Legal

Privacy Policy

Last updated: August 2026. This policy describes how LeakLocked ("LeakLock Inc.") collects, uses, and protects your information.

Information we collect

We collect account information (name, email), message content you create or send through the platform, investigation uploads, and usage data necessary to operate and improve the service.

How we use information

We use your information to provide watermarking, sending, and investigation features; authenticate your account; communicate with you about the service; and improve security and reliability.

Data storage and security

Data is stored in MongoDB Atlas with encryption at rest. We use TLS for data in transit, access controls, audit logging, and optional multi-factor authentication. See our Security page for details.

Subprocessors

We use third-party providers to operate the service. They process data only on our instructions:

  • MongoDB Atlas — database
  • Deno Deploy — application hosting
  • Resend — email delivery
  • OpenAI — signature detection and leak text extraction (OCR)
  • Google / Microsoft — sign-in (OAuth)
  • Adobe — PDF conversion

Retention

We retain your content until you delete it or delete your account. Security audit logs are retained for 12 months. Session data expires within hours of inactivity.

Your choices

You may access and update profile data in Account settings. Delete your account and associated data from Account → Delete account, or contact contact@leaklocked.com for data subject requests.

Contact

Privacy questions? Contact us at contact@leaklocked.com.