Privacy Policy

Last updated: August 2026

Leatly is a news reader. As part of our activities, we collect and process personal data relating to our users. These different data processing operations are detailed in this Privacy Policy.

1. What data we process and why

1.1 Account and authentication data

If you create an account, we process the data needed to create and manage it, such as your name, email address, account identifiers, and email verification status.

If you sign in via Google or GitHub OAuth, we receive the data you choose to share via the provider (typically email address, display name, and profile image URL) and we store provider-related account identifiers. Where required by the authentication flow, we may also store OAuth tokens (such as access or refresh tokens) to complete sign-in and manage sessions.

Passwords (if you use email/password login) are stored hashed.

1.2 Anonymous use

If you use Leatly without registering, we may create a temporary anonymous account so you can try the Service. Anonymous accounts that are not converted to a registered account are deleted after up to 7 days.

1.3 Session and security data

We use secure, HTTP-only authentication cookie(s) to keep you logged in. These cookie(s) are strictly necessary for the Service to work.

For account security and abuse prevention, our authentication system stores server-side session data including a session token, expiration time, and session metadata such as IP address and browser user agent associated with the session.

1.4 Your subscriptions, preferences, and in-app data

We process the data you create in the app so we can provide the Service, sync across devices, and apply your configured preferences. This includes:

  • Feed subscriptions (feed URLs, titles, ordering, and folder assignment)
  • Folders and tags
  • Rules/automation you configure
  • Read/unread and closed/dismissed item state
  • App settings (e.g. theme, font, UI preferences)

Some preferences and cached content are also stored locally on your device using browser storage (e.g. Local Storage / IndexedDB) and may be cached by a service worker for offline capability. This local data stays on your device unless you clear it via your browser/app settings.

1.5 RSS/Atom fetching and cached feed content

When you subscribe to a feed, our servers periodically fetch that feed and cache limited feed item data to display it efficiently. We cache only what the feed publishes (for example: title, URL, author (if provided), publication date, categories (if provided), thumbnail/image URL, and short summary/snippet).

We support caching mechanisms such as ETag and If-Modified-Since where the feed provides them.

1.6 Billing data (Pro plan)

If you subscribe to Pro, payments are processed by Stripe. We do not store your full payment card details. We process and store limited billing-related data needed to provide Pro, such as your Stripe customer/subscription identifiers, plan status, and billing period status.

Stripe processes billing and invoicing data under its own privacy policy.

1.7 Sharing links

Leatly may allow you to generate a share link to share selected parts of your setup (for example, subscriptions, folders, or tags). Anyone who has the share link may be able to view and/or import the shared data.

Share links are token-based and may expire. You control whether you create such a link and you can revoke it by disabling/deleting it (where the feature is available) or by contacting us.

1.8 Support communications

If you contact support, we will process the information you send us (such as your email address and message) to respond and resolve your request.

1.9 What we do not do

  • No advertising profiles
  • No third-party analytics (no Google Analytics, Mixpanel, etc.)
  • No sale of personal data
  • No link decoration or tracking parameters added to publisher URLs
  • No marketing emails (we send only transactional emails such as login and billing-related messages)

1.10 Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of GDPR Article 22.

2. Legal bases (GDPR Article 6)

  • Contract performance (Art. 6(1)(b)): to provide the Service (accounts, sessions, subscriptions, sync, preferences, and fetching/caching feeds you requested).
  • Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, and maintain reliability (e.g. session security metadata such as IP address/user agent, and Cloudflare WAF/rate limiting).
  • Legal obligation (Art. 6(1)(c)): where we must comply with applicable laws (for example, accounting/tax obligations that may apply to billing records).

