Privacy Policy
Last updated: 2026-05-13
1. Summary
Leivar ("Leivar", "we", "us", "our") is an AI-orchestrated content operating system. This policy explains what personal data we collect when you use the Service, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We operate this policy globally; in addition to the general terms below, residents of specific regions have additional rights described in Sections 13–18.
We do not sell your personal data. We do not use your content to train AI models. We do not show third-party advertising on the Service today, and we do not run third-party marketing pixels on our website. If any of that changes, we will update this policy and, where required, ask you to consent again.
2. Who is responsible for your data
The data controller (GDPR / UK GDPR) and the business (CCPA / CPRA) for the Service is:
Leivar (operated by Kamugisha Ibrahim) Canada (full operator address available on written request via legal email) Canada Privacy contact: kamugishaibrah@gmail.com Legal contact: kamugishaibrah@gmail.com
For privacy enquiries, data-subject requests, or to exercise any right described in this policy, write to kamugishaibrah@gmail.com. We aim to respond within 30 days; statutory windows in your jurisdiction take precedence where shorter.
3. Categories of data we collect
3.1 Account & profile data
- Email address, password (hashed; we never see it in plaintext).
- Optional profile fields you provide: display name, biography, timezone, language preference, avatar image.
- Onboarding answers: attribution (where you heard about us), business stage, niche, tone preference, target audience, and content formats you intend to produce.
- OAuth identifiers (e.g. Google account ID) when you choose to sign in with a federated provider.
3.2 Content you create or upload
- Text prompts, briefs, scripts, captions, brand voice descriptions, and other instructions you submit to the AI.
- Files you upload: images, videos, audio, documents (PDF, DOCX, XLSX, PPTX, TXT, MD), reference packs.
- AI-generated outputs produced for you: drafts, images, videos, voiceovers, music, motion graphics, schedule plans.
- Knowledge graph nodes you create when you "teach Leivar" about your brand, products, or audience.
3.3 Connected-platform data
- OAuth access tokens and refresh tokens for the platforms you choose to connect (YouTube via direct Google API; Instagram, TikTok, X, LinkedIn, Facebook via Ayrshare).
- Profile metadata returned by those platforms when you authorise the connection (handle, channel ID, follower count if exposed by the platform).
- Post performance metrics we retrieve on your behalf (views, likes, comments, shares, saves, engagement rate).
- Comments and direct messages we retrieve on your behalf for the engagement features you enable.
3.4 Voice consent recordings (when you use voice cloning)
If and when you use the voice-cloning feature, we collect an audio recording of you reading a fixed consent phrase, the resulting voice fingerprint, a cryptographic nonce that binds the consent to your account, and a content-credential (C2PA) assertion on outputs derived from the cloned voice. These items are processed only to enforce the consent gate and to label synthetic media. The AI-character feature similarly processes a reference face/likeness plus your consent attestation; both are governed in detail by our Biometric & Likeness Data Policy.
3.5 Billing data
- Plan selection, token balance, subscription status, renewal/cancellation dates.
- Stripe customer ID, last-four card digits, country, ZIP/postal code (we do not store full card numbers — Stripe does).
- Invoices, receipts, refund history.
3.6 Automated logs and telemetry
- Request logs: timestamps, IP address, user agent, URL, status code, latency. Retained 30 days for operations and abuse prevention.
- Audit log: account-significant events (sign-in, plan change, account deletion, AI tool calls that mutate external systems, etc.).
- Crash and error reports.
- AI usage metering: which tools were invoked, token cost, latency, success/failure. Used for billing, abuse detection, and capacity planning.
3.7 Cookies and similar
See our Cookie Policy. In short: we use strictly necessary cookies for sign-in and session security, and a small set of functional cookies for preferences. We do not currently load any third-party analytics or marketing cookies.
3.8 Abuse reports
If you submit an abuse report via /legal/report we collect the report content, the reported URL, optional contact information you choose to provide, and a SHA-256 hash of your IP address for rate-limiting. Anonymous reports are accepted.
4. How we use your data and the legal basis (GDPR Art. 6)
We process personal data only where we have a lawful basis. The table below maps each processing purpose to its basis.
- To provide the Service to you — account creation, authentication, content generation, scheduling, publishing, analytics. Legal basis: performance of a contract (Art. 6(1)(b)).
- To bill you and prevent fraud — Stripe charges, invoicing, dispute handling. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- To keep the Service secure — rate limiting, abuse detection, prompt-injection defence, account-takeover detection. Legal basis: legitimate interest (Art. 6(1)(f)) in operating a safe platform.
