Leo

Leo Privacy Policy

Last updated: 7 September 2026 · Account deletion

This Privacy Policy explains how Leo (“Leo”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use the Leo mobile application and related services (together, the “Service”). Leo is a social app for phone sign-in, chat, stories, clips, voice rooms, live gifts, 1:1 and group calls, families, relationships, rankings, and a diamond wallet.

By creating an account or using Leo, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Who we are and how to contact us

Leo operates the Service. Questions about privacy, access, correction, or deletion of your data should be sent to support@leo.app. Include the phone number on your account and your Leo ID so we can find the right record.

2. Scope

This policy covers information processed through the Leo Android and iOS apps, our Firebase backends, media hosting, SMS delivery, and live-audio servers used for calls and voice rooms.

It does not control how other users treat information you choose to share with them (for example a photo you send in chat, or a gift you send in a public room). Once you share something with other people, they may copy, screenshot, or re-share it outside Leo.

3. Information we collect

We collect the categories below. Some items are required to create an account. Others are optional and only collected if you use that feature or grant a permission.

3.1 Account and identity

3.2 Profile information you choose to add

3.3 Contacts and social graph

We do not sell your address book. Contact matching is used only to help you find people you already know and to apply story visibility rules.

3.4 Messages, stories, clips, and uploads

Media is stored with our hosting providers (including Cloudinary and, where used, Firebase Storage and Cloudflare R2). Chat messages are stored in our Realtime Database or Firestore so both people can see conversation history.

3.5 Voice rooms, calls, and live audio

3.6 Location

We do not continuously track your movement in the background for advertising.

3.7 Wallet, diamonds, gifts, and status

Diamonds are virtual items used inside Leo. They are not bank deposits. See the Refund Policy in the app for how purchases and unused balances are treated.

3.8 Device, diagnostics, and notifications

3.9 Permissions the app may request

Leo asks for permissions so features work. You can refuse or later revoke them in system settings. If you refuse, that feature will not work, but you can still use the rest of the app.

4. How we use information

We use the information above to:

We do not use your chat contents or address book to sell third-party advertising against your name.

5. Legal bases (where this applies)

If you are in a region that requires a legal basis (for example the EEA, UK, or similar laws), we process personal data because:

6. How information is shared

6.1 Other users

Your public profile (name, photo, Leo ID, bio, gender, age if you set a birthday, location text, badges, level, family, couple status, gift counters, and similar fields) can be seen by other people who open your profile or sit in the same public room.

Messages and media in a private chat are visible to the people in that chat. Room chat, gifts, PK activity, and seat presence are visible to people in that room and may appear on public rankings. Stories are limited to eligible contacts. Clips and mentions can be seen more widely inside Leo.

6.2 Service providers

We use trusted companies that process data on our instructions to run the Service:

6.3 Legal, safety, and business transfers

We may disclose information if we believe it is required by law, to respond to a valid legal request, to protect users or the public, to investigate fraud or abuse, or as part of a merger, acquisition, or sale of assets (in which case this policy will still apply or you will be notified of a change).

6.4 We do not sell personal information

We do not sell your personal information and we do not share it with third parties for their own cross-context advertising.

7. Public, private, and user-generated content

Think carefully before you post. Public rooms, rankings, clips, and profiles are designed to be seen by other Leo users. Do not share bank details, government IDs, or anyone else’s personal data in a room or clip.

You can edit your profile, leave a room, block another user, and delete some content you posted. Copies that other users already saved, and logs we keep for safety, may remain.

8. Cookies and on-device storage

The mobile app does not use web advertising cookies. It does store small amounts of data on your device so the app works offline and remembers your choices: login session, theme, language, onboarding, permission bootstrap flags, and cached assets. You can clear app data from your device settings; that will sign you out and reset local preferences.

This website uses no advertising cookies.

9. International processing

Leo is used in more than one country. Our primary databases are hosted in Google Cloud regions in Asia (including asia-southeast1 and asia-south1). Live-media servers and SMS providers may process data in other countries. If you use Leo from outside those regions, your information is transferred to where our providers operate. We rely on the safeguards those providers offer (for example Google Cloud contractual terms) and on the fact that the transfer is needed to provide the Service.

10. How long we keep information

When you ask us to delete your account, we delete or de-identify personal data we no longer need, except records we must keep (payments, abuse, legal holds). See Delete your account.

11. Security

We use industry-standard measures appropriate to a social app: encrypted transport (HTTPS / WSS), authenticated API access, server-side rules on many collections, and limited staff access. No method of transmission or storage is completely secure. You can help by not sharing your OTP, not installing unofficial builds, and logging out on devices you do not control.

Gift-agent PINs and OTP codes are sensitive. We will never ask you in a room or chat to send your OTP or PIN to another user.

12. Your choices and rights

You can:

Depending on where you live, you may also have the right to object to certain processing, restrict processing, or lodge a complaint with a data-protection authority. We will respond to valid requests within a reasonable time after we verify that the request comes from the account holder.

13. Account deletion

To delete your Leo account and associated personal data, use this account deletion page or email support@leo.app with your phone number and Leo ID. We may ask you to complete an OTP check so we know it is you.

Deletion closes the account, signs you out, and removes or de-identifies profile data we no longer need. Unused diamonds are forfeited and are not paid out as cash. Sent gifts, room rankings, and messages already delivered to other users are not reversed.

14. Children

Leo is not directed to children under 13, or under the minimum digital-consent age in your country if that age is higher. Do not create an account if you are under that age. We do not knowingly collect personal information from children below that age.

If you are a parent or guardian and believe a child has created an account, contact support@leo.app. We will delete the account when we can verify the request.

15. Third-party links and services

Rooms, chats, or clips may contain links or content from other people. Their sites and apps have their own policies. Payment processed by Apple, Google, or another store is also covered by that store’s privacy policy. We are not responsible for those third-party practices.

16. Changes to this policy

We may update this Privacy Policy when we add features or when the law changes. The “Last updated” date at the top will change. For material changes we will give extra notice in the app when we can. Continued use after an update means you accept the revised policy. If you do not agree, stop using Leo and ask us to delete your account.

17. Contact

Privacy, data-access, correction, and deletion requests: support@leo.app.

Please do not send OTPs, gift-agent PINs, or payment-card numbers in that email.