Privacy Policy
Last updated: August 2026
Leatly is a news reader. As part of our activities, we collect and process personal data relating to our users. These different data processing operations are detailed in this Privacy Policy.
1. What data we process and why
1.1 Account and authentication data
If you create an account, we process the data needed to create and manage it, such as your name, email address, account identifiers, and email verification status.
If you sign in via Google or GitHub OAuth, we receive the data you choose to share via the provider (typically email address, display name, and profile image URL) and we store provider-related account identifiers. Where required by the authentication flow, we may also store OAuth tokens (such as access or refresh tokens) to complete sign-in and manage sessions.
Passwords (if you use email/password login) are stored hashed.
1.2 Anonymous use
If you use Leatly without registering, we may create a temporary anonymous account so you can try the Service. Anonymous accounts that are not converted to a registered account are deleted after up to 7 days.
1.3 Session and security data
We use secure, HTTP-only authentication cookie(s) to keep you logged in. These cookie(s) are strictly necessary for the Service to work.
For account security and abuse prevention, our authentication system stores server-side session data including a session token, expiration time, and session metadata such as IP address and browser user agent associated with the session.
1.4 Your subscriptions, preferences, and in-app data
We process the data you create in the app so we can provide the Service, sync across devices, and apply your configured preferences. This includes:
- Feed subscriptions (feed URLs, titles, ordering, and folder assignment)
- Folders and tags
- Rules/automation you configure
- Read/unread and closed/dismissed item state
- App settings (e.g. theme, font, UI preferences)
Some preferences and cached content are also stored locally on your device using browser storage (e.g. Local Storage / IndexedDB) and may be cached by a service worker for offline capability. This local data stays on your device unless you clear it via your browser/app settings.
1.5 RSS/Atom fetching and cached feed content
When you subscribe to a feed, our servers periodically fetch that feed and cache limited feed item data to display it efficiently. We cache only what the feed publishes (for example: title, URL, author (if provided), publication date, categories (if provided), thumbnail/image URL, and short summary/snippet).
We support caching mechanisms such as ETag and If-Modified-Since where the feed provides them.
1.6 Billing data (Pro plan)
If you subscribe to Pro, payments are processed by Stripe. We do not store your full payment card details. We process and store limited billing-related data needed to provide Pro, such as your Stripe customer/subscription identifiers, plan status, and billing period status.
Stripe processes billing and invoicing data under its own privacy policy.
1.7 Sharing links
Leatly may allow you to generate a share link to share selected parts of your setup (for example, subscriptions, folders, or tags). Anyone who has the share link may be able to view and/or import the shared data.
Share links are token-based and may expire. You control whether you create such a link and you can revoke it by disabling/deleting it (where the feature is available) or by contacting us.
1.8 Support communications
If you contact support, we will process the information you send us (such as your email address and message) to respond and resolve your request.
1.9 What we do not do
- No advertising profiles
- No third-party analytics (no Google Analytics, Mixpanel, etc.)
- No sale of personal data
- No link decoration or tracking parameters added to publisher URLs
- No marketing emails (we send only transactional emails such as login and billing-related messages)
1.10 Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of GDPR Article 22.
2. Legal bases (GDPR Article 6)
- Contract performance (Art. 6(1)(b)): to provide the Service (accounts, sessions, subscriptions, sync, preferences, and fetching/caching feeds you requested).
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, and maintain reliability (e.g. session security metadata such as IP address/user agent, and Cloudflare WAF/rate limiting).
- Legal obligation (Art. 6(1)(c)): where we must comply with applicable laws (for example, accounting/tax obligations that may apply to billing records).
