Privacy Policy

Last updated: February 19, 2026

This Privacy Policy explains how Leap handles information when you use the app.

Scope

This Privacy Policy describes how Leap ("Leap," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our mobile applications and related services (collectively, the "Services").

Information We Collect

Information you provide in the app: • Profile information such as your name (if you choose to provide it) • Workout and progress data such as activity type, workout duration, dates, streaks, XP, and mission progress • Preferences and settings such as workout schedule, reminder settings, theme, companion choices, and personality settings • Optional wellness check-in data such as mood check-ins and check-in preferences Information from your device: • Basic app and device context needed to run features (for example, platform and app version) • Notification permission status and local notification scheduling metadata Analytics and event data (when enabled): • A generated anonymous analytics identifier stored on device • App lifecycle events and onboarding interaction events (for example, screen views, step completion timing, and selected onboarding options) • Event metadata such as timestamps and flow/session identifiers Information from third parties (when enabled): • App Store / Google Play transaction status for subscriptions • RevenueCat subscription status and entitlement metadata (if/when subscriptions are enabled) • PostHog analytics processing services (if/when analytics are enabled) Support communications: • If you contact us, we collect the information you include in your message (such as email address and support content).

How We Use Information

We use information to: • Operate core app features and personalization • Save and restore your progress and settings • Schedule reminders and notifications you configure • Improve app stability, quality, and feature design • Measure onboarding and product usage trends through analytics (if enabled) • Process and manage subscriptions (if/when enabled) • Respond to support requests and legal obligations

Storage and Security

The app is currently designed as local-first. Most user data is stored on your own device (for example, via local storage). When analytics is enabled, selected analytics events are transmitted to our analytics processor (PostHog) based on app configuration. We use commercially reasonable safeguards to protect information. No security method is perfect, and we cannot guarantee absolute security.

How We Share Information

We do not sell personal information. We may share information only in limited cases: • Service providers that help operate the Services (for example, app infrastructure, support, or subscription tooling) • App marketplaces and payment platforms for subscription processing • Analytics processors (such as PostHog) when analytics is enabled • Law enforcement, regulators, or other parties when required by law or to protect rights and safety • Parties involved in a merger, acquisition, financing, or asset sale, subject to confidentiality protections

Data Retention

Because most app data is stored locally, retention is primarily controlled by you. You can remove stored app data by using in-app reset/delete controls or by uninstalling the app. We may retain support or legal records as needed for compliance, dispute resolution, and enforcement of agreements.

Your Choices and Rights

You can: • Edit your profile, preferences, and wellness settings in-app • Disable or modify notifications in your app/device settings • Clear app data through in-app reset controls Depending on your location, you may have legal rights such as access, deletion, correction, portability, and objection rights. Contact us at privacy@leapapp.com to submit a request. We may need to verify your identity before processing.

Cookies, SDKs, and Tracking

The mobile app does not rely on browser cookies. It may use mobile SDKs and local device storage required for app functionality (and, when enabled, subscription management and analytics). When analytics is enabled, the app uses the PostHog mobile SDK to process product analytics events. Default analytics host configuration may route data to PostHog's US infrastructure unless you configure a different host.

Children's Privacy

The Services are not directed to children under 13 (or older age where required by local law). We do not knowingly collect personal information from children in violation of applicable law. If you believe a child submitted personal information, contact us and we will take appropriate steps.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. If changes are material, we may provide additional notice (such as in-app notice).

Contact and Controller Information

If you have questions about this Privacy Policy, contact us: Leap Email: privacy@leapapp.com Mailing Address: [Insert legal mailing address] Data Controller / Legal Entity: Lukas Hofbauer