Legal

Privacy Policy

Last updated: April 3, 2026

1. Introduction

Welcome to AllLeaks ("we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our website and services (collectively, the "Service"). By accessing or using the Service, you agree to the terms of this Privacy Policy.

2. Information We Collect

We collect the following categories of information:

  • Account information: When you register, we collect your email address, name (optional), and a hashed version of your password.
  • Authentication data: If you sign in via Google OAuth, we receive your Google profile ID and email address.
  • Payment information: Payments are processed by Stripe. We store only a Stripe customer ID and subscription status — we never store full card numbers.
  • Usage data: We may collect IP addresses, browser type, pages visited, and session metadata for security and analytics purposes.
  • Cookies: We use HTTP-only cookies to maintain your authenticated session. We do not use tracking or advertising cookies.

3. How We Use Your Information

  • To create and manage your account and authenticate your sessions.
  • To process subscription payments and manage billing through Stripe.
  • To enforce our Terms of Service and prevent abuse.
  • To respond to DMCA takedown requests and legal obligations.
  • To send transactional emails (e.g., account confirmation, password reset).

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention.

5. Security

We implement industry-standard security measures, including encrypted passwords, HTTPS-only communication, and HTTP-only session cookies. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

6. Third-Party Services

We use the following third-party services:

  • Stripe — payment processing. Subject to Stripe's Privacy Policy.
  • Google OAuth — optional sign-in. Subject to Google's Privacy Policy.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal data.
  • Object to or restrict certain processing.
  • Request a portable copy of your data.

To exercise any of these rights, contact us at privacy@allleaks.app.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

9. Contact

Questions about this Privacy Policy? privacy@allleaks.app