Leadesi

Privacy Policy

Last updated: 19 August 2026

What we collect

When you sign up for Leadesi, we collect your name and email address. When you use the product, we store the data you enter - leads, client records, notes, and bookings - on your behalf. This data belongs to you.

If you connect Gmail, we also store a copy of the email threads you link to a lead. That copy includes the full contents of those messages, not just their subject lines, so the conversation can be shown alongside the lead it belongs to.

Leadesi does not write replies to your customers for you - you reply in Gmail, and we never compose or send email on your behalf to the people in your pipeline.

When you book a job, we create the event in your own Google Calendar and keep only its identifier, so we can update or cancel that event later. We do not store your calendar or its contents.

Logs we keep automatically

Alongside the records you create, Leadesi keeps a few logs on its own.

Lead activity. Every lead carries a timeline of what has happened to it - stage changes, notes, calls you log, and emails sent or received. It is part of the lead record and is deleted along with it.

Text message notifications. When Leadesi sends a booking confirmation, reminder, or cancellation by SMS, we record the number it went to, what kind of message it was, whether it sent, and when. We do not keep the text of the message itself.

Help chat. If you ask the in-app help assistant a question, we store your question and the answer it gave, so we can see where the product confuses people. These are deleted automatically after 90 days.

We do not run session recording, and we do not use a third-party error-tracking service. Our hosting and database providers keep ordinary server access logs, as any web host does.

How we use it

We use your data solely to operate and improve Leadesi. We do not sell your data to third parties. We do not use your lead or client data to train AI models without your explicit consent.

How we protect your data

In transit. Everything travels over TLS. Leadesi is not served over plain HTTP.

At rest. The database is encrypted at rest by our hosting provider.

Account isolation. Every record in Leadesi carries the account it belongs to, and Postgres row-level security enforces that at the database level - not only in application code. A query made under your session can only return your own account's rows.

Connected accounts. When you connect Gmail, Google Calendar, or Xero, the access tokens are encrypted with AES-256-GCM before being stored, using a key held outside the database. A copy of the database on its own does not give anyone access to your mailbox or accounting data.

Sign-in. You sign in with Google, or with an email address and password. We never see or store your password - it is hashed by our authentication provider.

Payment details. Card numbers never reach Leadesi's servers. Payment and billing happen on Stripe's hosted pages; we store only a customer reference and your subscription status.

Access inside your account. People you invite hold a role - owner, admin, or member - and settings that change how the account works are restricted to owners and admins at both the application and the database layer.

Our access. Leadesi staff do not browse customer data. Access to production is limited to the people who maintain the service, and is used only to fix a fault or to answer a support request you have raised.

Sensitive data

Leadesi is a CRM. It is designed to hold names, contact details, notes about a job, bookings, and email correspondence. It is not designed to hold sensitive information - health or medical details, government identifiers such as a driver's licence, passport, or tax file number, card or bank account numbers, or information about a person's race, religion, sexuality, or political views.

Please do not enter that kind of information into lead notes, custom fields, or attachments. If your business genuinely needs to record something in one of these categories, contact us before you do - we would rather tell you honestly whether Leadesi is the right place for it.

Where sensitive information does reach us anyway - inside a forwarded email thread, for example - it is protected by the same measures described above: encrypted in transit and at rest, isolated to your account by row-level security, and deleted when you delete the record or close your account.

AI features and your data

Three features send text to a third-party AI provider: pulling the details of a new lead out of an email you forward or link, writing outreach emails to businesses you are prospecting, and answering your questions in the in-app help assistant. Only the content needed for that request is sent, and we do not use your data to train AI models. Anything an AI feature produces is shown to you first - nothing is sent, saved, or acted on until you choose it. An outreach email you save as a template is stored like any other template you write.

Third-party services

Leadesi is built on Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (transactional email), and Google (Gmail and Calendar, where you connect them). Our marketing site additionally uses Google Analytics, as described under Cookies and analytics below. AI features use third-party models. These services have their own privacy policies and receive only the minimum data necessary to provide their function. We do not send your data to any other service. Your data is stored in Australia - both our database and our application run in Sydney.

Data retention

Your data is retained for as long as your account is active. You can request deletion at any time by emailing us. We will delete your data within 30 days of your request. Deletion also removes your data from our backups on their normal rotation, within 30 days of the last backup that contained it.

Cookies and analytics

Keeping you signed in. Leadesi sets functional cookies that are necessary to keep you signed in and to remember your preferences. The product does not work without them.

Understanding how our site is used. Our marketing site uses Google Analytics, loaded through Google Tag Manager, to understand how people find and move around it - which pages are viewed, roughly which part of the world you are in, and which site referred you. We look at this in aggregate to decide what to improve. These scripts load only if you accept them in the cookie banner shown on your first visit - until you do, no analytics runs and no analytics cookies are set.

Analytics runs on our marketing site only. The Leadesi app itself - where your leads, clients, and email live - carries no analytics trackers at all. We do not run advertising or retargeting pixels on either site, and your customer data is never sent to Google.

Your choices. The cookie banner asks before any analytics loads. Choose "Change settings" in the banner to turn analytics off and save that choice. You can change your mind at any time through the "Cookie settings" link in the footer - your choice is remembered in a small functional cookie for six months, after which we ask again. Beyond that, you can block or delete cookies in your browser settings, and Google publishes a Google Analytics opt-out add-on for the major browsers. Declining or blocking affects nothing about how the Leadesi app works for you.

Browser extension

The Leadesi for Gmail extension reads a thread identifier from the Gmail page you have open - not the content of your emails - so it can look up and display the Leadesi lead linked to that thread, or show a stage badge next to threads in your inbox list. If you use its "create lead from this thread" action, that thread's content is processed by the same AI lead-extraction Leadesi already uses for email forwarding, to draft a lead on your behalf. The extension signs in with your own Leadesi account, the same way the web dashboard does, and stores that session only in your browser's local storage.

If something goes wrong

If we become aware of a breach affecting your data, we will contact you directly with what happened, what information was involved, and what we are doing about it. We will do that within 72 hours of confirming the breach, and we will notify the relevant regulator where the law requires it.

Contact

Questions about privacy? Email us or use the contact form.