The short version
We use your information to run Leadop, protect your account, process payments, and help you research and write.
We do not sell personal data. We do not use Google Account data for advertising or to train AI models.
Your writing may be sent to selected AI providers when you ask Leadop to work on it.
You can ask to access, correct, export, or delete your personal data by contacting us.
Who we are
Leadop is an AI writing partner operated by Thousandhouse OÜ, an Estonian private limited company with registration number 17453651. Thousandhouse OÜ is the controller of personal data described in this policy.
Our registered address is Juhkentali tn 8, 10132 Tallinn, Estonia. You can contact us at contact@thousandhouse.com.
Data we collect
We collect the following categories of information:
- Account data. Your email address, account and workspace identifiers, sign-in history, and authentication records.
- Writing content. Prompts, conversations, notes, source links, saved articles, reactions, preferences, voice samples, drafts, posts, and other material you choose to add to Leadop.
- Billing data. Your plan, purchases, credit balance and usage, Stripe customer and transaction identifiers, and payment status. Stripe processes payment card details. Leadop does not store full card numbers.
- Usage and device data. Request times, IP address, browser and device information, pages or features used, model and token usage, diagnostic events, errors, and security signals.
- Communications. Messages you send us, support requests, and feedback.
Please avoid submitting sensitive personal data that Leadop does not need to provide the service.
Google user data
If you choose Continue with Google, Leadop requests the OpenID Connect scopes openid, email, and profile. Google may return your basic profile information, including your verified email address.
Leadop currently uses and stores the verified email address to authenticate you, find or create your account, and associate you with your private workspace. We do not store the Google OAuth access token after the sign-in flow. We do not access your Gmail, Google Drive, Calendar, contacts, or other Google service content through this sign-in.
We do not use Google user data for advertising, generalized AI model training, credit decisions, or purposes unrelated to authentication. We do not sell Google user data. We disclose it only to service providers as needed to operate and secure authentication, or when required by law.
Leadop's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How we use data
We use personal data to:
- create and secure your account and workspace;
- provide article discovery, research, writing, editing, and organization features;
- remember preferences and context you ask Leadop to use;
- process purchases, subscriptions, credits, and usage metering;
- send sign-in links, service messages, and replies to support requests;
- detect abuse, investigate errors, protect users, and maintain service reliability;
- understand aggregate product usage and improve Leadop; and
- comply with legal obligations and enforce our agreements.
Leadop does not publish or post your work automatically. You decide what to publish and where to publish it.
AI and service providers
Leadop relies on specialist providers to deliver the service. Depending on the feature you use, personal data may be processed by:
Cloudflare
Hosting, database, security, and request processing.
OpenAI and Anthropic
AI-assisted research, analysis, drafting, and editing.
Brave Search
Web search queries requested through the writing assistant.
Resend
Email delivery, including magic sign-in links and service messages.
Stripe
Checkout, payment processing, subscriptions, and fraud prevention.
Optional Google sign-in and account verification.
When you ask Leadop to analyze or generate text, relevant prompts, source material, conversation history, and workspace context may be sent to the selected AI provider. We limit these transfers to information needed for the requested feature and contractually require providers to protect the data they process for us.
The marketing site may use Umami, configured without analytics cookies, to collect basic pageview and engagement information.
Legal bases
For people in the European Economic Area, we rely on:
- Contract. Processing needed to create your account, provide Leadop, and handle billing.
- Legitimate interests. Protecting the service, preventing abuse, improving reliability, understanding aggregate usage, and responding to business inquiries.
- Consent. Where you make an optional choice that requires consent, including choosing Google sign-in. You may withdraw consent at any time, without affecting processing already completed.
- Legal obligation. Keeping records and responding where applicable law requires us to do so.
How long we keep data
We keep account information and workspace content while your account is active and for as long as needed to provide Leadop. You can delete certain notes, sources, chats, and writing samples in the product. You may contact us to request account deletion.
Magic-link tokens expire after 15 minutes. Login sessions expire after 30 days unless you sign out sooner. Google OAuth state data expires after 10 minutes. These values are stored as security-protected tokens.
After a deletion request, we delete or anonymize personal data unless we must retain it for legal obligations, fraud prevention, dispute resolution, security, or enforcement. Billing and transaction records may be kept for the period required by tax and accounting law. Backups and distributed systems may take additional time to cycle out deleted data.
Where no fixed period applies, we consider the amount and sensitivity of the data, the reason we collected it, security needs, and applicable legal requirements.
How we protect data
We use technical and organizational safeguards designed to protect personal data. These include encrypted connections, access controls, tenant-separated workspaces, hashed magic-link and session tokens, scoped service credentials, rate limits, and monitoring for errors and abuse.
No online service can guarantee absolute security. Please use a trusted device, protect access to your email or Google Account, and contact us if you believe your Leadop account has been compromised.
International transfers
Thousandhouse OÜ is based in Estonia. Some providers process data in the United States or other countries outside the European Economic Area. Where required, we use recognized safeguards such as adequacy decisions, Standard Contractual Clauses, and supplementary security measures.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to receive a portable copy of data you provided. You may also withdraw consent where processing relies on consent.
Send requests to contact@thousandhouse.com. We may need to verify your identity before completing a request. We will respond within the period required by applicable law.
If you are in the EEA, you may complain to your local data protection authority or the Estonian Data Protection Inspectorate. We would appreciate the chance to address your concern first.
Children
Leadop is a business and professional writing service and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, please contact us so we can review and remove it.
Changes to this policy
We may update this policy when Leadop, our providers, or legal requirements change. We will post the revised policy here and change the effective date. If a change materially affects how we use personal data, we will provide additional notice and seek consent where required.
Contact
Registration number 17453651
Juhkentali tn 8
10132 Tallinn, Estonia
contact@thousandhouse.com