LEVERAGE Privacy Policy Document version: 1.0 — pending legal review Last updated: June 11, 2026 Effective date: June 11, 2026 Company: Incisive Venture Capital, LLC (“Leverage,” “we,” “us”) Contact: hello@mail.myleverage.app Governing law: Delaware, USA
Privacy Policy
- Introduction This Privacy Policy explains how Incisive Venture Capital, LLC (“Leverage,” “we,” “us”) collects, uses, shares, and protects your personal information when you use the Service. We designed Leverage to be privacy-respecting: your data is yours, and we are transparent about what we hold and why.
- Information We Collect • Information you provide: your name, email, password (hashed), and the content you enter — brain-dumps, goals, tasks, accomplishments, notes, and preferences. If you enable accountability messaging, your phone number or messaging handle. • Information from connected services: when you connect a third-party integration (calendar, email, task manager, notes), we access the data you authorize — such as events, email metadata and content relevant to tasks, and task/project records — to provide the Service. • Anonymous trial data: if you use the no-account trial, we temporarily store the data you enter against an anonymous session token so you can experience the Service. If you create an account, this data is associated with you; if not, it expires and is purged. • Usage and device data: we collect product-analytics events (how you use features), and standard device/browser information and logs for security and reliability. • Payment data: payments are processed by Stripe. We do not store full card numbers; Stripe handles card data under its own security and compliance.
- How We Use Your Information • To provide the core Service — reading context, generating prioritized actions, coaching, accountability, and syncing with your connected tools. • To send you messages you have opted into, on the channels you selected. • To process payments and manage your subscription. • To improve the Service, including measuring activation and retention through product analytics. • To maintain security, prevent abuse, debug, and meet legal obligations.
- Legal Bases for Processing (GDPR / UK GDPR) Where the EU GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (to provide the Service you signed up for); consent (for messaging channels and certain analytics, which you may withdraw at any time); legitimate interests (to secure and improve the Service); and legal obligation (to comply with law). [Counsel to confirm the legal bases and balancing tests.]
- How We Share Information • Service providers / sub-processors — infrastructure (e.g., Fly.io), database (Neon), authentication (Clerk), payments (Stripe), AI model providers, messaging providers (e.g., Twilio, WhatsApp, Telegram), email (Loops.so), and analytics (PostHog), each under contractual data-protection obligations. • Connected services you authorize — we send data back to integrations you have enabled for two-way sync. • Legal and safety — where required by law or to protect rights, safety, and the integrity of the Service. • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy. We do not sell your personal information. We do not share it for cross-context behavioral advertising.
- Your Rights & Choices • Access & export — you can view and export all data we hold about you from the in-app Data Dashboard. • Deletion — you can delete your account and data at any time. We soft-delete immediately and hard-delete after a 30-day grace period, except where retention is legally required. • Correction — you can correct your information in settings. • Consent withdrawal — you can withdraw messaging or analytics consent at any time in settings. California (CCPA/CPRA) and EU/UK (GDPR) residents have additional rights, including the right to know, delete, correct, and (CA) limit use of sensitive information, and (EU/UK) to object, restrict, and lodge a complaint with a supervisory authority. To exercise rights, contact hello@mail.myleverage.app. We will not discriminate against you for exercising your rights.
- Data Retention We retain your information for as long as your account is active or as needed to provide the Service. After account deletion, we hard-delete personal data following the 30-day grace period, except where we must retain certain records (e.g., billing/tax) as required by law. Append-only operational logs are retained for a limited period for security and reliability.
- Data Security • Encryption in transit (TLS) and encryption at rest for sensitive fields, including integration tokens and phone numbers. • Role-based access controls; staff access to user data is restricted and logged. • Reputable infrastructure and sub-processors with their own security programs. No system is perfectly secure. [Counsel to add breach-notification commitments per applicable law, including the GDPR 72-hour notification requirement.]
- International Data Transfers We and our sub-processors may process data in the United States and other countries. Where required, we use appropriate safeguards (such as Standard Contractual Clauses and the UK International Data Transfer Addendum) for international transfers. AI processing of your personal data is performed only through providers hosted in approved regions. [Counsel to confirm transfer mechanisms and the EU-U.S. Data Privacy Framework status of relevant sub-processors.]
- Children’s Privacy The Service is not directed to children under 16, and we do not knowingly collect their personal information. If we learn we have, we will delete it.
- Analytics & Cookies We use product analytics to understand how the Service is used and to improve it. During pre-launch (alpha/beta) stages, we may record sessions to diagnose usability issues; this is disclosed in-app and is off by default in production unless you opt in. We use only the cookies and similar technologies necessary for the Service and analytics, and we honor regional consent requirements.
- Changes to This Policy We may update this Policy. Material changes will be communicated in the Service or by email, with the version and effective date shown at the top. Where required, we will request renewed consent.
- Contact & Data Controller Privacy questions or requests: hello@mail.myleverage.app / 2212 Queen Anne Ave N, Suite 827, Seattle, WA 98109, USA. For the purposes of the EU GDPR and UK GDPR, the data controller is Incisive Venture Capital, LLC, 2212 Queen Anne Ave N, Suite 827, Seattle, WA 98109, USA. [Counsel to advise whether an EU and/or UK Article 27 representative and a Data Protection Officer are required given the EU/UK user base, and to add their details here if appointed.]