Privacy Policy
Last updated 2026-10-06
1. Who we are and what this policy covers
This policy explains how LeapScope ("we", "us") collects, uses, discloses and protects personal data when you visit https://leap-scope.com, join the waitlist, use the free tools, or use the LeapScope application (together, the "Services"). LeapScope is the data controller for the personal data described here, except where we process data on a customer's instructions inside the application, in which case the customer is the controller and we are the processor under our customer agreement.
The Services link to third-party websites and connect to third-party services (for example Google Search Console). Those services have their own privacy policies, which we do not control.
2. Personal data we collect
Data you give us. When you join the waitlist: your email address and, optionally, your website and role. When you create an account: your name, email address, password (stored hashed), company and the brands, websites, competitors and prompts you set up. When you subscribe: billing name, address and payment details, which are collected and stored by our payment processor; we keep only the last digits of a card and the transaction records. When you contact us: the content of your message and your contact details.
Data collected automatically. When you use the Services: IP address, approximate location derived from it, browser and device type, pages viewed, actions taken in the application, timestamps, and the referring page. On the marketing site we collect this through server logs and privacy-focused analytics; see section 6 on cookies.
Data from third parties. If you connect an integration such as Google Search Console or an analytics account, we receive the data you authorize, scoped to the permissions you grant, and use it only to provide the connected feature. You can revoke access at any time from the provider's settings or from the application.
Data collected through the product about other websites and brands. To provide AI visibility tracking, the application sends the prompts you configure to AI answer engines (ChatGPT, Perplexity, Gemini, Google AI Overviews) and stores the answers, including the brands they name and the public web pages they cite. To provide page audits, keyword research and rank tracking, it fetches public web pages and licensed search data. This content is about businesses and public websites, not about you as an individual, but it may incidentally include names of people (for example an article's author). We process it to provide the Services, do not use it to build profiles of individuals, and remove it on request where the law requires.
3. How we use personal data
- To provide, operate and secure the Services and your account.
- To send you a waitlist invitation and transactional messages about your account, billing and security.
- To send product updates and occasional marketing emails; every such email has an unsubscribe link.
- To answer support requests.
- To understand how the Services are used and improve them, using aggregated or de-identified data wherever possible.
- To process payments, prevent fraud and abuse, and enforce our terms.
- To comply with legal obligations and respond to lawful requests.
We do not sell personal data, and we do not use your account data or the content you configure in the application to train AI models.
4. Legal bases (EEA, UK and Switzerland)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract to provide the Services you signed up for, including the waitlist and your account.
- Legitimate interests to secure and improve the Services, prevent abuse, and send relevant product information to existing customers, balanced against your rights.
- Consent for marketing emails to people who are not customers, for optional integrations you connect, and for any non-essential cookies; you can withdraw consent at any time.
- Legal obligation for tax, accounting and responding to lawful requests.
5. How we disclose personal data
- Service providers that process data on our instructions under data processing agreements: cloud hosting and content delivery, database hosting, transactional and marketing email, payment processing, error monitoring and analytics, AI and search data providers used to run your prompts and fetch public pages, and human-verification services.
- Integrations you connect, which receive only the requests needed to provide the feature.
- Professional advisers such as accountants and lawyers, bound by confidentiality.
- Authorities where required by law, to protect rights and safety, or to enforce our terms.
- A successor if we are involved in a merger, acquisition or sale of assets, under this policy or one at least as protective.
We will publish a list of subprocessors for the application before it opens, and keep it current.
6. Cookies and analytics
The marketing site sets no advertising cookies and does not use cross-site tracking. It may use a cookie-free, privacy-focused analytics service that records page views without identifying individual visitors, and a human-verification challenge on forms and free tools that may set a short-lived cookie to remember that you passed it.
The application sets strictly necessary cookies to keep you signed in and to protect against cross-site request forgery, and a preference cookie for settings such as theme. If we add optional cookies, we will ask for consent where the law requires and describe them here.
7. Retention
- Waitlist data: until you ask us to delete it, or until the waitlist is closed and converted into accounts, whichever is earlier.
- Account data: for as long as your account exists and for up to 30 days after deletion to allow recovery, then deleted or anonymized.
- Tracking data in your workspace (answers, citations, rankings): for as long as your subscription includes it, and deleted with the workspace.
- Billing records: as long as tax and accounting law requires.
- Server logs and free-tool caches: a short, fixed period, typically days.
8. Security
Data is encrypted in transit and at rest in our hosting providers, access is limited to staff who need it and protected by multi-factor authentication, passwords are stored hashed, and API keys are shown once and stored hashed. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as the law requires.
9. International transfers
Our providers may store and process data in the United States and other countries outside your own. Where data moves out of the EEA, the UK or Switzerland, we rely on the European Commission's and UK government's Standard Contractual Clauses or another lawful transfer mechanism, and on our providers' equivalent commitments.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable format, to withdraw consent, and to lodge a complaint with a supervisory authority. To exercise a right, write to support@leapfun.ai. We will verify your identity, respond within the time the law allows, and will not treat you differently for exercising a right.
California notice. In the preceding twelve months we have collected the categories of personal information described in section 2 for the purposes in section 3, and disclosed them to the categories of recipients in section 5. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly collect personal information of consumers under 16. California residents may exercise the rights to know, delete, correct and limit use of sensitive information by writing to support@leapfun.ai; an authorized agent may act for you with signed permission.
11. Children
The Services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We will update this page when our practices change and show the date of the last change at the top. For material changes affecting account holders we will also notify you by email or in the application before they take effect.
13. Contact
Questions and requests about this policy: support@leapfun.ai. LeapScope is the controller; a postal address will be published here before the product opens.