Privacy policy
Version 1.0 · Effective 5 September 2026 · Loomens, Tunisia
In plain words. We keep the data needed to run your account, your projects and your deployments, and nothing for advertising. Your chat messages and project files go to an AI model provider to generate code and are never used to train models. Your Cloudflare token is encrypted and only used to deploy. You can export or delete your projects yourself and ask us to delete your account at any time.
1. Who is responsible
Loomens, a company established in Tunisia, operates LeadMax and is the controller of the personal data described in this policy. Contact for anything related to personal data: legal@leadmaxhq.com. Postal address: [to be completed before launch].
This policy covers the LeadMax platform and the generated website analytics described below. For other personal data processed by applications you build and deploy to your own Cloudflare account, you are responsible for your own privacy notices and provider relationships.
2. What we collect and why
We only collect what the Service needs to work. By category:
| Category | Data | Purpose |
|---|---|---|
| Waitlist | Email address, phone number with country code, preferred language, request date and notice version. | To record your interest and contact you about LeadMax access. Joining does not create an account or send an automatic email or SMS. |
| Account | Name, email address, password (stored hashed), whether the email is verified, sign-in method, session identifiers, IP address and browser of each session. | To create and secure your account, sign you in, send verification and password-reset emails. |
| Cloudflare connection | The identity Cloudflare returns at authorisation, the ids and names of the Cloudflare accounts you granted, their workers.dev subdomain, the permissions granted, and the OAuth tokens (encrypted). | To deploy to your Cloudflare account and to show you what was authorised. |
| Projects | Project names and settings, every file of the project, snapshots (versions), the chat history with the agent, deployment records and build logs. | To provide the editor, the preview, the versions and the deployments; the chat history lets you continue a conversation. |
| Usage | Per turn: model used, token counts, estimated cost, credits debited. Credit ledger entries (grants and debits). | To count credits, enforce workspace limits, show your balance and history, and keep the accounts the law requires. |
| Support | Emails you send us and our answers. | To answer you and keep a record of the exchange. |
| Technical | Server logs (request path, status, timing, IP address, user agent), error reports, and, where analytics is enabled, page views and product events tied to your account id. | To keep the Service running, find and fix problems, protect it against abuse, and understand which features are used. |
We do not buy data about you from third parties, and we do not use your data for advertising.
3. Generated website analytics
Published websites created with the business starter send LeadMax public page views and optional UTM source, medium and campaign labels. Project owners see aggregate counts in their project overview. This collector sets no cookies, stores no full query strings and does not track visitors across websites or days.
To estimate daily unique visitors, the collector briefly processes the IP address and browser user agent into a keyed hash specific to the project and UTC day. It never stores the raw IP address or user agent in these analytics records. Counts are estimates: shared devices, blocked requests and daily rotation affect them. Do Not Track and Global Privacy Control are respected; previews, administration and authentication pages and known bots are excluded.
Reports cover a rolling 30-day window. Older records are removed on the next collected visit to the project; dormant projects may retain older records until that cleanup or project deletion. The website owner should describe this collection in their own visitor-facing privacy notice. The small Made by LeadMax credit is visible to people and crawlers alike; bot filtering changes counting only, not website content.
4. Legal bases (EU, EEA and UK users)
- Performance of the contract (GDPR article 6(1)(b)): account, Cloudflare connection, projects, usage and usage tracking, support. Without this data the Service cannot be provided.
- Legal obligation (article 6(1)(c)): keeping invoices and accounting records, answering lawful requests from authorities.
- Legitimate interests (article 6(1)(f)): security and abuse prevention, server logs, error reports, product analytics that helps us improve the Service, and defending our rights. You may object (section 8).
- Consent (article 6(1)(a)): only where we ask for it, for example optional emails about new features. You can withdraw consent at any time.
5. AI processing
When you send a message to the agent, the Service sends that message, the relevant files of your project and the agent's working instructions to an AI model through OpenRouter. The model provider processes them to produce the next edit and returns it to us. We store the conversation and the resulting files in your project.
- We do not train AI models on your projects or messages, and we do not allow our providers to do so under our agreements with them.
- Do not put personal data or secrets into chat messages or project files unless you need them there; the agent has no need for them.
- The Service does not make decisions about you with legal or similarly significant effects by automated means.