- To comply with law — audit logs, abuse reports, response to lawful demands, takedown processing, CSAM reporting under 18 U.S.C. § 2258A and equivalents. Legal basis: legal obligation (Art. 6(1)(c)).
- To improve the Service — aggregate, usage telemetry (not your content) used to size capacity, debug models, and refine UX. Legal basis: legitimate interest (Art. 6(1)(f)).
- To send service emails — account, billing, policy updates. Legal basis: contract (Art. 6(1)(b)). We do not send marketing email today; if we begin, we will rely on consent (Art. 6(1)(a)) and provide an opt-out.
- To enforce the voice-cloning consent gate — storing the consent recording and nonce. Legal basis: explicit consent for special-category biometric data (Art. 9(2)(a)) where applicable, plus legitimate interest in preventing non-consensual cloning.
5. AI processing and how Leivar improves over time
Because we are an AI product, we want to be specific about what happens to the captions, scripts, images, audio, and video you submit, and how we learn from how the Service is used. We treat two categories of data very differently:
5.1 Customer Content
"Customer Content" means everything you create, upload, or generate through the Service — captions, scripts, video, images, voice clones, knowledge-base files, brand voice rules, and the AI outputs we produce for you in response to your prompts. Customer Content is yours.
- Leivar shall not use, nor permit a third party to use, Customer Content to train artificial intelligence models utilized by the Service. We use third-party model providers (listed in the Sub-processor list) under enterprise/business APIs. We configure providers not to train on your inputs where the provider offers that control, and we have not opted any of your Customer Content into any provider training program. Each provider's specific contractual position and data-retention terms are summarised in the Sub-processor list; we are completing signed data-processing agreements with each provider and not every provider's position has yet been independently verified (see the status note on that page).
- Customer Content is never shared with any other customer. Your prompts, drafts, captions, and uploads are visible only to you and the Leivar accounts you authorise.
- Your prompts and outputs are transmitted to the model provider you (or the AI router) selected for that turn. Those providers may retain inputs for a short period (typically 0–30 days) for abuse review under their terms. See the Sub-processor table for current vendor retention policies.
- Outputs you receive are yours, subject to the limits we describe in the Terms of Service. We make no warranty that AI outputs are copyrightable; current U.S. Copyright Office guidance is that purely AI-generated content lacks a human author and may not receive copyright protection.
5.2 Service Data
"Service Data" means data concerning your use of the Service and the performance of content you publish through it — for example, the platform-returned metrics on a post (views, engagement rate, saves, click-through rate), the structural metadata of what you published (hook category, length range, format type, posting time bucket), usage telemetry, error logs, and statistical or performance information generated by the Service. Leivar may use Service Data, including such statistical and performance information, for any lawful purpose including operating, maintaining, securing, and improving the Service. Leivar retains all rights in Service Data.
Service Data does notinclude the text or media of your Customer Content. The distinction matters: we may record that a hook of type "numerical" performed in the top 10% of its niche this month; we do not store the specific hook text in this bucket. Our legal basis for processing Service Data is our legitimate interest in operating and improving the Service (GDPR Art. 6(1)(f)), supplemented by the "statistical purposes" presumption of compatibility under Art. 5(1)(b) and Art. 89(1) for aggregate analytics.
5.3 Aggregated insights
We may use information that does not identify you — including information that has been aggregated or de-identified — for any purpose, including to surface playbook recommendations to other users.Aggregated insights describe abstract patterns (for example, "hooks leading with a number outperform benefit-led hooks by 22% across fitness creators this month, sample size 1,847") and never reveal an individual user's content, captions, identity, or per-account metrics. Before any aggregated pattern is surfaced to other users, the system enforces a minimum observation floor (a k-anonymity threshold) so single-user patterns cannot leak through.
Aggregated insights are de-identified in such a way that the data subject is not or no longer identifiable, and accordingly fall outside the definition of "personal data" under Article 4(1) and Recital 26 of the GDPR, and outside the definition of "personal information" under the California Consumer Privacy Act (Cal. Civ. Code § 1798.140(v)(3)).
5.4 Your control
You can opt this brand out of contributing to Aggregated insights at any time. The control lives on the /brand page as a Shared learning on / off toggle. Opting out removes your published content from the input set of future aggregations and does not affect your continued access to the Service. You may also exercise your underlying data-protection rights — including the right to object to processing under legitimate interest — using the contacts in Section 10.
6. Who we share data with
We share personal data with three categories of recipients, and no others:
- Sub-processors — third parties we use to run the Service (hosting, AI inference, payments, email, publishing). Each is contractually bound to confidentiality and to process data only on our instructions. The full, dated list lives at /legal/sub-processors.
