Privacy Policy

Last updated: December 1, 2024

This Privacy Policy describes how LeapKeep collects, uses, and handles your information when you use our platform. This is not legal advice. If you have specific legal questions about data handling, we encourage you to consult a qualified professional.

What we collect

We collect the information you provide when creating an account (name and email address), project metadata and configuration data you enter while using the platform, uploaded project files or repository connection data required to operate the service, deployment configuration and environment variable keys (not secret values in plain text), and standard usage data such as page visits and feature interactions. We do not collect data beyond what is necessary to provide the service.

How we use your information

We use your information to operate and improve the platform, authenticate your account and protect it from unauthorized access, analyze and simulate your project configuration on your behalf, store your project history and deployment records, and communicate with you about your account and material changes to the service. We do not use your data for advertising, profiling, or sale to third parties.

What we do not do

We do not sell your personal information or project data to any third party. We do not use your code or project data to train machine learning models. We do not share your information with third parties except as required to operate the service (such as cloud infrastructure providers operating under data processing agreements) or where required by law.

Code and project data

Project files, repository connection data, and code you import into the platform are stored and processed solely to provide the analysis, simulation, and deployment features you request. We do not inspect, share, or retain your code beyond what is necessary to operate those features. You retain full ownership of your code and project data at all times.

Provider credentials and environment variables

Environment variable values you mark as secrets are stored encrypted at rest. Secret values are not exposed in the client-side interface or transmitted in API responses in plain text. Provider credentials you connect are stored under your account and are not visible to other users. You can disconnect any provider connection at any time from your account settings.

Data retention and deletion

Your account data, project data, simulation history, and deployment records are retained for as long as your account is active. If you delete a project, associated data is removed. If you close your account, we will delete your personal information and project data upon request. To request account deletion or data removal, contact us at [email protected].

Security practices

We use row-level security at the database layer to ensure each user can only access their own data. Connections to our services are encrypted in transit. We apply a zero-trust default posture: access is explicitly granted, never assumed. No security system is perfect. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account.

Your rights

You have the right to access the personal information we hold about you, request correction of inaccurate information, request deletion of your account and associated data, and receive a copy of your data in a portable format. To exercise any of these rights, contact us at [email protected]. We will respond within a reasonable timeframe.

Changes to this policy

We may update this Privacy Policy as the product evolves. Material changes will be communicated through the platform or by email to the address on your account. Continued use of the platform after changes are published constitutes acceptance of the updated policy.

Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at [email protected].