Leo Privacy Policy
This Privacy Policy explains how Leo (“Leo”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use the Leo mobile application and related services (together, the “Service”). Leo is a social app for phone sign-in, chat, stories, clips, voice rooms, live gifts, 1:1 and group calls, families, relationships, rankings, and a diamond wallet.
By creating an account or using Leo, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Who we are and how to contact us
Leo operates the Service. Questions about privacy, access, correction, or deletion of your data should be sent to support@leo.app. Include the phone number on your account and your Leo ID so we can find the right record.
2. Scope
This policy covers information processed through the Leo Android and iOS apps, our Firebase backends, media hosting, SMS delivery, and live-audio servers used for calls and voice rooms.
It does not control how other users treat information you choose to share with them (for example a photo you send in chat, or a gift you send in a public room). Once you share something with other people, they may copy, screenshot, or re-share it outside Leo.
3. Information we collect
We collect the categories below. Some items are required to create an account. Others are optional and only collected if you use that feature or grant a permission.
3.1 Account and identity
- Phone number (E.164 format) used to sign in. We send a one-time password (OTP) by SMS to verify that you control the number.
- A derived sign-in identity used with Firebase Authentication so we can keep your session without asking you to invent a password.
- A unique Leo ID assigned to your account so other people can find and connect with you.
- Firebase user ID (UID), account creation time, and session version.
- Active device identifier and, where used, a record of the last device that signed in.
3.2 Profile information you choose to add
- Display name, profile photo, cover photo, and bio.
- Gender, birthday (and the age we calculate from it), and location text you add to your profile or to a voice room.
- Avatar frames, entry effects, badges, achievement counters, level, Noble and SVIP status, family membership and role, couple or friend relationship IDs, and other cosmetic or status fields shown on your public profile.
3.3 Contacts and social graph
- If you grant Contacts permission, we read phone contacts on your device so we can show which of your contacts also use Leo, suggest people to chat or call, and limit some stories to contacts who are already on Leo.
- People you connect with by Leo ID, follow, block, or add as chat members; follower and following counts.
- Family, couple, and friend relationships you create or accept.
We do not sell your address book. Contact matching is used only to help you find people you already know and to apply story visibility rules.
3.4 Messages, stories, clips, and uploads
- Chat content you send or receive: text, emoji, images, videos, voice notes, files, shared contacts, and location pins.
- Stories you post (visible for about 24 hours to eligible contacts) and clips you publish, including captions, mentions, language, and country tags taken from your profile.
- Photos and files you upload for avatars, room covers, SVIP or gift-agent verification, and similar features.
- Moderation reports, ban-review requests, and any text or media you attach when you report abuse.
Media is stored with our hosting providers (including Cloudinary and, where used, Firebase Storage and Cloudflare R2). Chat messages are stored in our Realtime Database or Firestore so both people can see conversation history.
3.5 Voice rooms, calls, and live audio
- Rooms you create or join: title, cover, announcement, location, host, seat layout, contributor lists, weekly gift totals, and owner-task progress.
- Live microphone and camera streams for voice rooms, PK battles, 1:1 calls, and group calls. Live audio and video are sent through our media servers so other participants can hear and see you. We do not record voice-room or call audio as a stored file by default.
- Call signaling data: who called whom, room IDs, ring and connect times, and whether a call was answered, missed, or declined.
- In-room chat, gifts, games, PK scores, and seat or mute state.
- Time spent in rooms (used for room level and some achievements), subject to daily caps.
3.6 Location
- If you grant Location permission, we may read your approximate or precise location when you share a live location pin in chat or tap “Use current location” while creating a voice room.
- A location label you type yourself (for a profile or room) is stored as text even if GPS is off.
We do not continuously track your movement in the background for advertising.
3.7 Wallet, diamonds, gifts, and status
- Black Diamond (recharge) and Yellow Diamond (earned) balances, including frozen amounts that cannot be spent.
- Store package you selected, listed price, credit amount, bonus diamonds, and a recharge transaction record.
- Gifts you send or receive: gift type, quantity, diamond type, sender, receiver, room, and resulting Yellow Diamonds credited to the receiver.
- Wallet ledger entries, received-gift collections, weekly / daily / monthly rankings, room contributor totals, Noble and SVIP recharge progress, and gift-agent or reseller activity if you are assigned that role.