3. Summary table (processing, purpose, legal basis, retention)

DataPurposeGDPR basisRetention
Account data (name, email, identifiers, email verification status)Provide and manage your accountArt. 6(1)(b)Until account deletion
OAuth provider data (e.g. provider account ID; tokens if applicable)Enable sign-in via providerArt. 6(1)(b)Until account deletion
Session cookie(s) + server-side session record (token, expiry, IP address, user agent)Authentication; account security; abuse preventionArt. 6(1)(b), Art. 6(1)(f)Until session expires (typically within ~7 days) or is revoked
Network traffic data (e.g. IP address, request metadata) processed by CloudflareContent delivery, security (WAF), rate limiting, abuse preventionArt. 6(1)(f)According to Cloudflare retention and our Cloudflare configuration
Subscriptions, folders, tags, rules, preferencesProvide core app functionality and syncArt. 6(1)(b)Until account deletion
Cached feed item metadata/snippetsEfficient display of feeds you subscribed toArt. 6(1)(b)As long as needed for subscribers; periodically pruned
Anonymous accounts (temporary)Let first-time visitors try the ServiceArt. 6(1)(b)Up to 7 days (if not claimed/converted)
Share links (token, expiration, shared dataset)Enable optional sharing/importArt. 6(1)(b) (feature requested by user)Until revoked/expired, or account deletion
Support messagesRespond to support requestsArt. 6(1)(f)As long as needed to resolve request
Billing linkage (Stripe customer/subscription IDs)Provide Pro and manage billing stateArt. 6(1)(b), Art. 6(1)(c)For the subscription term; longer where legally required
  • Account data (name, email, identifiers, email verification status)

    Purpose: Provide and manage your account

    GDPR basis: Art. 6(1)(b)

    Retention: Until account deletion

  • OAuth provider data (e.g. provider account ID; tokens if applicable)

    Purpose: Enable sign-in via provider

    GDPR basis: Art. 6(1)(b)

    Retention: Until account deletion

  • Session cookie(s) + server-side session record (token, expiry, IP address, user agent)

    Purpose: Authentication; account security; abuse prevention

    GDPR basis: Art. 6(1)(b), Art. 6(1)(f)

    Retention: Until session expires (typically within ~7 days) or is revoked

  • Network traffic data (e.g. IP address, request metadata) processed by Cloudflare

    Purpose: Content delivery, security (WAF), rate limiting, abuse prevention

    GDPR basis: Art. 6(1)(f)

    Retention: According to Cloudflare retention and our Cloudflare configuration

  • Subscriptions, folders, tags, rules, preferences

    Purpose: Provide core app functionality and sync

    GDPR basis: Art. 6(1)(b)

    Retention: Until account deletion

  • Cached feed item metadata/snippets

    Purpose: Efficient display of feeds you subscribed to

    GDPR basis: Art. 6(1)(b)

    Retention: As long as needed for subscribers; periodically pruned

  • Anonymous accounts (temporary)

    Purpose: Let first-time visitors try the Service

    GDPR basis: Art. 6(1)(b)

    Retention: Up to 7 days (if not claimed/converted)

  • Share links (token, expiration, shared dataset)

    Purpose: Enable optional sharing/import

    GDPR basis: Art. 6(1)(b) (feature requested by user)

    Retention: Until revoked/expired, or account deletion

  • Support messages

    Purpose: Respond to support requests

    GDPR basis: Art. 6(1)(f)

    Retention: As long as needed to resolve request

  • Billing linkage (Stripe customer/subscription IDs)

    Purpose: Provide Pro and manage billing state

    GDPR basis: Art. 6(1)(b), Art. 6(1)(c)

    Retention: For the subscription term; longer where legally required

Note: Payment card data is processed by Stripe. We do not store full card details.

4. Processors, hosting, and international transfers

We use the following sub-processors to run the Service. Their role is limited to providing infrastructure (hosting, database, email, payments, and authentication).