6. Who receives your data
We share personal data only with providers that process it on our instructions (processors) and, where the law requires, with authorities. Our processors:
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. (USA) | Runs our platform: Workers, the D1 database, R2 storage, KV cache, queues and the build containers. Also the Turnstile bot-protection widget on sign-in pages where enabled. | All categories, as the hosting provider. |
| OpenRouter, Inc. (USA) and the AI model provider it routes each request to | Generates the agent's responses. | Your chat messages and the project files needed for a turn. |
| StackBlitz, Inc. (USA) | Provides the WebContainer runtime that your browser downloads to run the preview; the runtime works inside your browser and your project files do not leave it. | Technical data needed to load the runtime. |
| Resend, Inc. (USA) | Delivers the emails we send you (verification, password reset). | Email address and the content of those emails. |
| PostHog, Inc. (data hosted in the EU), where enabled | Product analytics. | Page views, product events and your account id; no advertising use. |
Cloudflare, Inc. also receives data directly from you when you authorise LeadMax on its consent screen and when you use your own Cloudflare account; Cloudflare's privacy policy governs that. We never sell personal data and never share it with advertisers.
7. International transfers
Loomens is established in Tunisia and most of our providers are established in the United States, so personal data of users in the EU, EEA and UK is transferred outside those areas. Neither Tunisia nor the United States (outside the EU-US Data Privacy Framework) benefits from a general adequacy decision.
We rely on the European Commission's standard contractual clauses (and the UK addendum) in our agreements with each provider, on the EU-US Data Privacy Framework where a provider is certified, and on technical measures such as encryption in transit and at rest. You can ask for a copy of the safeguards in place at legal@leadmaxhq.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | While your account exists, then deleted within 30 days of your deletion request. |
| Cloudflare tokens | Until you disconnect the account or delete your LeadMax account; deleted at once. |
| Projects, snapshots, chat history | Until you delete the project (or your account); removed from live storage at once and from backups within 30 days. |
| Deployment records and build logs | While the project exists. |
| Credit ledger and usage records | For as long as accounting and tax law requires after the transaction, typically up to 10 years. |
| Server logs and error reports | Up to 30 days. |
| Analytics events (where enabled) | Up to 12 months. |
| Support emails | Up to 24 months after the last exchange. |
9. Your rights
Under the GDPR, the UK GDPR and Tunisia's personal data protection law, you may ask us to access the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, and to receive the data you gave us in a portable format. Where processing is based on consent you may withdraw it at any time.
Write to legal@leadmaxhq.com from the email address of your account. We answer within one month (extended by up to two months for complex requests, in which case we tell you). We may ask you to confirm your identity.
You can also complain to a supervisory authority: in Tunisia the Instance Nationale de Protection des Données Personnelles (INPDP); in the EU the authority of your country (for France, the CNIL); in the UK the ICO. We would appreciate the chance to address your concern first.
Much of this is self-service: your account page shows your details, projects can be exported and deleted from the dashboard, and Settings shows and revokes the Cloudflare connection.
The Service uses a strictly necessary session cookie to keep you signed in, and a short-lived cookie during OAuth sign-in to protect against forged requests. Both are first-party and are not used for tracking. The editor keeps preferences such as pane sizes in your browser's local storage.
Where Cloudflare Turnstile is enabled on sign-in pages, it may set a cookie of its own to tell people from bots. Where analytics is enabled, it is served from our own domain and an EU-hosted provider, uses no advertising identifiers and is not shared with third parties for their purposes.
We do not use advertising cookies or third-party tracking, so the Service shows no cookie banner.
11. Security
- All traffic is encrypted in transit (TLS). Data at rest is stored on Cloudflare's infrastructure with encryption at rest.
- Cloudflare OAuth tokens are encrypted with a platform secret before storage and are only decrypted on our servers when a deploy needs them.
- Passwords are stored as salted hashes; sign-in and password reset are rate-limited and, where enabled, protected by Turnstile.
- Calls between our internal services are signed; the build container that compiles your project never sees your Cloudflare token.
- Access to production data is limited to the people who operate the Service and need it.
12. Children
The Service is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has created an account, write to legal@leadmaxhq.com and we will delete it.
13. Changes to this policy
We may update this policy when the Service, our providers or the law change. Material changes are announced by email or in the Service at least 30 days before they take effect. The version and effective date are shown at the top of this page.
14. Contact
Loomens, Tunisia. Email: legal@leadmaxhq.com. See also the terms of service.