Privacy Policy
1. Who is responsible
Controller within the meaning of the EU General Data Protection Regulation (GDPR): Benneth Müller, Benneth Müller Digital Solutions & Education, Borgfelder Str. 16, 20537 Hamburg, Germany. Contact for all privacy questions: ben@leadcalm.app.
2. Short version
- You use Leadcalm with an account (email and password), created when you set up the app.
- Your practice data (conversations, reviews, progress) is stored on your device and saved to your account so it is safe and on all your devices. You can turn this off in Settings and delete the account copy.
- The chat with prepared replies works without AI. The AI chat (the chat with AI replies), voice conversations and AI feedback need your separate consent; the text AI is Google Gemini, reached through our server. You can withdraw each consent in the app.
- No advertising, no tracking across apps or websites, no analytics or crash-reporting SDK, no sale of your data.
- You can export or delete your data and delete your account in the app at any time. See Delete your account.
3. What we process, why, and on which legal basis
3.1 Data on your device
Your practice sessions, conversation transcripts (turn text and the time of each turn within the conversation), reports, reflections, custom situations, talk cards, communication check-ins, your confidence ratings before and after a rehearsal (1–5), your progress in the story mode (chapter and position, choices, team “weather” levels, collected notes and start/end timestamps) and settings (including your work role and area and whether reply suggestions are shown in the AI chat) are stored on your device in its secure storage (iOS Keychain / Android Keystore) and, while “Save to your account” is on, also saved to your account (3.3). Content goes to AI providers only when you use an AI feature (3.4, 3.5). You can export it (Settings → Data & privacy → Export JSON) or delete it (Settings → Data & privacy → Delete local data).
3.2 Your account
When you create an account we process your email address, your password (stored by our hosting provider only in hashed form) and an internal user ID. Sign-in is by email and password only; there is no social login. An account is required to use Leadcalm, because the AI features, their daily and monthly allowances and purchases are tied to it. When you create the account, we also store which version of the Terms of Use and this Privacy Policy you agreed to, and when. Purpose: creating and securing your account, confirming your email address and signing you in. Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
3.3 Saving to your account
While “Save to your account” is on (the default once you are signed in), the app saves a copy of your app data with your account: the content listed in 3.1, including conversation transcripts, reviews, reflections, custom situations, talk cards, check-ins, learning progress, story progress, settings and an optional display name of up to 60 characters. The copy is updated shortly after each change, so your data is safe and available on your other devices. Your progress figures (points, levels, certificates) are calculated from this data. Purpose: keeping your practice data safe and available across your devices as part of the service. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). You can turn saving off at any time (Settings → Account & subscription → Account & cloud → “Save to your account”); the app then keeps everything on your device only and offers to delete the copy. You can also delete the copy separately (“Delete the saved copy”). The copy is kept until you delete it, turn saving off and delete it, or delete your account. Conversations and reflections may mention other people (for example colleagues): please do not use real names or details that identify them.
3.4 Written AI features and AI chat (Google Gemini)
When you use an AI feature (for example the written AI chat with its reply suggestions, a scenario, feedback on a reflection, live hints or a report), the content needed for that task is sent through our server to Google's Gemini API (model Gemini 2.5 Flash), which generates the answer. In the AI chat, each of your turns sends the situation, the conversation so far and whether suggestions are on. For a reflection, only the entry you choose is used. We do not send your user ID or email address to Google. Our server does not store the content of these requests, and it does not use Gemini features that keep content stored at Google, such as file uploads, context caching or grounding with Google Search. Under Google's Gemini API terms, Google keeps prompts and responses for 55 days to detect and prevent misuse and for legal obligations; content flagged by its safety systems may be reviewed by authorised Google staff. The same terms say that for paid use of the Gemini API, and for all use by customers in the European Economic Area, Google does not use prompts and responses to improve its products and processes them under its data processing terms as a processor; for other, unpaid use, Google may use them to improve its products, including through human review. Google may process this data in countries outside the EU. For voice conversations, our server sends the conversation text (not audio) to the Gemini API for live hints and reports only if you have allowed “AI hints and reports for conversations” in Settings. Independently of that setting, ElevenLabs uses Google Gemini to generate the conversation partner's replies during every voice conversation (see 3.5). Legal basis: Art. 6(1)(b) GDPR; for conversation analysis, Art. 6(1)(a) GDPR (consent).
3.5 Voice conversations (ElevenLabs)
The microphone is used only when you start a voice conversation (or dictation) and after you have given the separate live-audio consent. For “Talk”, our server checks your allowance and issues a short-lived conversation token; your app then sends your microphone audio and the details of the chosen situation directly to ElevenLabs, which voices the conversation partner and creates the transcript. To generate the partner's replies, ElevenLabs passes the situation details and the running transcript (not the audio) to Google Gemini, which it uses as its sub-processor. The situation details are the counterpart's name and role, the situation, the goal, the opening line and your current practice focus; for a situation you created yourself, these are the texts you entered. Your user ID is not sent to ElevenLabs. Our server only starts a conversation if the voice agent is configured not to record the voice and to delete audio and transcripts with a retention of 0 days. A conversation lasts at most 10 minutes. The transcript comes back to your device and is stored there (and in your account while “Save to your account” is on). No voice cloning is used. Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR.