- A gift-agent transaction PIN is stored only as a verification secret for selling or transferring diamond quota. We send an OTP to your phone when you create or reset that PIN.
Diamonds are virtual items used inside Leo. They are not bank deposits. See the Refund Policy in the app for how purchases and unused balances are treated.
3.8 Device, diagnostics, and notifications
- Device type, operating system, app version, language and theme you choose, and basic capability signals so we can keep the app stable on low-end devices.
- Push tokens: Firebase Cloud Messaging (FCM) token and, on iOS, a VoIP token so we can deliver incoming-call and other alerts.
- Crash and error logs generated on the device. We use these to fix bugs. We do not run third-party advertising SDKs to profile you for ads.
- On-device preferences stored locally (theme, language, onboarding seen, whether first-launch permissions were already requested).
3.9 Permissions the app may request
Leo asks for permissions so features work. You can refuse or later revoke them in system settings. If you refuse, that feature will not work, but you can still use the rest of the app.
- Microphone — voice rooms, calls, voice notes, and face filters that need audio.
- Camera — profile photos, chat photos/video, clips, stories, video calls, and face filters.
- Photos / media library — picking images, videos, or files to send or set as an avatar.
- Contacts — finding friends already on Leo and contact-limited stories.
- Location — optional live location in chat and optional room location.
- Notifications — messages, calls, gifts, and other alerts.
- Phone, Bluetooth, battery optimization, and full-screen intent (Android) — incoming-call UI, audio routing, and reliable ringing when the app is in the background.
4. How we use information
We use the information above to:
- Create, secure, and recover your account, including OTP sign-in and session control.
- Show your profile, Leo ID, badges, levels, family, couple status, and public room activity to other users as designed by each feature.
- Deliver chat, stories, clips, voice rooms, PK battles, games, calls, and notifications.
- Process diamond top-ups, gifts, rankings, Noble / SVIP progress, and gift-agent transfers.
- Match contacts who are already on Leo and apply story visibility.
- Detect spam, scams, harassment, under-age use, payment abuse, and other violations; review reports; freeze diamonds; and suspend or ban accounts.
- Operate customer support and investigate refund or billing questions.
- Improve reliability, translate the interface, and remember your theme and language.
- Comply with law and enforce our terms.
We do not use your chat contents or address book to sell third-party advertising against your name.
5. Legal bases (where this applies)
If you are in a region that requires a legal basis (for example the EEA, UK, or similar laws), we process personal data because:
- The processing is necessary to provide the Service you asked for (account, chat, rooms, wallet).
- You consented, for example by granting microphone, camera, contacts, or location permission, or by posting public content.
- We have a legitimate interest in keeping the Service safe, preventing fraud, and improving features, balanced against your rights.
- We must keep some records to meet legal, tax, or dispute obligations.
6. How information is shared
6.1 Other users
Your public profile (name, photo, Leo ID, bio, gender, age if you set a birthday, location text, badges, level, family, couple status, gift counters, and similar fields) can be seen by other people who open your profile or sit in the same public room.
Messages and media in a private chat are visible to the people in that chat. Room chat, gifts, PK activity, and seat presence are visible to people in that room and may appear on public rankings. Stories are limited to eligible contacts. Clips and mentions can be seen more widely inside Leo.
6.2 Service providers
We use trusted companies that process data on our instructions to run the Service:
- Google Firebase — Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Messaging, Hosting, and related services.
- Cloudinary, Firebase Storage, and Cloudflare R2 — photos, videos, voice notes, avatars, room covers, clips, and other uploads.
- notify.lk — SMS delivery of OTP codes.
- Our live-media servers — real-time audio and video for voice rooms and calls.
- Apple, Google, or other app stores and payment channels if you pay through them. They process the payment under their own policies. We receive confirmation that a package was purchased so we can credit diamonds. We do not store your full card number.
6.3 Legal, safety, and business transfers
We may disclose information if we believe it is required by law, to respond to a valid legal request, to protect users or the public, to investigate fraud or abuse, or as part of a merger, acquisition, or sale of assets (in which case this policy will still apply or you will be notified of a change).
