LeanHQ
Home Terms Open LeanHQ

Last updated 29 July 2026

Privacy Policy

This policy explains what LeanHQ collects, why, where it lives, and the controls you have over it. We've written it to be read, not to be survived.

1. Who we are

LeanHQ ("LeanHQ", "we", "us") is a business operations platform operated by Viavize Ventures LLP, registered at [registered address]. For anything in this policy, write to privacy@leanhq.ai.

2. The data we handle

Account data

Your name, work email, hashed password, workspace name, role, and activity records (sign-ins, actions taken, credits used). We need this to run your account and keep an audit trail.

Documents and content you upload

Résumés, job descriptions, receipts, vendor bills, customer invoices, bank statements, notes your team writes, and anything else you put into a skill. This content — and the structured data our AI extracts from it — is stored in your workspace and used only to provide the service to you.

Personal data about other people

LeanHQ is used to process information about third parties — most obviously job candidates. For that data, you are the controller and we are your processor: you decide what to upload and why, and you are responsible for having a lawful basis and for telling those individuals how their data is used. We process it only on your instructions, as described here.

Technical data

IP address, browser type, and timestamps, recorded for security, abuse prevention and debugging. We do not use advertising or cross-site tracking cookies. The only cookie we set is the one that keeps you signed in.

3. Google user data

Connecting a Google account is entirely optional. It exists so that candidate outreach and rejection emails can be sent from your own address rather than a generic one.

The permission we request

When you connect Google, LeanHQ requests exactly one scope: https://www.googleapis.com/auth/gmail.send.

That scope allows one thing: sending an email on your behalf. Concretely:

  • We can send an email that you have composed or reviewed inside LeanHQ, and record that we sent it.
  • We cannot read, search, download, or index any message in your mailbox.
  • We cannot read your inbox, drafts, labels, contacts, or attachments.
  • We cannot modify or delete anything in your Google account.

We deliberately do not request any Gmail read permission. We store the OAuth tokens Google issues, encrypted at rest, solely to send on your behalf. We also store the email address of the connected mailbox so we can show you which account is in use.

You can disconnect at any time in LeanHQ under Settings → Connected Accounts, which revokes our stored tokens immediately. You can also revoke access from your Google Account permissions page.

Limited Use disclosure. LeanHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the feature you asked for, and we do not use it to train AI models.

4. How we use your data

  • To provide the skills you use — screening résumés, extracting receipt and invoice data, matching bank transactions, generating drafts.
  • To maintain your workspace's records and audit trail, including credits consumed.
  • To send the emails you explicitly ask us to send.
  • To secure the service, investigate abuse, and comply with law.
  • To contact you about your account or material changes to the service.

We do not use your content to train AI models — not ours, and not our providers'. We do not sell your data or share it with advertisers.

5. AI processing

LeanHQ uses third-party large language models to extract and analyse the documents you upload. When you run a skill, the relevant content (for example the text of a résumé, or an image of a receipt) is sent to our AI provider to produce the result you asked for. Under our provider's API terms, that content is not used to train their models.

AI output is a suggestion, not a decision. Scores, matches and drafts are presented for a person to review; LeanHQ does not automatically reject a candidate, mark a bill paid, or send an email without a human confirming it.

6. Who we share data with

We use a small number of sub-processors to run the service. They may process your data only to provide their service to us:

ProviderPurpose
RailwayApplication hosting and managed PostgreSQL database
Cloudflare (R2)Encrypted object storage for uploaded documents
OpenAIAI extraction, scoring and drafting (no training on your data)
GoogleSending email — only if you connect a Google account

We may also disclose data if required by law, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

7. Where data is stored, and for how long

Data is stored on infrastructure operated by the providers above. We keep your content for as long as your workspace is active, because these are working records — an audit trail is only useful if it persists. Financial documents in particular are designed to be retained for statutory audit periods.

You may delete individual records in the product at any time. If you close your workspace, contact us and we will delete your content within 30 days, except where we are legally required to retain it. Backups are purged on a rolling cycle.

8. Security

  • All traffic is encrypted in transit (TLS).
  • Uploaded documents are stored in access-controlled object storage, not on public URLs.
  • OAuth tokens are encrypted at rest with authenticated encryption (AES-256-GCM).
  • Passwords are stored only as salted hashes — we never see them.
  • Each workspace's data is isolated and scoped to that account on every request.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly.

9. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to privacy@leanhq.ai and we will respond within 30 days.

If your personal data is in LeanHQ because one of our customers uploaded it (for example, you applied for a job), that customer controls it. Contact them directly, or write to us and we will pass your request on.

10. Children

LeanHQ is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

If we change this policy materially, we will update the date above and notify workspace administrators by email before the change takes effect.

12. Contact

Privacy questions, data requests, or anything unclear: privacy@leanhq.ai.

LeanHQ
Home Privacy Terms Contact

LeanHQ is a product of Viavize Ventures LLP. © 2026 — all rights reserved.