Skip to content

Last updated July 30, 2026

This policy explains what Leaki collects, why, where it is stored, and what you can require us to do with it. It covers leaki.app and the Leaki application. Leaki, Inc. is a Delaware corporation and is the data controller for the information described here.

1. Information we collect

Account information

When you create an account we collect your email address, a display name, and a password. Passwords are never stored. We store a bcrypt hash at twelve rounds, which cannot be reversed to recover the original password.

Financial data from connected systems

When you connect QuickBooks, Xero, or Zoho Books, Leaki reads transaction records through the provider's API using OAuth. The scopes we request are read-only. Leaki has no write permission and is technically incapable of creating, modifying, or deleting anything in your accounting system.

The records read include vendor and customer names, invoices, bills, payments, credit memos, purchase orders, line item detail, and account categories. We read this data because it is the subject of the audit. There is no way to detect a duplicate payment without reading the payments.

Documents you upload

If you use the document analyzer, the files you upload are processed to extract transaction data and are retained with your account until you delete them.

Usage and device information

We collect standard web analytics: pages viewed, approximate location derived from IP address, browser and device type, and referring site. This is collected through Google Analytics and PostHog. It is used to understand how the product is used and is not combined with your financial records.

2. How we use it

  • To run audits against your connected accounting data and produce findings.
  • To draft dispute correspondence for findings you choose to pursue.
  • To send you transactional email: alerts on critical findings, and account and security notices.
  • To authenticate you and keep your session secure.
  • To diagnose faults and improve detection accuracy.
  • To bill you when a recovery is realised.

We do not sell your data. We do not share it with advertisers. We do not use your financial records to train general-purpose machine learning models.

3. Subprocessors

Leaki relies on the following third parties, each of which processes some category of data on our behalf. This list is exhaustive as of the date at the top of this page.

  • Vercel, for application hosting and delivery.
  • Supabase, for the Postgres database holding account records and audit findings.
  • Google, for the Gemini models that perform analysis on transaction data, and for Google Analytics on the marketing site.
  • Intuit, Xero, and Zoho, as the sources of the accounting data you choose to connect.
  • Resend, for outbound transactional email.
  • PostHog, for product analytics.

4. Security

  • All traffic is served over TLS with HSTS and a preload directive.
  • Data is encrypted at rest by our database provider using AES-256.
  • OAuth tokens are stored encrypted and are scoped read-only.
  • Sessions are signed tokens with expiry and server-side revocation.
  • A strict Content Security Policy restricts what may execute or connect from our pages.
  • Rate limits apply to authentication and to every mutating endpoint.

No system is perfectly secure. If you believe you have found a vulnerability in Leaki, write to us before disclosing it publicly and we will work with you on a fix.

5. Retention

Account records and audit findings are retained while your account is open. If you disconnect an accounting system, we stop reading from it immediately, and the data already read is retained until you request deletion so that historical findings remain reviewable. If you close your account, we delete your personal data and financial records within thirty days, except where a longer period is required to resolve a billing dispute or comply with law.

6. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, export it in a portable format, or object to particular processing. California residents have the rights granted by the CCPA and CPRA, including the right not to be discriminated against for exercising them. Residents of the EEA and UK have the rights granted by the GDPR.

To exercise any of these, email us using the address on the contact page. We respond within thirty days. We do not charge a fee, and we will not ask you to justify the request.

7. Cookies

Leaki sets a session cookie when you sign in, which is strictly necessary and cannot be disabled while remaining logged in. Analytics cookies are set by Google Analytics and PostHog. Your theme preference is stored in local storage on your own device and is never sent to us.

8. Children

Leaki is a business tool and is not directed at anyone under sixteen. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

9. International transfers

Leaki is operated from the United States and our infrastructure is hosted there. If you access Leaki from outside the United States, your data is transferred to and processed in the United States.

10. Changes

If we change this policy in a way that materially affects how we handle your data, we will email account holders before the change takes effect. The date at the top of this page always reflects the current version.

Questions about any of this go to our contact page. The companion document is the terms of service.