A glass dome sheltering a small lit storefront in the dark

Security and privacy

Built private and
secure, first

Before anything we build answers a call, drafts a reply or takes a payment, it clears the same bar: your customers' information stays yours, and a human signs off on anything they will ever see.

How we build

Nothing customer-visible ships without a human OK.

Every review reply, follow-up text, post and email our AI agents draft is approval-gated: it waits for a person before it goes anywhere. That is not a beta limitation, it is the design, and it never comes off.

Under the hood, the same caution applies. Our systems fail closed: if a key is missing or a check cannot run, the system stops instead of guessing. Every public endpoint is rate-limited and server-side validated. Private feeds are HMAC-signed, so a request without the right signature gets nothing. And every page ships with strict security headers.

We write this code by hand, the same way we build the websites: small, readable, and reviewed before it runs anywhere near your customers.

Your data

  1. 01

    We collect the minimum to do the job

    The contact details you give us in a form. The leads an AI agent captures for you: a name, a number, what they asked for. Counters that record what a service did, so your monthly email reports real numbers. Our free scanner records the site checked and what it found. That is the list. No browsing profiles, no data brokers, no tracking beyond anonymized analytics that never carry your message text or contact details.

  2. 02

    It lives in per-client isolated stores

    Each client's records sit in their own keyed store, never mixed with another business's data. Access is scoped per client and signed per client, so one client's key structurally cannot read another's records. Health-adjacent clients: appointment and contact handling only, no health details stored.

  3. 03

    You can take it or delete it, any time

    Your data is exportable on request, in plain formats you can actually use. If you leave, your service runs to the end of the period you paid for, and your service data is deleted within 30 days of offboarding. We put that in writing per service, before you sign up.

Payments

Card details never touch our servers.

Every checkout, saved payment method and billing update runs on Stripe-hosted pages. We see that a payment happened; we never see, store or transmit a card number. Invoices, payment methods and cancellation live in the Stripe customer portal, on Stripe's infrastructure, not ours.

The AI layer

Where AI helps, and where it is fenced in.

Our AI agents draft, sort and answer from the business facts you approve. Around that sits the fence: approval gates on anything customer-visible, per-client usage caps so a runaway can never happen quietly, audit-logged actions so there is a record of what ran and when, and a kill switch per client that halts everything at once.

On training: our AI provider is Anthropic, and per its commercial data policy, Anthropic does not use API inputs or outputs to train its models by default. Your customers' conversations are not teaching anyone's model.

And the free scanner on our homepage is not AI at all. It is a self-built tool running fixed, server-side checks.

The other side of the promise

What we never do.

We never sell or rent your data. Not to advertisers, not to partners, not in aggregate. Your customer list is your business.

We never buy contact lists. Every AI agent works only with the customers who contacted you.

We never post or send anything customer-visible without approval. Yours or ours, depending on the rules you set, but always a person.

We never claim certifications we do not hold. Payments run through Stripe, which carries its own certifications. LeadLeak itself is a two-person studio, and we would rather show you exactly how we work than borrow a badge.

Who else touches the data

The handful of companies we rely on.

We keep this list short on purpose. Each company processes one narrow slice, and nothing more.

Netlify. Hosts the site, runs our serverless functions, and holds the keyed data stores where each client's records live.

Anthropic. The AI that drafts and answers. Per its commercial data policy, Anthropic does not use API inputs or outputs to train its models by default.

Stripe. All payment data. Card numbers never touch our servers; checkout and billing run on Stripe-hosted pages.

Brevo. Sends our transactional email: order confirmations, alerts, and the monthly reports. Recipient addresses transit Brevo when a message goes out.

Google Analytics. Anonymized traffic counts only, with IP anonymization on. It never carries a message, a contact detail, or anything a visitor typed.

What we hold, and for how long

Minimal, per client, and never kept forever.

The whole list is short: the contact details you send us, the leads an agent captures for you (a name, a number, what someone asked for), counters that let your monthly report show real numbers, and the results of the site checks we run. No browsing profiles, no bought lists.

Every client's records sit in their own keyed store, scoped and signed per client, so one client's data structurally cannot read another's. We keep the minimum the job needs, and nothing extra.

Service data is deleted within 30 days of offboarding, and that deletion is now automated. A daily retention sweep stamps the clock when a client offboards and removes their stored data once the 30 days are up, then logs exactly what it deleted. Consent records, like opt-outs, are the one thing we keep, because that state has to outlive the service. Want a copy first? Your data is exportable on request, in plain formats you can actually use.

Responsible AI

How the agents are fenced in.

A person approves anything a customer will ever see, and that gate does not come off. Around it, every agent runs inside hard limits: a per-agent kill switch, daily send caps so nothing can run away quietly, and quiet hours that hold messages to sensible times.

The agents also refuse, by design. They will not invent a price or a fact you did not give them. They will not act on instructions hidden inside an email, a form, or a web page; they follow only the rules you set. And they cannot reach across clients: one business's agent only ever sees that business's data.

Every action is logged, so there is always a record of what ran, when, and whether a human approved it. See how we test every agent.

Found a problem?

Tell us, and thank you.

If you find a security issue in anything we run, email hello@leadleakai.net and we will get on it. A machine-readable contact lives at /.well-known/security.txt.

Ask us how we handle anything

If a question about your data is not answered here, ask it. You will get a plain answer from us, usually within one business day.