Leap
Legal

Privacy Policy

How Leap collects, uses, discloses and protects personal data across the platform, your connected social accounts and the Wizards marketplace.

Effective 17 August 2026Last updated 17 August 2026Version 1.0

1. Who we are

Leap (“Leap”, “we”, “us”, “our”) is an AI-powered social media management platform that lets businesses, agencies and individuals plan, create, approve, publish and analyse content across social networks, engage with their audiences, and, through the Wizards marketplace, find and work with social media service providers.

This Privacy Policy explains how we collect, use, disclose and protect personal data when you use our website, applications and services (together, the “Service”).

Data controller: Tide Venture Studio Ltd, a company registered in England and Wales, registered office in London. “Leap” is a trading name of Tide Venture Studio Ltd. Email: privacy@leap-social.com.

Privacy contact: our privacy team, at privacy@leap-social.com.

2. Scope and our role (controller vs. processor)

Because Leap is a multi-tenant platform used by businesses and agencies, our role under data protection law depends on the data.

We act as a controller for personal data where we determine the purposes and means of processing, principally the account data of people who register for and use Leap (account owners, team members and Wizards participants), billing data, marketing and communications data, and Service security and usage data. This Privacy Policy governs that processing.

We act as a processor for the personal data contained in the content our customers create and manage, and in the connected social accounts they operate, including data about their followers, audiences, commenters and, for agencies, their clients' end users. For that data our customer (and, where an agency manages a client, that client) is the controller, and our processing is governed by our Data Processing Agreement rather than this Policy. Customers are responsible for having a lawful basis and appropriate notices for the data they process through Leap.

If you are an end user, audience member or client of a Leap customer and have questions about how your data is used, please contact that business directly; we will support them in responding to your request.

3. The personal data we collect

We collect the following categories of personal data. Not all applies to every user.

3.1 Data you provide

  • Account and identity data: name, email address, password (stored only as a secure hash) or, where you sign in via a third party, the identifier and profile fields that provider returns. Leap supports single sign-on via Google, Microsoft, Apple, Facebook, LinkedIn and X; when you use SSO we receive your subject identifier and basic profile (and, where available and permitted, email) from that provider.
  • Organization and workspace data: organization or agency name, workspaces, team members you invite, roles and (for agencies) the client accounts you set up.
  • Content data: posts, campaigns, media assets, captions, comments, brand and house-rules and brand-voice settings, documents, and other content you create, upload, schedule or manage in Leap.
  • Wizards marketplace data: if you participate in Wizards: your Expert or Client profile, listings, portfolio and work examples, articles and videos you publish, requests and offers, bookings, and messages exchanged with the other party.
  • Communications and support data: messages you send us, support tickets, survey responses and feedback.

3.2 Data from connected social accounts

When you connect a social account you authorize Leap to access it via that platform's API using OAuth. Depending on the platform and the permissions you grant, we process:

  • Connection and authorization data: the connected account's identifier, name or username, avatar, and the access and refresh tokens issued by the platform (stored encrypted; see section 13). Connected platforms are Facebook (Pages), Instagram, LinkedIn (profiles and company pages), X, TikTok, YouTube, Pinterest and Telegram.
  • Published content and its metadata: the posts you publish or schedule through Leap.
  • Analytics data: engagement metrics we retrieve for your connected accounts and posts (followers, reach and impressions, likes, comments, shares, clicks, video views).
  • Engagement data: comments, mentions and, where you enable it, messages on your connected accounts, which the Replies feature displays and, if you turn on autopilot, uses AI to help draft or send responses in your brand voice.

This data is obtained through the social platforms' APIs and is subject to those platforms' own terms and privacy policies (see section 7).

3.3 Data collected automatically

  • Usage and device data: pages and features used, actions taken, timestamps, referring URLs, diagnostic events.
  • Technical and log data: IP address, browser and device type, operating system, and application logs, used for security, debugging and abuse prevention.
  • Cookies and similar technologies: see section 6.

3.4 Billing data

Payments are processed by Stripe. We do not store full payment card numbers; Stripe processes card data under its own terms. We store your subscription status, plan, quantities (seats and client accounts), Stripe customer and subscription identifiers, billing contact, country and VAT or tax identifiers, and, for Wizards, booking and payout records.