- Platforms you connect — when you authorise a social platform, we send to that platform the content and metadata required to publish, schedule, retrieve metrics, or fetch comments. Those platforms operate under their own privacy policies.
- Authorities and successors — where required by law, court order, or valid legal process; in connection with an investigation of a violation of our Terms or this policy; to protect the rights, property, or safety ofLeivar, our users, or the public; or in connection with a merger, acquisition, financing, or sale of assets, in which case the acquirer takes on the obligations of this policy.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising as those terms are defined under the California Privacy Rights Act, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, or comparable laws.
7. International data transfers
Leivar operates as a global service. Some sub-processors are located outside the European Economic Area, the United Kingdom, Switzerland, Canada, Brazil, Australia, or your country of residence. When personal data leaves your home region we rely on the following transfer mechanisms:
- Standard Contractual Clauses (European Commission decision 2021/914) and the UK International Data Transfer Addendum for transfers from the EEA / UK.
- The EU–US Data Privacy Framework where the recipient is certified.
- Adequacy decisions where the European Commission, the UK ICO, or the Swiss FDPIC has determined the destination provides adequate protection.
- Equivalent mechanisms for transfers from other jurisdictions (e.g. APEC CBPR for some Asia-Pacific flows, ANPD-approved tools for Brazil under LGPD).
A copy of the relevant clauses is available on written request to kamugishaibrah@gmail.com.
8. How long we keep data
- Account & profile data — while your account is active, then 30 days after deletion (so the deletion can be reversed in case of mistake or account takeover).
- Content and AI outputs — while your account is active, then deleted within 30 days of account deletion. You may delete individual items at any time.
- Connected-platform tokens — until you revoke the connection or delete your account, whichever first. Tokens are refreshed transparently while connected.
- Voice consent recordings — retained for the life of the cloned voice plus 24 months after revocation, to defend against false-claims and to comply with synthetic-media traceability laws.
- Billing records — retained for the period required by tax law in our jurisdiction of incorporation (typically 7 years) and the laws of the country in which you were billed.
- Audit log — retained for 24 months for security and dispute purposes. The audit row remains after account deletion (the user_id reference is preserved but no longer resolves).
- Request logs — 30 days.
- Abuse reports — retained for 24 months from receipt or for the duration of any related investigation, whichever is longer.
9. Security
We use industry-standard technical and organisational measures including transport encryption (TLS) for all data in transit; encryption at rest for stored data through our infrastructure provider; an additional layer of application-level AES-256-GCM encryption applied specifically to connected-platform and cloud-storage OAuth tokens before they are written to the database; role-scoped database access (PostgreSQL row-level security on every multi-tenant table); least-privilege service accounts; request-level audit logging; multi-layer rate limits; and credential rotation. Note that your prompts and generated content are stored so the Service can function and are protected by the access controls and infrastructure encryption above, but are not additionally encrypted with a per-field application key. We restrict employee access to user data to a small number of accounts and require justification logged in our audit trail for any elevated access. No system is invulnerable; if a breach occurs that affects your personal data we will notify you and the relevant supervisory authority within the timelines required by GDPR Art. 33–34, equivalent UK/EU rules, and applicable US state breach laws.
10. Your rights — global baseline
Subject to local law, you may:
- Access the personal data we hold about you, and receive a copy in a structured machine-readable form. You can self-serve this from your Profile page (Account → "Export my data"), which downloads a JSON archive of your account, content, and a manifest of your uploaded files. For security, that export deliberately excludes live secrets — connected-platform and cloud-storage OAuth tokens, vault secrets, and single-use authentication tokens; you may request anything not covered in the self-serve export by writing to the contact below.
- Rectify data that is inaccurate or incomplete.
- Deleteyour account and the personal data associated with it. The "Delete Account" button on your profile page calls /api/account/delete which cascades through every user-scoped table, wipes your storage prefix, and removes your authentication record. Some records are retained as described in Section 8 (audit log, tax billing records).
- Restrict or object to processing where it is based on legitimate interest.
- Withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint with your local data protection authority (Sections 13–18 list the relevant body for each region).
To exercise any right, write to kamugishaibrah@gmail.com. We may need to verify your identity (for example by confirming you control the account email). We will respond within 30 days, or sooner if your local law requires.
11. Children
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13 (United States, COPPA), under 16 in the European Economic Area unless a Member State has set a lower digital-consent age between 13 and 16, or the applicable minimum age in your jurisdiction. If you believe a child has provided personal data to us, write to kamugishaibrah@gmail.com and we will delete it.