3.6 Dictation
Dictation uses your device's speech recognition; depending on your system and language, Apple or Google may process the audio in their cloud under their own terms. Dictated text stays an editable draft until you tap Send.
3.7 Purchases (Apple, Google, RevenueCat)
Subscriptions are sold and paid through the App Store or Google Play. We never see your payment details. We use RevenueCat to manage subscriptions; it receives your purchase information and your Leadcalm user ID (no email address). RevenueCat informs our server about the status of your subscription, and we store it with your account (entitlement, active, expiry date, store environment) so that the server can grant the Pro allowances. Legal basis: Art. 6(1)(b) GDPR.
3.8 Usage counters
To enforce the free and Pro allowances, our server counts per account how many AI requests, voice conversations, live hints and reports you use per day, per minute and per month. These counters contain no content. They are not used for analytics, advertising or tracking. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (our legitimate interest in preventing misuse and controlling costs).
3.9 Reporting AI content, emails and support
Every piece of AI output in the app can be reported inside the app. When you send a report, we store it in our database with your account: your user ID, the time, where in the app the text appeared (for example chat, voice conversation or review), the reason you chose, your optional note (up to 1,000 characters), the reported AI text (up to 4,000 characters), the situation ID and the app version. The report does not leave the app and is not sent to AI providers. Only we can read reports; your account can send them but not read them back. We use them to review the AI output and to improve our safeguards. When you delete your account, your reports are deleted with it. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in safe AI content, and the app store rules that require in-app reporting). If you are not signed in or offline, the app offers the text to copy instead, so you can send it to us by email yourself.
If you write to us, we use your message and email address to answer you. Legal basis: Art. 6(1)(b) or (f) GDPR.
3.10 Technical data
Some technical data is processed automatically when the app talks to these services: when you sign in, use a server function or when the app loads new practice situations (anonymously, without your account), our hosting provider Supabase records your IP address and the app's user agent in its authentication and request logs, kept for a limited time for security and troubleshooting. When a voice conversation starts, the conversation SDK (LiveKit, used by ElevenLabs) sends your device model and operating system together with the connection to ElevenLabs. The RevenueCat SDK sends technical request data such as your IP address, operating system and app version, language and store country to RevenueCat. We do not use this data for advertising or tracking. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (our legitimate interest in running the service securely).
4. Service providers
| Provider | Purpose | Data |
|---|---|---|
| Supabase (hosting, authentication, database, server functions) | Account, saving your data to your account, server logic, loading new practice situations | Email, password hash, user ID, terms acceptance, your saved app data (3.3), subscription status, usage counters, reports of AI content you send (3.9); IP address and user agent in logs. Our project is hosted in the EU (Frankfurt, Germany). |
| Google (Gemini API; for paid use from the EEA: Google Cloud EMEA Limited, Ireland; otherwise Google LLC, USA) | Written AI chat and suggestions, AI features, live hints, reports | The content of the AI request, without user ID or email |
| ElevenLabs (with Google Gemini as its sub-processor for the partner's replies) | Voice conversations | Microphone audio and situation details (counterpart name and role, situation, goal, opening line, practice focus; for your own situations, what you entered) during a voice conversation; the transcript (not audio) to generate replies; device model and operating system |
| RevenueCat | Subscription management | User ID, purchase history, technical request data (IP address, operating system and app version, language, store country) |
| Apple, Google | App distribution, payments, device dictation | Under their own privacy policies |
We use these providers as processors on our behalf. Every service provider we share data with is bound by contract to protect it at least as well as this policy and applicable law require. Some of them are based in the USA or may process data outside the EU. Where this happens, the transfer relies on the safeguards the provider offers, such as the EU standard contractual clauses or certification under the EU-U.S. Data Privacy Framework.
5. How long we keep data
- Data on your device: until you delete it in the app or delete the app.
- Account, the saved copy of your app data, subscription status, usage counters and your reports of AI content: until you delete your account (the copy also earlier, if you delete it in the app). Deleting the account removes them from our database.
- A log of subscription events from RevenueCat keeps only event IDs and results, without your user ID.
- Content sent to Google (Gemini API) and ElevenLabs is not stored by our server. Google keeps Gemini API prompts and responses for 55 days for abuse monitoring (see 3.4). Otherwise, retention on the providers' side follows their terms and our settings with them.
- Deleting your Leadcalm account does not delete the customer record at RevenueCat or the purchase records at Apple or Google, and it does not cancel your subscription.
6. What we do not do
- No advertising and no tracking; no advertising identifier is used.
- No analytics, keystroke logging or crash-reporting SDK in the app.
- Drafts are not synced automatically.
Please do not enter confidential information about other people (for example colleagues' health or personal details) that you are not entitled to share. Use descriptions instead of real names.
7. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). You can withdraw a consent at any time with effect for the future (Art. 7(3)); in the app, withdrawing stops pending and new AI or voice requests, but cannot retract data that was already processed. Send requests to ben@leadcalm.app. You also have the right to lodge a complaint with a data protection supervisory authority, for example the Hamburg Commissioner for Data Protection and Freedom of Information.
8. Children and minors
Leadcalm is for people aged 18 and over and is not directed at anyone under 18 (see the Terms of Use). We do not knowingly process personal data of people under 18. If you believe someone under 18 has created an account, write to ben@leadcalm.app and we will delete the account and its data.
9. Changes
We update this policy when the app or the law changes. The date at the top shows the current version.