Last updated 29 July 2026
This policy explains what LeanHQ collects, why, where it lives, and the controls you have over it. We've written it to be read, not to be survived.
LeanHQ ("LeanHQ", "we", "us") is a business operations platform operated by Viavize Ventures LLP, registered at [registered address]. For anything in this policy, write to privacy@leanhq.ai.
Your name, work email, hashed password, workspace name, role, and activity records (sign-ins, actions taken, credits used). We need this to run your account and keep an audit trail.
Résumés, job descriptions, receipts, vendor bills, customer invoices, bank statements, notes your team writes, and anything else you put into a skill. This content — and the structured data our AI extracts from it — is stored in your workspace and used only to provide the service to you.
LeanHQ is used to process information about third parties — most obviously job candidates. For that data, you are the controller and we are your processor: you decide what to upload and why, and you are responsible for having a lawful basis and for telling those individuals how their data is used. We process it only on your instructions, as described here.
IP address, browser type, and timestamps, recorded for security, abuse prevention and debugging. We do not use advertising or cross-site tracking cookies. The only cookie we set is the one that keeps you signed in.
Connecting a Google account is entirely optional. It exists so that candidate outreach and rejection emails can be sent from your own address rather than a generic one.
When you connect Google, LeanHQ requests exactly one scope: https://www.googleapis.com/auth/gmail.send.
That scope allows one thing: sending an email on your behalf. Concretely:
We deliberately do not request any Gmail read permission. We store the OAuth tokens Google issues, encrypted at rest, solely to send on your behalf. We also store the email address of the connected mailbox so we can show you which account is in use.
You can disconnect at any time in LeanHQ under Settings → Connected Accounts, which revokes our stored tokens immediately. You can also revoke access from your Google Account permissions page.
Limited Use disclosure. LeanHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the feature you asked for, and we do not use it to train AI models.
We do not use your content to train AI models — not ours, and not our providers'. We do not sell your data or share it with advertisers.
LeanHQ uses third-party large language models to extract and analyse the documents you upload. When you run a skill, the relevant content (for example the text of a résumé, or an image of a receipt) is sent to our AI provider to produce the result you asked for. Under our provider's API terms, that content is not used to train their models.
AI output is a suggestion, not a decision. Scores, matches and drafts are presented for a person to review; LeanHQ does not automatically reject a candidate, mark a bill paid, or send an email without a human confirming it.
We use a small number of sub-processors to run the service. They may process your data only to provide their service to us:
| Provider | Purpose |
|---|---|
| Railway | Application hosting and managed PostgreSQL database |
| Cloudflare (R2) | Encrypted object storage for uploaded documents |
| OpenAI | AI extraction, scoring and drafting (no training on your data) |
| Sending email — only if you connect a Google account |
We may also disclose data if required by law, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.
Data is stored on infrastructure operated by the providers above. We keep your content for as long as your workspace is active, because these are working records — an audit trail is only useful if it persists. Financial documents in particular are designed to be retained for statutory audit periods.
You may delete individual records in the product at any time. If you close your workspace, contact us and we will delete your content within 30 days, except where we are legally required to retain it. Backups are purged on a rolling cycle.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly.
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to privacy@leanhq.ai and we will respond within 30 days.
If your personal data is in LeanHQ because one of our customers uploaded it (for example, you applied for a job), that customer controls it. Contact them directly, or write to us and we will pass your request on.
LeanHQ is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
If we change this policy materially, we will update the date above and notify workspace administrators by email before the change takes effect.
Privacy questions, data requests, or anything unclear: privacy@leanhq.ai.