Privacy Policy
Last updated: August 12, 2026
This Privacy Policy explains how Leap handles information when you use the website or app.
Scope
This Privacy Policy describes how Leap ("Leap," "we," "us," or "our")
collects, uses, discloses, and protects personal information when you use our
website, mobile applications, and related services (collectively, the
"Services"). The Services are operated by Lukas Hofbauer, whose contact details
are provided below.
Information We Collect
Account and profile information:
• Profile information such as your name (if you choose to provide it)
• Email address, authentication identifiers, and sign-in provider details needed to operate your account
Local app information:
• Workout and progress data such as activity type, workout duration, dates, streaks, XP, and mission progress
• Preferences and settings such as workout schedule, reminder settings, theme, companion choices, and personality settings
• Optional wellness check-in data such as mood check-ins and check-in preferences
Optional health and activity information:
• Optional step counts read from Apple Health, Health Connect, or device pedometer services
• Information from health integrations is requested only when you enable the relevant feature. This information may constitute health-related or special-category data under applicable law.
Information from your device:
• Basic app and device context needed to run features (for example, platform and app version)
• Notification permission status and local notification scheduling metadata
Analytics and event data (when enabled):
• A pseudonymous analytics identifier derived from your LEAP account ID
• App lifecycle events and onboarding interaction events (for example, screen views, step completion timing, and selected onboarding options)
• Event metadata such as timestamps and flow/session identifiers
Information from third parties (when enabled):
• App Store / Google Play transaction status for subscriptions
• RevenueCat subscription status, purchase history, and entitlement metadata
• PostHog app lifecycle and onboarding analytics linked to your pseudonymous LEAP account identifier
• Supabase authentication information needed to operate your LEAP account
Support communications:
• If you contact us, we collect the information you include in your message (such as email address and support content).
How We Use Information
We use information for the following purposes and legal bases:
• Operate your account, provide core app features, save progress, and schedule configured reminders — necessary to provide the Services or perform a contract with you
• Process subscriptions and entitlements — necessary to perform the relevant contract and comply with legal obligations
• Respond to support requests and account or privacy requests — necessary to perform a contract, take steps at your request, or pursue legitimate interests in providing support
• Protect the Services, prevent abuse, investigate security incidents, and enforce our Terms — legitimate interests and, where applicable, legal obligations
• Process optional health and activity integrations — your separate, explicit consent or another legally valid condition for health-related data; you can revoke access in the app or device settings
• Measure product usage through PostHog analytics — your consent where required; you can disable analytics or withdraw consent through the available app controls
• Meet accounting, tax, legal, and regulatory obligations — compliance with legal obligations
Storage and Security
LEAP is designed as a local-first app. Workout history, progress, wellness
check-ins, step snapshots, and preferences are stored on your device unless a
feature explicitly requires account or service-provider processing.
Supabase stores the authentication account needed for Google and Apple sign-in.
RevenueCat processes subscription and entitlement information. PostHog processes
the limited analytics events described above. PostHog is configured for EU cloud
hosting for Leap's analytics data.
When analytics is enabled, selected analytics events are transmitted to our
analytics processor (PostHog) based on your settings and the app configuration.
Health and activity data is not included in analytics events as described above.
We use safeguards appropriate to the nature and risk of the processing, including
access controls and service-provider security measures. No security method is
perfect, and we cannot guarantee absolute security.
How We Share Information
We do not sell personal information. We share information only as needed
for the purposes described in this policy:
• Supabase for account authentication and related infrastructure
• RevenueCat for subscription status, purchase history, and entitlements
• PostHog for optional product analytics when analytics is enabled
• Apple and Google for sign-in, app distribution, and subscription processing
• Service providers that provide hosting, support, security, or other services under our instructions
• Law enforcement, regulators, or other parties when required by law or to protect rights and safety
• Parties involved in a merger, acquisition, financing, or asset sale, subject to appropriate confidentiality protections
These providers may use subprocessors. We require appropriate contractual and
security protections for processing carried out on our behalf. Apple, Google, and
other third parties may also process information under their own privacy policies
and roles as independent controllers.
International Transfers
PostHog is configured for EU cloud hosting. Other providers or subprocessors
may process information outside the European Economic Area. Where a transfer
outside the EEA occurs, we rely on an applicable adequacy decision, standard
contractual clauses, or another lawful transfer safeguard. Information about the
relevant safeguard can be requested from us where required by law.
Data Retention
Local app data remains until you reset or delete it, clear the app's storage,
or uninstall the app.
Account and authentication data is retained while your account is active and
deleted or de-identified when your account is deleted, subject to lawful
retention. Subscription, transaction, tax, security, fraud-prevention, backup,
and support records may be retained for the period required or permitted by law.
Analytics records are retained according to the account, analytics configuration,
and applicable provider retention settings.
Verified account-deletion requests are normally completed within 30 days. Limited
records may remain where required for compliance, fraud prevention, dispute
resolution, security, or enforcement. App stores retain payment records under
their own policies.
Your Choices and Rights
You can:
• Edit your profile, preferences, and wellness settings in-app
• Disable or modify notifications in your app/device settings
• Clear local app data through the in-app reset control
• Permanently delete your account in Settings → Account → Delete Account
• Request deletion without the app at https://www.leap-companion.com/account-deletion
• Revoke optional health permissions in the app or device settings
• Disable analytics or withdraw analytics consent through the available app controls
Depending on your location, you may have the right to access, correct, delete,
restrict, or object to processing of your personal information, receive a
portable copy, withdraw consent, and object to certain direct marketing. You may
also have rights concerning automated decision-making where applicable. Contact us
at support@leap-companion.com to submit a request. We may need to verify your identity.
We normally respond to data-protection requests within one month. This period may
be extended by up to two additional months where permitted by law, with notice
and reasons for the extension.
You may lodge a complaint with the Austrian Data Protection Authority
(Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria,
at https://dsb.gv.at/ or with another supervisory authority competent for you.
Cookies, SDKs, and Tracking
The mobile app does not rely on browser cookies. It may use mobile SDKs and
local device storage required for app functionality, subscription management, and
optional analytics.
The website may use strictly necessary local storage for preferences such as the
selected theme. We do not describe any non-essential website cookies or tracking
here unless they are actually enabled. If website analytics, advertising, or
additional tracking is introduced, this policy and any required consent controls
will be updated before that processing begins.
When analytics is enabled, the app uses the PostHog mobile SDK to process
product analytics events. Analytics events do not include the health and activity
data described above.
Children's Privacy
The Services are not directed to children under 14. We do not knowingly
collect personal information from children under 14 in violation of applicable
law. If you believe a child submitted personal information, contact us and we
will take appropriate steps.
Data Protection Officer
No data protection officer has been appointed at this time. For all privacy
questions and rights requests, contact the Data Controller using the details
provided below. We will reassess whether a data protection officer is required if
the nature, scale, or scope of the processing changes.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated
policy on this page and update the "Last updated" date. If changes are material,
we may provide additional notice, such as an in-app notice, before the change
becomes effective where required by law.
Contact and Controller Information
Leap
Operator / Data Controller: Lukas Hofbauer
Email: support@leap-companion.com
Website: https://www.leap-companion.com
Mailing Address: Wilhelm-Mantlergasse 610, 3571 Gars am Kamp, Austria