscription payments and stores your payment method on our behalf; we receive status and identifiers back, not your card number.
- Resend — delivers transactional email (account notices, the Daily Brief, and any automation message you explicitly approve for sending).
- Vercel — hosts and runs the application.
- A managed PostgreSQL database provider — stores your data at rest.
We may also disclose information if required to do so by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
7. Data retention
We retain your account and connected business data for as long as your account remains open, so the Service can continue to function and so you can see historical findings and recoveries. If you delete specific data or your account (see Section 8), we delete it as described there. We may retain minimal records (for example, billing history or logs needed for security, fraud prevention, or legal compliance) for a limited period after deletion where we have a legitimate need or legal obligation to do so.
8. Deletion and your choices
From Settings, at any time, you can:
- Delete your imported financial data — removes every customer, vendor, invoice, estimate, expense, and finding LEAK has for your business, and disconnects QuickBooks if connected. Your account and login stay active.
- Delete your account — permanently deletes your account, every business connected to it, and all data under it. This cannot be undone. Deleting your account does not automatically cancel an active Stripe subscription — cancel it separately from the billing portal first if you want billing to stop.
- Turn the Daily Brief email on or off.
You may also contact us using the details in Section 10 to ask what information we hold about you or to request deletion, subject to the exceptions described in Section 7.
9. Security
We take reasonable measures designed to protect your information, including hashing passwords, encrypting QuickBooks access tokens at rest, restricting each account to its own business data, and validating imported files before they touch the database. Communications between your browser and LEAK are encrypted in transit. No method of storage or transmission is completely secure, and we cannot guarantee that our security measures will prevent every possible unauthorized access, loss, misuse, or alteration of information — we do not claim the Service “cannot be hacked” or is otherwise absolutely secure, and we do not hold any specific security or compliance certification (such as SOC 2, HIPAA, or PCI DSS) at this time.
10. Contact
Questions about this Privacy Policy, or requests regarding your information, can be sent to support@useleak.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date above and, where appropriate, notify you by email. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.