3. Summary table (processing, purpose, legal basis, retention)
| Data | Purpose | GDPR basis | Retention |
|---|---|---|---|
| Account data (name, email, identifiers, email verification status) | Provide and manage your account | Art. 6(1)(b) | Until account deletion |
| OAuth provider data (e.g. provider account ID; tokens if applicable) | Enable sign-in via provider | Art. 6(1)(b) | Until account deletion |
| Session cookie(s) + server-side session record (token, expiry, IP address, user agent) | Authentication; account security; abuse prevention | Art. 6(1)(b), Art. 6(1)(f) | Until session expires (typically within ~7 days) or is revoked |
| Network traffic data (e.g. IP address, request metadata) processed by Cloudflare | Content delivery, security (WAF), rate limiting, abuse prevention | Art. 6(1)(f) | According to Cloudflare retention and our Cloudflare configuration |
| Subscriptions, folders, tags, rules, preferences | Provide core app functionality and sync | Art. 6(1)(b) | Until account deletion |
| Cached feed item metadata/snippets | Efficient display of feeds you subscribed to | Art. 6(1)(b) | As long as needed for subscribers; periodically pruned |
| Anonymous accounts (temporary) | Let first-time visitors try the Service | Art. 6(1)(b) | Up to 7 days (if not claimed/converted) |
| Share links (token, expiration, shared dataset) | Enable optional sharing/import | Art. 6(1)(b) (feature requested by user) | Until revoked/expired, or account deletion |
| Support messages | Respond to support requests | Art. 6(1)(f) | As long as needed to resolve request |
| Billing linkage (Stripe customer/subscription IDs) | Provide Pro and manage billing state | Art. 6(1)(b), Art. 6(1)(c) | For the subscription term; longer where legally required |
Account data (name, email, identifiers, email verification status)
Purpose: Provide and manage your account
GDPR basis: Art. 6(1)(b)
Retention: Until account deletion
OAuth provider data (e.g. provider account ID; tokens if applicable)
Purpose: Enable sign-in via provider
GDPR basis: Art. 6(1)(b)
Retention: Until account deletion
Session cookie(s) + server-side session record (token, expiry, IP address, user agent)
Purpose: Authentication; account security; abuse prevention
GDPR basis: Art. 6(1)(b), Art. 6(1)(f)
Retention: Until session expires (typically within ~7 days) or is revoked
Network traffic data (e.g. IP address, request metadata) processed by Cloudflare
Purpose: Content delivery, security (WAF), rate limiting, abuse prevention
GDPR basis: Art. 6(1)(f)
Retention: According to Cloudflare retention and our Cloudflare configuration
Subscriptions, folders, tags, rules, preferences
Purpose: Provide core app functionality and sync
GDPR basis: Art. 6(1)(b)
Retention: Until account deletion
Cached feed item metadata/snippets
Purpose: Efficient display of feeds you subscribed to
GDPR basis: Art. 6(1)(b)
Retention: As long as needed for subscribers; periodically pruned
Anonymous accounts (temporary)
Purpose: Let first-time visitors try the Service
GDPR basis: Art. 6(1)(b)
Retention: Up to 7 days (if not claimed/converted)
Share links (token, expiration, shared dataset)
Purpose: Enable optional sharing/import
GDPR basis: Art. 6(1)(b) (feature requested by user)
Retention: Until revoked/expired, or account deletion
Support messages
Purpose: Respond to support requests
GDPR basis: Art. 6(1)(f)
Retention: As long as needed to resolve request
Billing linkage (Stripe customer/subscription IDs)
Purpose: Provide Pro and manage billing state
GDPR basis: Art. 6(1)(b), Art. 6(1)(c)
Retention: For the subscription term; longer where legally required
Note: Payment card data is processed by Stripe. We do not store full card details.
