Privacy Policy

Last updated: August 12, 2026

This Privacy Policy explains how Leap handles information when you use the website or app.

Scope

This Privacy Policy describes how Leap ("Leap," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our website, mobile applications, and related services (collectively, the "Services"). The Services are operated by Lukas Hofbauer, whose contact details are provided below.

Information We Collect

Account and profile information: • Profile information such as your name (if you choose to provide it) • Email address, authentication identifiers, and sign-in provider details needed to operate your account Local app information: • Workout and progress data such as activity type, workout duration, dates, streaks, XP, and mission progress • Preferences and settings such as workout schedule, reminder settings, theme, companion choices, and personality settings • Optional wellness check-in data such as mood check-ins and check-in preferences Optional health and activity information: • Optional step counts read from Apple Health, Health Connect, or device pedometer services • Information from health integrations is requested only when you enable the relevant feature. This information may constitute health-related or special-category data under applicable law. Information from your device: • Basic app and device context needed to run features (for example, platform and app version) • Notification permission status and local notification scheduling metadata Analytics and event data (when enabled): • A pseudonymous analytics identifier derived from your LEAP account ID • App lifecycle events and onboarding interaction events (for example, screen views, step completion timing, and selected onboarding options) • Event metadata such as timestamps and flow/session identifiers Information from third parties (when enabled): • App Store / Google Play transaction status for subscriptions • RevenueCat subscription status, purchase history, and entitlement metadata • PostHog app lifecycle and onboarding analytics linked to your pseudonymous LEAP account identifier • Supabase authentication information needed to operate your LEAP account Support communications: • If you contact us, we collect the information you include in your message (such as email address and support content).

How We Use Information

We use information for the following purposes and legal bases: • Operate your account, provide core app features, save progress, and schedule configured reminders — necessary to provide the Services or perform a contract with you • Process subscriptions and entitlements — necessary to perform the relevant contract and comply with legal obligations • Respond to support requests and account or privacy requests — necessary to perform a contract, take steps at your request, or pursue legitimate interests in providing support • Protect the Services, prevent abuse, investigate security incidents, and enforce our Terms — legitimate interests and, where applicable, legal obligations • Process optional health and activity integrations — your separate, explicit consent or another legally valid condition for health-related data; you can revoke access in the app or device settings • Measure product usage through PostHog analytics — your consent where required; you can disable analytics or withdraw consent through the available app controls • Meet accounting, tax, legal, and regulatory obligations — compliance with legal obligations

Storage and Security

LEAP is designed as a local-first app. Workout history, progress, wellness check-ins, step snapshots, and preferences are stored on your device unless a feature explicitly requires account or service-provider processing. Supabase stores the authentication account needed for Google and Apple sign-in. RevenueCat processes subscription and entitlement information. PostHog processes the limited analytics events described above. PostHog is configured for EU cloud hosting for Leap's analytics data. When analytics is enabled, selected analytics events are transmitted to our analytics processor (PostHog) based on your settings and the app configuration. Health and activity data is not included in analytics events as described above. We use safeguards appropriate to the nature and risk of the processing, including access controls and service-provider security measures. No security method is perfect, and we cannot guarantee absolute security.

How We Share Information

We do not sell personal information. We share information only as needed for the purposes described in this policy: • Supabase for account authentication and related infrastructure • RevenueCat for subscription status, purchase history, and entitlements • PostHog for optional product analytics when analytics is enabled • Apple and Google for sign-in, app distribution, and subscription processing • Service providers that provide hosting, support, security, or other services under our instructions • Law enforcement, regulators, or other parties when required by law or to protect rights and safety • Parties involved in a merger, acquisition, financing, or asset sale, subject to appropriate confidentiality protections These providers may use subprocessors. We require appropriate contractual and security protections for processing carried out on our behalf. Apple, Google, and other third parties may also process information under their own privacy policies and roles as independent controllers.

International Transfers

PostHog is configured for EU cloud hosting. Other providers or subprocessors may process information outside the European Economic Area. Where a transfer outside the EEA occurs, we rely on an applicable adequacy decision, standard contractual clauses, or another lawful transfer safeguard. Information about the relevant safeguard can be requested from us where required by law.

Data Retention

Local app data remains until you reset or delete it, clear the app's storage, or uninstall the app. Account and authentication data is retained while your account is active and deleted or de-identified when your account is deleted, subject to lawful retention. Subscription, transaction, tax, security, fraud-prevention, backup, and support records may be retained for the period required or permitted by law. Analytics records are retained according to the account, analytics configuration, and applicable provider retention settings. Verified account-deletion requests are normally completed within 30 days. Limited records may remain where required for compliance, fraud prevention, dispute resolution, security, or enforcement. App stores retain payment records under their own policies.

Your Choices and Rights

You can: • Edit your profile, preferences, and wellness settings in-app • Disable or modify notifications in your app/device settings • Clear local app data through the in-app reset control • Permanently delete your account in Settings → Account → Delete Account • Request deletion without the app at https://www.leap-companion.com/account-deletion • Revoke optional health permissions in the app or device settings • Disable analytics or withdraw analytics consent through the available app controls Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing of your personal information, receive a portable copy, withdraw consent, and object to certain direct marketing. You may also have rights concerning automated decision-making where applicable. Contact us at support@leap-companion.com to submit a request. We may need to verify your identity. We normally respond to data-protection requests within one month. This period may be extended by up to two additional months where permitted by law, with notice and reasons for the extension. You may lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, at https://dsb.gv.at/ or with another supervisory authority competent for you.

Cookies, SDKs, and Tracking

The mobile app does not rely on browser cookies. It may use mobile SDKs and local device storage required for app functionality, subscription management, and optional analytics. The website may use strictly necessary local storage for preferences such as the selected theme. We do not describe any non-essential website cookies or tracking here unless they are actually enabled. If website analytics, advertising, or additional tracking is introduced, this policy and any required consent controls will be updated before that processing begins. When analytics is enabled, the app uses the PostHog mobile SDK to process product analytics events. Analytics events do not include the health and activity data described above.

Children's Privacy

The Services are not directed to children under 14. We do not knowingly collect personal information from children under 14 in violation of applicable law. If you believe a child submitted personal information, contact us and we will take appropriate steps.

Data Protection Officer

No data protection officer has been appointed at this time. For all privacy questions and rights requests, contact the Data Controller using the details provided below. We will reassess whether a data protection officer is required if the nature, scale, or scope of the processing changes.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. If changes are material, we may provide additional notice, such as an in-app notice, before the change becomes effective where required by law.

Contact and Controller Information

Leap Operator / Data Controller: Lukas Hofbauer Email: support@leap-companion.com Website: https://www.leap-companion.com Mailing Address: Wilhelm-Mantlergasse 610, 3571 Gars am Kamp, Austria