We do not intentionally collect special category data (such as health, biometrics or political opinions). Please do not upload such data unless you have a lawful basis; if your content includes it, you are the controller for it (see section 2).

4. How we use personal data and our legal bases

Where UK GDPR or EU GDPR applies, we rely on the legal bases indicated below (Art. 6(1)).

#PurposeData usedLegal basis
1Create and administer your account; authenticate you (including SSO)Account and identity, organizationContract (Art. 6(1)(b))
2Provide the core Service, publishing, scheduling, campaigns, assets, analytics, connected accountsContent, connection, analyticsContract
3Operate the Replies inbox and, where enabled, AI autopilot responsesEngagement data, brand-voice settingsContract (a feature you enable); see section 5
4Operate the Wizards marketplaceMarketplace, communications, billingContract
5Process payments, invoicing and taxBillingContract; legal obligation (Art. 6(1)(c)) for tax and accounting records
6Secure the Service, prevent fraud and abuse, maintain audit logs, ensure tenant isolationUsage, technical and log, accountLegitimate interests (Art. 6(1)(f))
7Screen users against applicable sanctions listsAccount and identity, countryLegal obligation; legitimate interests
8Maintain, debug and improve the Service; develop new featuresUsage, technical and log, aggregated or pseudonymized dataLegitimate interests
9Communicate with you about the Service (service messages, security notices)Account, communicationsContract; legitimate interests
10Send marketing communicationsAccount, usageConsent where required; otherwise legitimate interests, with an opt-out
11Comply with legal obligations and respond to lawful requestsAny relevantLegal obligation
12Set cookies and similar technologiesSee section 6Consent for non-essential; legitimate interests or contract for strictly necessary

Where we rely on legitimate interests we have balanced those interests against your rights, and you may object at any time (see section 10). Where we rely on consent you may withdraw it at any time without affecting prior processing.

5. AI features and where AI processing happens

At a glance. Leap is an AI-powered platform and AI processing is a core part of how the Service works: it is not an optional add-on. Our AI provider is Anthropic (Claude). Content sent to an AI feature is processed in the United States under Standard Contractual Clauses and the UK International Data Transfer Addendum. Anthropic does not use it to train its models. Everything else Leap holds, your account, content, assets, analytics and backups, is stored in the European Union (Frankfurt). Features that send messages automatically without your review are off by default and must be switched on deliberately.

5.1 What the AI features do

Leap uses AI to help you work. The Replies feature can analyse incoming comments and messages and draft or send responses in your configured brand voice, and other features assist with content creation and analysis.

5.2 What is sent, and what is not

We send to our AI provider only the content needed for the specific feature you are using at the moment you use it: for example the individual comment or message being replied to, together with your brand-voice settings. We do not send your whole content library, your audience lists, your analytics datasets, your billing data, or content from features you are not using.

5.3 Our AI provider

Our AI provider is Anthropic, PBC, which provides the Claude models. Under our commercial agreement with Anthropic:

  • Anthropic does not use inputs or outputs from our use of its API to train its models. This is a contractual commitment, not a setting.
  • Anthropic acts as our sub-processor under a data processing agreement incorporating Article 28 terms, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Anthropic retains API inputs and outputs for no longer than 30 days, other than where longer retention is required for its own policy enforcement obligations.

5.4 Where AI processing happens

Anthropic processes this content in the United States. This is a transfer of personal data outside the UK and EEA, and it is made under the safeguards described in section 8.

We are transparent about this because the rest of the Leap platform is EU-hosted, and we would rather you know exactly where the boundary sits than infer it. We keep the AI provider's data location under review.

5.5 AI processing is core to the Service

Leap is an AI-powered platform. AI processing is integral to the Service and is not optional: we do not offer a version of Leap without it. Where UK or EU GDPR applies, our legal basis for this processing is performance of the contract (Art. 6(1)(b)): the AI features are part of the Service you have signed up for, not a separate purpose we have added on top.