4. Processors, hosting, and international transfers
We use the following sub-processors to run the Service. Their role is limited to providing infrastructure (hosting, database, email, payments, and authentication).
| Processor | Purpose | Location / notes |
|---|---|---|
| Neon.tech | PostgreSQL database | Frankfurt (EU) (as configured) |
| Cloudflare | Hosting/edge network, DNS, WAF/rate limiting; scheduled fetching | Global network (processing may occur outside the EEA) |
| Resend | Transactional email (verification, password reset) | As configured by provider |
| Google / GitHub | OAuth sign-in (optional) | Global providers (processing may occur outside the EEA) |
| Stripe | Payments, subscriptions, invoices | Global provider (processing may occur outside the EEA) |
Neon.tech
Purpose: PostgreSQL database
Location / notes: Frankfurt (EU) (as configured)
Cloudflare
Purpose: Hosting/edge network, DNS, WAF/rate limiting; scheduled fetching
Location / notes: Global network (processing may occur outside the EEA)
Resend
Purpose: Transactional email (verification, password reset)
Location / notes: As configured by provider
Google / GitHub
Purpose: OAuth sign-in (optional)
Location / notes: Global providers (processing may occur outside the EEA)
Stripe
Purpose: Payments, subscriptions, invoices
Location / notes: Global provider (processing may occur outside the EEA)
Where our processors process personal data outside the EEA, we rely on appropriate transfer mechanisms offered by those processors (for example, Standard Contractual Clauses) and their GDPR-related contractual commitments.
5. Cookies and similar technologies
We do not use advertising cookies, tracking cookies, or third-party analytics cookies, and we do not show a cookie consent banner, because everything we store on your device is strictly necessary to deliver the Service you asked for.
5.1 Cookies we set
- Session cookie(s): keep you signed in, including as an anonymous visitor before you create an account. HttpOnly, and they expire with the session (typically within ~7 days).
- Sign-in cookie(s): short-lived and HttpOnly, set only while you are completing an email sign-in link, and cleared when the sign-in finishes.
- Language cookie: remembers the language you picked. Set only if you change the language.
5.2 Storage on your device
We also use Local Storage, IndexedDB and a service worker. This is not incidental: Leatly is local-first, so your subscriptions, folders, tags and feed items live on your device and are the app itself, together with your display preferences (theme, font, layout) and offline caching. Clearing your browser storage for this site removes them.
5.3 Stripe (checkout only)
Stripe.js loads only when you open the upgrade or checkout screen — not on ordinary visits. When it loads, Stripe sets its own cookies on our domain (for example __stripe_mid and __stripe_sid) and may perform fraud-prevention checks. We do not use these for analytics or advertising. See Stripe's privacy policy for how Stripe processes that data.
5.4 Images loaded from publishers
Article images and site icons are loaded directly from the publisher's own servers when they are displayed to you. Those requests go to the publisher, not to us, and the publisher may set its own cookies or log the request. We send no referrer information with them and add no tracking parameters, but we do not control what a publisher does. Your browser's third-party cookie settings and any content blocker you use apply to these requests.
6. Data deletion and retention
- You can delete your account from the app. Account deletion removes your personal data from our primary systems.
- Anonymous accounts are deleted after up to 7 days if not claimed/converted.
- Authentication sessions expire automatically (typically within ~7 days).
- Share links may expire automatically and can also be revoked.
- Cached feed metadata is periodically pruned and may be retained as long as at least one user subscribes to the relevant feed.
- Billing records are primarily handled by Stripe; we may retain minimal billing linkage data as needed for the subscription and for legal compliance.
We do not intentionally maintain separate long-term application access logs in our own systems beyond what is necessary to operate the Service. Network-layer logs and security telemetry may be processed by Cloudflare.
7. Children's privacy
Leatly is not intended for children under 16. We do not actively verify age and do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data to us, contact us at contact@leatly.com and we will take appropriate steps.
8. Your rights (GDPR)
If you are in the EU/EEA (and in certain other jurisdictions), you may have rights including:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection (for processing based on legitimate interests)
To exercise your rights, contact us at contact@leatly.com. We typically respond within 30 days. We may request additional information to verify your identity.
You also have the right to lodge a complaint with a supervisory authority. In Hungary, this is:
NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Website: https://naih.hu
Address: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf.: 9.
9. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we may provide notice via the Service or by email (for registered users).
10. Contact
contact@leatly.com
Pellet Kristóf EV
2600 Vác, Hungary