Privacy Policy

Last updated 16 August 2026

Leo (“Leo”, “we”, “us”) is a product venture of Cognexa Limited. This policy explains what personal data we process when you use the Leo platform at leo.co.ke, why we process it, and the rights you have. We act as a data controller for your account data and as a data processor for the customer data you load into your workspaces.

1. Data we collect

  • Account data — name, email, password hash, organisation and workspace names, role.
  • Billing data — plan, credit balance and transaction references. Card details are handled by our payment processor (Paystack); we never store full card numbers.
  • Workspace content — contacts, deals, content, tasks, brand guidelines and generated assets you create or import.
  • Enrichment data — when you use Discover, we retrieve business contact details from public sources and/or third-party providers (see §3).
  • Usage data — log data, device/browser information and product events used to operate and improve the service.

2. How we use data

We process personal data to provide and secure the service, authenticate you, meter credit usage, process payments, generate content and documents you request, send service and assignment emails, and comply with legal obligations. Our lawful bases are performance of a contract, our legitimate interests in operating the service, your consent (where required), and compliance with law.

3. Contact discovery & enrichment

Leo’s Discover feature helps you find business contacts for legitimate outreach. It gathers contact details that businesses have published publicly, and — when you choose the verified option — retrieves data from a third-party enrichment provider. We only collect business contact information and do not knowingly collect special-category data. If you are a contact who appears in a customer’s workspace and wish to exercise your rights, contact us and we will route your request to the relevant controller.

4. AI processing

When you generate images, video, documents or use the assistant, your prompts and the relevant workspace context are sent through OpenRouter to the selected model provider solely to produce your output. We do not use your workspace content to train our own models. AI output may contain inaccuracies; you are responsible for reviewing it before use.

5. Sharing & sub-processors

We share data only with service providers who help us run Leo, under contract and confidentiality, including: Supabase (database & storage), Paystack (payments), Resend (email), the AI provider selected by Leo's provider gateway for the requested capability, and our enrichment provider. We do not sell personal data.

6. International transfers

Some providers process data outside your country. Where required, we rely on appropriate safeguards such as standard contractual clauses.

7. Retention

We keep account and workspace data for as long as your account is active and as needed to provide the service, then delete or anonymise it within a reasonable period, subject to legal retention requirements.

8. Security

We use HTTPS encryption in transit, tenant-scoped access controls and the principle of least privilege. New conversation titles and message text are additionally encrypted with AES-256-GCM inside the application before they are stored in the database; the encryption key is held separately from the database. Earlier conversation history is protected as it is migrated to the same encrypted format.

This storage protection is not zero-knowledge end-to-end encryption. Leo must briefly decrypt content inside its application service to provide the feature you requested. When you use cloud AI, the relevant prompt and workspace context are sent to the selected AI provider as described in §4. Production is configured to refuse new conversation writes if the application-layer encryption key is unavailable rather than silently storing new transcript text in plain form.

9. Your rights

Subject to your jurisdiction (including Kenya’s Data Protection Act 2019 and, where applicable, the GDPR), you may request access, correction, deletion, restriction, portability, or object to processing, and lodge a complaint with your data protection authority. To exercise these rights, email us at the address below.

10. Cookies and analytics

We use strictly necessary cookies to keep you signed in and operate the service. These are required for Leo to work and are not optional.

Separately, we use Google Analytics to understand which parts of Leo people use. Analytics cookies are set only if you agree when we ask, and you can decline without losing any functionality. If you decline, the Google Analytics script is not loaded at all.

What we send to analytics is limited to product telemetry: which page or tool was used, which step of a flow was reached, categories such as the plan or the tool involved, and counts. We do not send your conversations with Leo, your prompts or Leo’s replies, your files or their contents, file names, contact or customer records, workspace, project or task names, invitation tokens, or the query strings of the pages you visit. Advertising signals and ad personalisation are switched off, and we do not use analytics for advertising.

You can change your mind at any time by clearing this site’s stored data in your browser, which makes us ask again. You can also control cookies through your browser settings.

11. Children

Leo is a business tool not directed to children, and we do not knowingly collect data from anyone under 18.

12. Changes & contact

We may update this policy and will revise the date above. Questions or requests: privacy@leo.wallacemecha.com.