ProcessorPurposeLocation / notes
Neon.techPostgreSQL databaseFrankfurt (EU) (as configured)
CloudflareHosting/edge network, DNS, WAF/rate limiting; scheduled fetchingGlobal network (processing may occur outside the EEA)
ResendTransactional email (verification, password reset)As configured by provider
Google / GitHubOAuth sign-in (optional)Global providers (processing may occur outside the EEA)
StripePayments, subscriptions, invoicesGlobal provider (processing may occur outside the EEA)
  • Neon.tech

    Purpose: PostgreSQL database

    Location / notes: Frankfurt (EU) (as configured)

  • Cloudflare

    Purpose: Hosting/edge network, DNS, WAF/rate limiting; scheduled fetching

    Location / notes: Global network (processing may occur outside the EEA)

  • Resend

    Purpose: Transactional email (verification, password reset)

    Location / notes: As configured by provider

  • Google / GitHub

    Purpose: OAuth sign-in (optional)

    Location / notes: Global providers (processing may occur outside the EEA)

  • Stripe

    Purpose: Payments, subscriptions, invoices

    Location / notes: Global provider (processing may occur outside the EEA)

Where our processors process personal data outside the EEA, we rely on appropriate transfer mechanisms offered by those processors (for example, Standard Contractual Clauses) and their GDPR-related contractual commitments.

5. Cookies and similar technologies

We do not use advertising cookies, tracking cookies, or third-party analytics cookies, and we do not show a cookie consent banner, because everything we store on your device is strictly necessary to deliver the Service you asked for.

5.1 Cookies we set

  • Session cookie(s): keep you signed in, including as an anonymous visitor before you create an account. HttpOnly, and they expire with the session (typically within ~7 days).
  • Sign-in cookie(s): short-lived and HttpOnly, set only while you are completing an email sign-in link, and cleared when the sign-in finishes.
  • Language cookie: remembers the language you picked. Set only if you change the language.

5.2 Storage on your device

We also use Local Storage, IndexedDB and a service worker. This is not incidental: Leatly is local-first, so your subscriptions, folders, tags and feed items live on your device and are the app itself, together with your display preferences (theme, font, layout) and offline caching. Clearing your browser storage for this site removes them.

5.3 Stripe (checkout only)

Stripe.js loads only when you open the upgrade or checkout screen — not on ordinary visits. When it loads, Stripe sets its own cookies on our domain (for example __stripe_mid and __stripe_sid) and may perform fraud-prevention checks. We do not use these for analytics or advertising. See Stripe's privacy policy for how Stripe processes that data.

5.4 Images loaded from publishers

Article images and site icons are loaded directly from the publisher's own servers when they are displayed to you. Those requests go to the publisher, not to us, and the publisher may set its own cookies or log the request. We send no referrer information with them and add no tracking parameters, but we do not control what a publisher does. Your browser's third-party cookie settings and any content blocker you use apply to these requests.

6. Data deletion and retention

  • You can delete your account from the app. Account deletion removes your personal data from our primary systems.
  • Anonymous accounts are deleted after up to 7 days if not claimed/converted.
  • Authentication sessions expire automatically (typically within ~7 days).
  • Share links may expire automatically and can also be revoked.
  • Cached feed metadata is periodically pruned and may be retained as long as at least one user subscribes to the relevant feed.
  • Billing records are primarily handled by Stripe; we may retain minimal billing linkage data as needed for the subscription and for legal compliance.

We do not intentionally maintain separate long-term application access logs in our own systems beyond what is necessary to operate the Service. Network-layer logs and security telemetry may be processed by Cloudflare.

7. Children's privacy

Leatly is not intended for children under 16. We do not actively verify age and do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data to us, contact us at contact@leatly.com and we will take appropriate steps.

8. Your rights (GDPR)

If you are in the EU/EEA (and in certain other jurisdictions), you may have rights including:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection (for processing based on legitimate interests)

To exercise your rights, contact us at contact@leatly.com. We typically respond within 30 days. We may request additional information to verify your identity.

You also have the right to lodge a complaint with a supervisory authority. In Hungary, this is:

NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Website: https://naih.hu
Address: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf.: 9.

9. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we may provide notice via the Service or by email (for registered users).

10. Contact

contact@leatly.com
Pellet Kristóf EV
2600 Vác, Hungary