Privacy Policy
Last updated: March 2026
1. Who We Are
openLEO is an AI assistant platform operated by Reza Rezvani, based in Berlin, Germany. We are committed to protecting your personal data and processing it in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection law.
Data Controller: Reza Rezvani, openLEO, Berlin, Germany
Contact: privacy@openleo.ai
2. Data We Collect
We collect the minimum data necessary to provide our service:
- Email address — to create and manage your account, send transactional emails, and waitlist communications.
- Usage data — feature interactions, session durations, and error logs to improve the platform.
- Assistant configurations — the names, instructions, and settings of AI assistants you create within openLEO.
- Prompt and conversation data — messages you send to your AI assistants, processed to generate responses.
- Billing information — handled directly by our payment processor; we do not store full card details.
3. How We Use Your Data
- Service delivery — running your AI assistants, storing configurations, and processing prompts.
- Product improvement — analysing aggregated usage patterns to prioritise features and fix bugs. Individual conversations are not used to train AI models without your explicit consent.
- Communication — sending account-related notifications, product updates, and waitlist status emails.
- Legal compliance — retaining records as required by German and EU law.
Our legal basis for processing is primarily contract performance (Art. 6(1)(b) GDPR) and, where applicable, legitimate interests (Art. 6(1)(f) GDPR).
4. Data Storage & Security
All data is stored on EU-hosted infrastructure. Your data is isolated per user — no assistant configuration or conversation data is accessible to other users or used across accounts.
We apply industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews.
5. Third-Party Processors
We work with carefully selected sub-processors to deliver our service:
- AI providers (e.g. Anthropic, OpenAI) — process prompts you send to your assistants. These providers operate under their own privacy policies and data processing agreements with openLEO. Prompts are not retained for model training under our agreements.
- Resend — used to deliver transactional and waitlist emails. Only your email address and message content are shared.
- Payment processor — handles subscription billing. We do not receive or store full payment card details.
6. Your Rights (GDPR)
As a data subject under GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your account and associated data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, email privacy@openleo.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Berlin Commissioner for Data Protection and Freedom of Information.
7. Cookies
openLEO uses only session cookies necessary for authentication and platform functionality. We do not use tracking, advertising, or analytics cookies. No cookie consent banner is required beyond this notice.
8. Data Retention
We retain your data for as long as your account is active. Upon account deletion, personal data is erased within 30 days, except where retention is required by law (e.g. invoicing records retained for 10 years per German tax law).
9. Changes to This Policy
We may update this policy as our service evolves. Material changes will be communicated via email or an in-app notice. The date at the top of this page reflects the latest revision.
10. Contact
Questions about this policy or your data? privacy@openleo.ai
Get early access to openLEO
Join the waitlist and be among the first to experience your AI assistant platform.