What you do control. Features that send messages automatically from your connected accounts without your prior review: including Replies autopilot auto-send, are off by default, must be switched on deliberately by an administrator, and can be switched off at any time. Agencies can make that choice per client account.

If you are a Leap customer, you are the controller for your audience data and you are responsible for informing the people whose data you process, including people who comment on or message your accounts, that their messages may be processed using AI as described here, and for having a lawful basis for it. Our DPA sets out how we support you in doing that.

5.6 Automated decision-making

These features assist our customers and are configured and supervised by them. They do not make decisions producing legal or similarly significant effects about individuals within the meaning of Article 22 GDPR. Where a customer enables autopilot responses, that customer remains responsible for the messages sent from its accounts, and for complying with the relevant platform's automation rules and applicable law.

6. Cookies and similar technologies

We use strictly necessary cookies to keep you signed in, secure the Service and remember which organization you are working in. These are always active and cannot be switched off without breaking the Service.

We also use Google Analytics to understand how Leap is used so we can improve it. These analytics cookies are only set if you accept them, and they are not set until you do. You can accept or reject them in our cookie banner and change your choice at any time through the cookie settings link. Rejecting them does not affect your use of the Service.

Google Analytics data is processed by Google LLC in the United States under Standard Contractual Clauses. It relates to your use of our website and app: it is not applied to your Customer Content, to your audiences, or to anything published through Leap.

Full detail, including every cookie we set, is in our Cookie Policy.

7. How we share personal data

We do not sell your personal data. We share it only as described here.

Service providers and sub-processors who process data on our behalf under contract:

Sub-processorPurposeLocationTransfer safeguard
RenderApplication hosting, managed PostgreSQL and RedisEU, Frankfurtn/a (EU)
Object storage providerMedia and asset storageEUn/a (EU)
Anthropic, PBCAI features (Claude), content assistance and reply draftingUnited StatesSCCs + UK Addendum. Does not train on our data
StripePayments, tax, invoicing, marketplace payoutsEU / USSCCs + UK Addendum where applicable
BrevoTransactional and notification emailEU, Francen/a (EU)
SentryError monitoring and diagnostics, error data may incidentally contain personal data in stack tracesUnited StatesSCCs + UK Addendum
Google LLCGoogle Analytics, website and app usage analytics. Not applied to Customer ContentUnited StatesSCCs via Google's data processing terms

Identity providers. Where you sign in using Google, Microsoft, Apple, Facebook, LinkedIn or X, that provider processes your authentication data as an independent controller under its own terms, not as our sub-processor.

A current list of sub-processors is maintained and customers can subscribe to be notified of changes; we give the notice period set out in the DPA before adding a new sub-processor.

Social media platforms: when you connect an account and publish or retrieve data, we exchange data with the relevant platform (Meta/Facebook and Instagram, LinkedIn, X, TikTok, YouTube, Pinterest, Telegram) via their APIs. These platforms are largely US-based and operate under their own terms and privacy policies. Data you choose to publish through Leap is transmitted to the platform you selected, at your instruction, under your own relationship with that platform.

Wizards marketplace counterparties: where you request or accept an offer, or collaborate, we share the information necessary for the transaction (profile, brief, messages) with the other party. Payments are handled by Stripe.

Within your organization: content and account data are visible to other members of your organization or workspace according to their roles; agency staff may access the client accounts they are assigned to.

Legal, safety and compliance: where necessary to comply with law, enforce our terms, screen against sanctions lists, or protect the rights, safety and security of Leap, our users or the public.

Business transfers: in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

8. Where your data is stored and international transfers

Storage, European Union. The Leap platform is hosted in the European Union (Frankfurt, Germany). Our application servers, primary PostgreSQL database, cache, object storage and backups are located there. Personal data you and your audiences provide is stored in the EU.

Transfers we make. There are two categories of transfer outside the UK and EEA, and we set them out separately because they are different in kind.

(a) AI processing, a transfer we make. When you use an AI feature, the content needed for that feature is transmitted to Anthropic in the United States (see section 5). This is a transfer that Leap initiates and for which Leap is accountable. It is made under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we have assessed the safeguards as appropriate for the content involved.

