Privacy

Privacy Policy

This Privacy Policy explains how Leara handles personal data when you visit the website, create an account, use the application, call the API, or contact us.

Last updated August 31, 2026

Leara is operated by Techtale AB. If you use Leara on behalf of an organization, your organization may also control some personal data processed through the product. For product data processed on behalf of customers, see the Data Processing Addendum.

1. Who We Are

Learaprovides a generative interface runtime for SaaS products. In this policy, "Leara", "we", "us", and "our" mean Techtale AB, unless the context says otherwise.

For privacy questions, requests, or complaints, contact us at privacy@leara.dev. For general support, contact support@leara.dev.

2. Personal Data We Collect

CategoryExamplesSource
Account dataName, email address, profile image, authentication provider, account identifiers, workspace membership, and encrypted two-factor authentication settings when enabled.You, your organization, and authentication providers such as Google.
Workspace and project dataOrganization names, project names, settings, API key metadata, scopes, timestamps, and status. We store API keys as hashes after creation.You and authorized users in your workspace.
Waitlist dataName, work email, company, consent timestamp, waitlist source, status, and related timestamps.You.
Product and API usage dataPrompts, generated interface trees, runtime metadata, request timing, selected tools, validation status, error metadata, and usage counters.Your use of the app, API, SDK, and demo surfaces.
Billing dataPlan, subscription status, customer identifiers, invoice metadata, tax or billing details, and payment status. We do not store full card numbers.You and payment processors such as Stripe.
Support and communicationsMessages, feedback, attachments you send us, and related contact details.You.
Website and analytics dataDevice, browser, approximate location, page views, referrers, and cookie identifiers when optional analytics cookies are accepted.Your browser and analytics providers such as Google Analytics.
Security and log dataIP address, request metadata, authentication events, fraud prevention signals, audit logs, and error logs.Your browser, our systems, and infrastructure providers.

3. How We Use Personal Data

  • Provide, operate, secure, and improve Leara.
  • Manage the waitlist, prioritize access, and contact you about availability.
  • Create and manage accounts, workspaces, projects, and API keys.
  • Authenticate users and prevent unauthorized access.
  • Compose, validate, render, meter, and debug generated interface output.
  • Process subscriptions, invoices, taxes, payments, and plan limits.
  • Respond to support requests and product feedback.
  • Measure public website usage when optional cookies are accepted.
  • Detect abuse, enforce limits, comply with law, and protect rights.

5. AI, Prompts, and Generated Output

Leara may process prompts, context, retrieved data, generated interface trees, and related metadata to provide the product. Do not submit special category data, payment card numbers, health records, or other regulated data unless your agreement with us explicitly permits it and appropriate safeguards are in place.

Generated output can be incomplete or incorrect. You and your organization are responsible for reviewing outputs before using them for decisions that affect people, customers, finances, or legal rights.

6. Cookies and Analytics

We use strictly necessary cookies for authentication, security, and remembering cookie preferences. We use Google Analytics only after you accept optional cookies on public pages. See the Cookie Policy for details and how to change your choice.

7. Sharing and Subprocessors

We share personal data with service providers that help us host, secure, operate, analyze, and bill for Leara. These providers may include Render, MongoDB, Google, Stripe, and OpenAI depending on the features used. Our current list is available on the Subprocessors page.

We may also disclose data if required by law, to protect rights and security, or in connection with a merger, financing, acquisition, or similar corporate transaction.

8. International Transfers

Leara and its subprocessors may process personal data in countries outside your own. Where required, we rely on appropriate transfer safeguards such as adequacy decisions, standard contractual clauses, or equivalent contractual and technical protections.

9. Retention

We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required by law. Typical retention periods are:

  • Account and workspace data: while the account or workspace is active.
  • Waitlist entries: until access is granted, you ask us to remove the entry, or the waitlist is no longer needed.
  • API keys: metadata while active; full secrets are shown once and then stored only as hashes.
  • Usage, trace, and security logs: as needed for reliability, abuse prevention, debugging, billing, and audit trails.
  • Billing records: as required for tax, accounting, chargeback, and compliance obligations.
  • Support messages: for as long as needed to respond and maintain a useful support history.
  • Analytics data: according to the configured Google Analytics retention settings.

10. Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export your personal data. Where processing is based on consent, you may withdraw consent at any time.

Contact privacy@leara.dev to exercise these rights. We may need to verify your identity and, if your data is controlled by your organization, direct your request to that organization.

Signed-in users can also open Account settings, then Privacy & data, to download an account export or delete eligible Leara account data directly from the app.

11. Security

We use technical and organizational measures designed to protect personal data, including access controls, secret hashing where appropriate, encryption for two-factor authentication secrets, server-side API key handling, transport security, provider-level infrastructure protections, and operational monitoring. No system is perfectly secure, but we work to reduce risk by default.

12. Children

Leara is intended for business use and is not directed to children. Do not use Leara if you are under the age required to enter into a binding agreement in your jurisdiction.

13. Changes

We may update this policy as Leara changes. Material changes will be posted on this page, and where appropriate we will provide additional notice.

14. Helpful References

For general background on EU data protection concepts, see the European Commission data protection overview.