12. Automated decision-making
The Service uses automated systems extensively to generate, score, and screen content. We do not use automated processing in any way that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Art. 22. Two specific exceptions:
- Pre-publish content classification — an automated classifier checks content before it is sent to a third-party platform on your behalf. If it flags the content we place it on hold for human review (yours) rather than auto-blocking permanently.
- Abuse-rate limiting — automated rate limits may temporarily restrict access if your activity pattern looks like account takeover or scraping. You may contact support to request a manual review.
13. European Economic Area & European Union — additional rights
If you are in the EEA, the rights described in Section 10 are backed by Articles 12–22 of the General Data Protection Regulation (Regulation 2016/679, "GDPR"). You also have:
- The right to lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement. A list is maintained by the European Data Protection Board at edpb.europa.eu.
- The right to have decisions reviewed by a natural person where automated decision-making would otherwise produce legal or similarly significant effects.
EU Article 27 representative: Not currently appointed Not applicable until EU representative is appointed; EU data subjects may contact privacy email directly kamugishaibrah@gmail.com
14. United Kingdom — additional rights
If you are in the UK, your rights are backed by the UK GDPR and the Data Protection Act 2018. You may complain to the Information Commissioner's Office (ICO) at ico.org.uk.
UK Article 27 representative: Not currently appointed Not applicable until UK representative is appointed; UK data subjects may contact privacy email directly kamugishaibrah@gmail.com
15. California, and US state-privacy disclosures
This section applies if you are a resident of California (CCPA / CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or any other US state that has enacted a comprehensive consumer-privacy statute. The categories of personal information we collect, and the sources, purposes, and recipients of disclosure, are described in Sections 3, 4, and 6 above.
We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising. We do not knowingly process the personal information of consumers under 16 for sale or share without affirmative consent.
Sensitive personal information.The CPRA recognises a category of "sensitive personal information" that includes precise geolocation, racial or ethnic origin, religious beliefs, union membership, content of non-public communications, genetic data, biometric information used for identification, health information, and information about sex life or sexual orientation. The sensitive categories we may process are biometric and likeness information — voice fingerprints in the voice-clone feature and facial/likeness reference data in the AI-character feature — and we use them solely to provide the requested feature, enforce the consent gate, and label outputs, not for identification or inference about you. Full detail, including the retention and destruction schedule, is in our Biometric & Likeness Data Policy. You may direct us to limit our use of sensitive personal information by writing to kamugishaibrah@gmail.com.
Right to opt-out preference signal. We detect the Global Privacy Control (GPC) signal (the Sec-GPC request header) and record it as an opt-out of sale and sharing. Because we do not sell or share personal information, do not engage in cross-context behavioural advertising, and load no third-party analytics or advertising trackers, there is no such data flow to switch off; the signal is nonetheless recorded and any future non-essential processing will respect it before it is enabled.
Right to know, delete, correct, opt-out, limit, and non-discrimination. You have these rights as defined by California Civil Code §§ 1798.100, 1798.105, 1798.106, 1798.120, 1798.121, and 1798.125. We will not deny you services, charge you a different price, or provide a different level of quality because you exercise a privacy right.
Authorized agents.You may designate an authorized agent to act on your behalf. We may require proof of the agent's authority and verification of your identity.
Shine the Light (California Civil Code § 1798.83). We do not share personal information with third parties for their direct marketing.
16. Canada — additional notice
If you are in Canada, this policy doubles as our PIPEDA notice and incorporates the obligations of Quebec Law 25 (the Act respecting the protection of personal information in the private sector). You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the Commission d'accès à l'information du Québec at cai.gouv.qc.ca if you reside in Quebec.
17. Brazil — LGPD
If you are in Brazil, our processing of your personal data is governed by the Lei Geral de Proteção de Dados (Lei nº 13.709/2018). You have the rights listed in Articles 17–22. Our LGPD representative for Brazilian residents is:
Not currently appointed kamugishaibrah@gmail.com
You may complain to the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
18. Australia — APP notice
If you are in Australia, our handling of personal information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
19. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top, and, for material changes, give you notice in the Service or by email. Continued use after the effective date of a change constitutes acceptance to the extent permitted by law; where consent is required for a change, we will ask for it.
20. Contact
Privacy questions, data-subject requests, or anything else related to this policy: kamugishaibrah@gmail.com.
See also: Terms · Cookies · Refund · DMCA · Sub-processors · AUP · Biometric · Accessibility