Legal · Last updated 5 October 2026
Privacy Policy
Leakly analyses public pages and, when you connect them, your own analytics sources to produce a ranked conversion audit. This policy explains what we collect, why, how long we keep it, and the rights you can exercise at any time.
1. Who is responsible for your data
The data controller is Sky Labs LLC, a limited liability company incorporated in Wyoming, United States, with its registered office at 30 N Gould St Ste N, Sheridan, WY 82801, United States. Leakly is a product operated by Sky Labs LLC. You can reach our privacy contact at hello@leakly.ai. We have not appointed a data protection officer; privacy requests go to the same address.
2. What we collect
Data you give us
- Audit inputs — the URL you submit and the conversion goal you select.
- Contact data — the email address you give us to receive your report.
- Billing data — if you buy a paid plan, your plan and billing details. Card details are handled by our payment provider and never reach our servers.
- Support messages — anything you send us by email.
Data we collect automatically
- Audit output — the pages we fetch, rendered screenshots, extracted copy, measured performance and the findings we derive from them.
- Product usage — pages viewed, features used, device and browser type, coarse location derived from IP, and error logs. Collected unless you refuse analytics cookies in the cookie banner.
- Server logs — standard HTTP request data including IP address, user agent and timestamps, kept for security and debugging.
When you connect an analytics source
Analytics, tag manager and CRM connections are on our roadmap and are not available yet. When they ship, connecting one will let us read the aggregate metrics needed for the audit (sessions, funnel steps, events, conversion rates). We will not import customer-level records unless you explicitly map them, and this policy will be updated before the feature is released.
We do not knowingly collect special-category data, and Leakly is not intended for anyone under 16.
3. Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Running audits and delivering the report you asked for | Performance of the contract |
| Sending the report to the email address you provide | Performance of the contract |
| Billing, fraud prevention, accounting | Contract · legal obligation |
| Product analytics, experimentation and reliability monitoring | Legitimate interest (understanding how the service is used) — you can refuse at any time in the cookie banner |
| Security logging and abuse prevention | Legitimate interest (keeping the service available and safe) |
| Product emails and newsletters | Consent, or legitimate interest for existing customers |
| Aggregated, de-identified benchmarks published in our content | Legitimate interest — never traceable to your company |
Where we rely on consent you can withdraw it at any time, without affecting processing already carried out.
4. Who we share it with
We never sell your data. We use a short list of processors bound by data-processing agreements and instructed to act only on our behalf:
| Processor | Role | Location |
|---|---|---|
| Hetzner | Application and database hosting | Finland (EU) |
| PostHog | Product analytics and experimentation | United States |
| Google (Google Analytics 4) | Audience and traffic measurement | United States |
| Google (Google Ads) | Measuring advertising campaigns, unless you refuse marketing cookies | United States |
| Resend | Transactional email (delivering your report) | United States |
| OpenAI | Generating audit findings and recommendations | United States |
Content submitted for an audit is not used to train third-party models. We may also disclose data to professional advisers, to an acquirer in a corporate transaction, or to authorities where the law requires it.
5. International transfers
Application data is stored in Hetzner data centres in Finland (European Union). Sky Labs LLC operates from the United States, and several of our processors are US-based, so your data is transferred to the United States. Those transfers are covered by the European Commission's standard contractual clauses plus supplementary technical measures (encryption in transit and at rest, access logging, data minimisation).
6. How long we keep it
- Audits and reports — 24 months, or until you ask us to delete them.
- Email addresses submitted for a report — until you unsubscribe or ask for erasure.
- Billing records — 7 years, as required by accounting law.
- Server and product logs — 30 days.
- Your cookie choice — 12 months, then we ask again.
7. Your rights
Subject to the GDPR you may request access, rectification, erasure, restriction or portability of your data, object to processing based on legitimate interest, and withdraw consent. Write to hello@leakly.ai — we answer within one month. If our answer does not satisfy you, you may lodge a complaint with your local supervisory authority. If you are in California, the CCPA gives you comparable rights to know, delete and opt out of any sale of personal information; we do not sell personal information.
8. Security
Encryption in transit (TLS 1.2+) and at rest, least-privilege access with MFA for our team, isolated environments, audit logging, and regular restore tests of encrypted backups. We notify affected customers and the competent authority within 72 hours of confirming a personal-data breach.
9. Changes
We post material changes on this page and email account owners at least 15 days before they take effect.
Questions about any of this? Write to hello@leakly.ai.