6.4 We do not sell personal information
We do not sell your personal information and we do not share it with third parties for their own cross-context advertising.
7. Public, private, and user-generated content
Think carefully before you post. Public rooms, rankings, clips, and profiles are designed to be seen by other Leo users. Do not share bank details, government IDs, or anyone else’s personal data in a room or clip.
You can edit your profile, leave a room, block another user, and delete some content you posted. Copies that other users already saved, and logs we keep for safety, may remain.
8. Cookies and on-device storage
The mobile app does not use web advertising cookies. It does store small amounts of data on your device so the app works offline and remembers your choices: login session, theme, language, onboarding, permission bootstrap flags, and cached assets. You can clear app data from your device settings; that will sign you out and reset local preferences.
This website uses no advertising cookies.
9. International processing
Leo is used in more than one country. Our primary databases are hosted in Google Cloud regions in Asia (including asia-southeast1 and asia-south1). Live-media servers and SMS providers may process data in other countries. If you use Leo from outside those regions, your information is transferred to where our providers operate. We rely on the safeguards those providers offer (for example Google Cloud contractual terms) and on the fact that the transfer is needed to provide the Service.
10. How long we keep information
- Account and profile data — while your account is open.
- Chat history and media — while the conversation exists or until the media is deleted from our hosts.
- Stories — about 24 hours, then they expire from the feed. Backup copies on media hosts may last a short extra period before cleanup.
- Live call and room audio — streamed, not kept as a recording by default.
- Wallet, gift, recharge, ranking, and gift-agent records — for as long as needed to operate balances, rankings, dispute reviews, and legal or tax obligations.
- Push tokens — until they are replaced or the account is closed.
- Safety, ban, and fraud records — longer if needed to prevent repeat abuse or to comply with law.
When you ask us to delete your account, we delete or de-identify personal data we no longer need, except records we must keep (payments, abuse, legal holds). See Delete your account.
11. Security
We use industry-standard measures appropriate to a social app: encrypted transport (HTTPS / WSS), authenticated API access, server-side rules on many collections, and limited staff access. No method of transmission or storage is completely secure. You can help by not sharing your OTP, not installing unofficial builds, and logging out on devices you do not control.
Gift-agent PINs and OTP codes are sensitive. We will never ask you in a room or chat to send your OTP or PIN to another user.
12. Your choices and rights
You can:
- Edit your name, photo, bio, gender, birthday, and location in your profile.
- Control who you chat with, leave rooms, block users, and hide some badges from your public profile.
- Turn notifications off in the app or in system settings.
- Revoke microphone, camera, contacts, photos, or location in system settings.
- Log out of this device from Settings.
- Ask us to access, correct, or delete personal data we hold, or to export a copy, by emailing support@leo.app or using the account deletion page.
Depending on where you live, you may also have the right to object to certain processing, restrict processing, or lodge a complaint with a data-protection authority. We will respond to valid requests within a reasonable time after we verify that the request comes from the account holder.
13. Account deletion
To delete your Leo account and associated personal data, use this account deletion page or email support@leo.app with your phone number and Leo ID. We may ask you to complete an OTP check so we know it is you.
Deletion closes the account, signs you out, and removes or de-identifies profile data we no longer need. Unused diamonds are forfeited and are not paid out as cash. Sent gifts, room rankings, and messages already delivered to other users are not reversed.
14. Children
Leo is not directed to children under 13, or under the minimum digital-consent age in your country if that age is higher. Do not create an account if you are under that age. We do not knowingly collect personal information from children below that age.
If you are a parent or guardian and believe a child has created an account, contact support@leo.app. We will delete the account when we can verify the request.
15. Third-party links and services
Rooms, chats, or clips may contain links or content from other people. Their sites and apps have their own policies. Payment processed by Apple, Google, or another store is also covered by that store’s privacy policy. We are not responsible for those third-party practices.
16. Changes to this policy
We may update this Privacy Policy when we add features or when the law changes. The “Last updated” date at the top will change. For material changes we will give extra notice in the app when we can. Continued use after an update means you accept the revised policy. If you do not agree, stop using Leo and ask us to delete your account.
17. Contact
Privacy, data-access, correction, and deletion requests: support@leo.app.
Please do not send OTPs, gift-agent PINs, or payment-card numbers in that email.