Privacy policy.
What we collect, what we do with it, who else sees it, and how long we keep it — including the parts that are not finished yet.
Effective 23 July 2026. We post changes here and update this date.
Leodesk is a help-desk product sold to businesses. That means there are two different groups of people whose data we touch, and the rules are different for each:
- Our customers — the companies who sign up, and the agents who log in. We decide how their account data is handled, so for them we are the data controller.
- Their customers — the people who email a support address or open a chat widget. That content belongs to our customer. We only process it on their instructions, so for those people we are a data processor, and you should read the privacy policy of the company you contacted, not this one.
This policy covers both, and says which is which as it goes.
1. What we collect
From agents (our customers)
Name, email address, job title, the role assigned to you, which workspaces you belong to, your notification preferences, and presence information — that you are online and when you were last seen. Your password is stored only as a bcrypt hash; we cannot read it. We also record failed login attempts in order to lock an account temporarily after repeated failures.
From end-customers (our customers' customers)
When someone emails a support address or writes in a chat widget, we store what they sent: the message body in both plain text and HTML, the subject, the sender's name and address, any Cc and Bcc addresses, attachments, and the email headers needed to thread replies correctly. We also store an optional contact record — name, email, company, and any custom fields the workspace chooses to attach.
From chat-widget visitors
The widget records the browser and operating system, the page currently being viewed, a capped history of pages visited during the session, the browser language and timezone, and the visitor's IP address. If the workspace has configured a geolocation provider, the IP is sent to that provider to resolve an approximate country, region and city; this is off by default and no IP leaves our servers unless a workspace turns it on.
The widget sets no cookies. It stores a visitor identifier and recent messages in the browser's local storage so a conversation survives a page reload. Clearing site data removes them.
2. What we use it for
Operating the service: delivering and receiving email, routing tickets, running automations and SLA timers, showing reports, and sending notifications. Billing. Security — rate limiting, abuse prevention and the audit log. Support, when you ask us for help. That is the whole list. We do not sell personal data, and we do not use customer content for advertising.
3. AI features
Leodesk includes optional AI features: automatic tagging of incoming tickets, thread summaries, draft replies and chat assistance. They are off until an administrator turns them on.
When they are on, the relevant ticket content is sent to Anthropic for processing. Depending on the feature that includes the message text, the subject, the contact's name and email address, and internal agent notes on the thread. Automatic tagging runs on inbound mail without an agent triggering it, so enabling it means new customer email is sent for processing as it arrives.
If you do not want customer content processed this way, leave AI off. An administrator can disable it at any time in Settings, and it takes effect immediately.
4. Who else receives data
We use the sub-processors listed on our security page. Which of them apply depends on your configuration — AI, error monitoring and IP geolocation only receive data if you have enabled them.
Separately, if you connect an integration — Slack, Linear, Jira, GitHub, Shopify or an outbound webhook — Leodesk sends ticket data to that service on your instruction. That typically includes the subject, the contact's name and email address and some or all of the message body. Please note that if you connect a public GitHub repository, ticket content and contact email addresses will be publicly visible. These integrations are yours to configure, and the receiving service's own terms govern what it does with the data.
We also disclose data where we are legally required to.
5. How long we keep it
We want to be straightforward here, because it is the part most policies are vague about.
Ticket and contact data is retained for as long as the workspace exists. There is no automatic expiry. Agents can delete individual tickets and contacts at any time, and that deletion is immediate and permanent. A small number of operational records expire automatically: authentication tokens after seven days, chat-visitor session records after twenty-four hours, and outbound email records after ninety days.
Self-serve export and a published post-cancellation deletion window are not built yet. Until they are, email [email protected] and we will export your data or delete your workspace on request. We would rather tell you that than publish a timeline the product does not yet enforce.
One consequence worth stating plainly: our audit log records administrative actions, including deletions, and those entries — which may contain the name or email address of a deleted contact — are retained as part of the security record.
6. How we protect it
Passwords are stored as bcrypt hashes. Stored third-party credentials, such as the SMTP and IMAP passwords you give us for your own mail server, are encrypted with AES-256-GCM before being written. Connections to Leodesk use TLS. Each workspace's data is separated at the database-query layer, and the mechanism fails closed — a request that cannot establish which workspace it belongs to returns nothing rather than another tenant's data.
We do not currently encrypt stored data at rest at the application level, and we do not yet offer two-factor authentication. We are telling you this because a security page that lists only the good parts is not much use to someone doing a real review. The security page has the full picture.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a data protection authority.
If you are an agent or account holder, email [email protected] and we will action the request. We aim to respond within 30 days.
If you contacted a company that uses Leodesk and want your data accessed or deleted, contact that company directly. The data is theirs; we hold it on their behalf and act on their instruction. If you write to us, we will pass the request to them and tell you we have done so, but we cannot action it ourselves.
8. Where data is held
Leodesk runs in a single United States region. If you are outside the United States, using Leodesk means your data is transferred there. A data processing agreement is available on request from [email protected].
9. Cookies
The Leodesk application sets four cookies. Three are strictly necessary and one is a convenience:
leodesk_session— your signed-in agent session. HTTP-only, 30 days.leodesk_portal— the equivalent for an end-customer signed into a help centre. HTTP-only, 30 days.leodesk_brand— the workspace's brand colour, so the login screen renders correctly before the app loads. 30 days.leodesk_locale— your interface language. One year.
The marketing site sets no cookies. We use no analytics, advertising or tracking cookies anywhere. The site does load web fonts from Google Fonts, which means your browser sends its IP address and user agent to Google when a page loads.
10. Children
Leodesk is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
If we change this policy materially, we will update the effective date above and notify account administrators by email before the change takes effect.
12. Contact
Leodesk, Inc. — [email protected]. For privacy requests, please put "Privacy" in the subject line so it reaches the right place quickly.