(b) Publishing to social platforms, a transfer you instruct. When you publish content or retrieve analytics, data is exchanged with the social platform you have connected. Those platforms are largely US-based. This transfer happens at your instruction, to a platform you have chosen and with which you have your own relationship and terms. Leap transmits the data you have told it to transmit, to the destination you selected.

Other sub-processors. Where any other sub-processor processes personal data outside the EEA or UK, we put in place a lawful transfer mechanism, typically the Standard Contractual Clauses and the UK Addendum, with supplementary measures where appropriate. The table in section 7 records this per vendor.

You can request more information about these safeguards, including a copy of the relevant clauses, using the contact details in section 1.

9. Data retention

We keep personal data only as long as necessary for the purposes described, then delete or anonymize it.

  • Account and organization data: for the life of your account, then deleted or anonymized within 90 days of account closure, subject to legal retention needs.
  • Content, connection and analytics data: for as long as you keep the relevant workspace or connection, then deleted on disconnection or account closure. Some analytics are available from platforms only for limited windows and are stored accordingly.
  • Data sent to our AI provider: retained by Anthropic for no longer than 30 days (see 5.3). Leap does not retain a separate copy beyond the content already stored in your workspace.
  • Billing and tax records: retained for the period required by applicable tax and accounting law (commonly 6 years in the UK).
  • Logs and security data: typically up to 12 months, longer where needed for a security investigation.
  • Marketing data: until you opt out or withdraw consent.

Platform-required deletion and refresh. To comply with the social platforms' terms, we honour their deletion and refresh obligations, reflecting deletions and edits, and refreshing or purging cached platform data within the timeframes those platforms require. When you disconnect an account or delete content, we remove the associated stored data and revoke tokens with the platform on a best-effort basis.

10. Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data;
  • restrict or object to processing, including processing based on legitimate interests, and direct marketing at any time;
  • data portability: receive certain data in a structured, machine-readable format;
  • withdraw consent at any time where processing is based on consent;
  • not be subject to solely automated decisions with legal or similarly significant effects (see 5.6).

To exercise any right, contact privacy@leap-social.com. We will respond within the time required by law, generally one month. We may need to verify your identity. If you are an end user or audience member of a Leap customer, we will generally direct your request to that customer as controller (see section 2).

You also have the right to complain to a supervisory authority. As we are established in the United Kingdom, our supervisory authority is the Information Commissioner's Office (ICO), www.ico.org.uk, helpline 0303 123 1113. If you are in the EEA you may also complain to the authority in your country of residence.

11. Your California privacy rights (CCPA/CPRA)

If you are a California resident you have the right to know the categories and specific pieces of personal information we collect, the sources, purposes and third parties with whom we share it; to request deletion and correction; and to opt out of the “sale” or “sharing” of personal information and to limit use of sensitive personal information. We do not sell your personal information and do not “share” it for cross-context behavioural advertising. We do not discriminate against you for exercising your rights. To exercise these rights contact privacy@leap-social.com; you may use an authorized agent. The categories we collect and disclose correspond to sections 3 and 7.

12. Children

The Service is not directed to children and is for users aged 18 and over. We require confirmation of age at sign-up and do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@leap-social.com and we will delete it. Connected social platforms impose their own minimum-age requirements in addition to ours.

13. Security

We implement technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and encryption at rest, with social account access and refresh tokens encrypted using AES-256-GCM; per-tenant isolation enforced at the database level (PostgreSQL Row-Level Security, with the application connecting as a non-privileged role); role-based access controls; append-only audit logging of administrative actions; least-privilege staff access; and secure development and monitoring practices.

No system is perfectly secure and we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals as required by law.

14. Changes to this Policy

We may update this Policy. We will post the updated version with a new “Last updated” date and, for material changes, give additional notice by email or in-product. If we change where AI processing takes place, or add an AI provider, we will update sections 5 and 7 and notify customers before the change takes effect.

15. Contact us

Questions or requests about this Policy or your personal data:

privacy@leap-social.com · Tide Venture Studio Ltd · Registered in England and Wales · London.

Cookies

We use essential cookies to run Leap, and optional ones to understand how the site is used. You choose. Cookie preferences