This Privacy Policy explains how LEEKA, a French société par actions simplifiée (SAS) with share capital of €999, registered with the Paris Trade and Companies Register under number 108 437 344 and with its registered office at 94 Boulevard Flandrin, 75116 Paris, France, collects and processes personal data when you use the Leeka mobile application and the website at leeka.app (together, the “Service”). LEEKA is the data controller for this processing under the EU General Data Protection Regulation (GDPR) and applicable French data protection law. In this policy, “Leeka”, “we”, “us”, and “our” all refer to LEEKA as the operator of the Service.
For any privacy question, or to exercise your rights, you can contact us at privacy@leeka.app.
About this website (leeka.app)
This policy covers all of Leeka. On the leeka.app website, the personal data collected is what you enter in the newsletter sign-up: you give us your email address so that we can send you Leeka news, behind-the-scenes updates, and upcoming races. The sections below describe the Leeka Service as a whole — primarily the mobile app.
On the website specifically:
- We collect what you submit in the newsletter form: your email address. We also store the language you were viewing the site in (so we can send the newsletter in the right language) and the date you signed up, which records your consent. To protect the form from abuse, we also process limited technical data — your IP address or a hashed request fingerprint — used only for rate-limiting, not linked to your subscription.
- The legal basis is your consent, given when you tick the box and submit the form, for the single purpose of sending you our newsletter.
- We keep your email address until you ask us to delete it — by emailing privacy@leeka.app — after which we remove it. There is no automated unsubscribe or subscription-status mechanism.
- The website runs no analytics, no advertising and no third-party trackers, so there is no cookie banner. (PostHog and Sentry, named below, are used by the mobile app — not by this website.)
- To unsubscribe or have your email address deleted, email privacy@leeka.app and we will remove it.
1. What Leeka is
Leeka connects runners preparing for the same race with the same goal time, so that they can group together and run together in local crews.
Leeka publishes proposed meet-ups in the app, each with a date, a time, a meeting point, a session type, a distance, and a pace. These details are provided for information only. Leeka provides no sports supervision within the meaning of Article L. 212-1 of the French Sports Code and is neither a coaching service nor a medical service.
To do this, the Service stores profile information, session and coordination data, your participation choices, the content you post to your crew, and the declarations and evidence described in Section 2.
2. Data we collect
Account and identity
- Your email address and a hashed password (managed by our authentication provider), or, if you choose “Sign in with Apple” or “Sign in with Google”, the identifier those providers return to us.
- Your first name, last name, and gender, provided during onboarding.
Declarations and evidence
Before your first participation in a session, and as you use the Service, we record the following:
- Your sworn declaration that you have no medical contraindication to running, with the date and time of that declaration.
- Your sworn declaration that you hold valid personal civil-liability insurance, with the date and time of that declaration.
- The version of the Terms of Service and of this policy in force when you created your account, with the date, the time, and the IP address of the connection.
- A safety-notice display log: your account identifier, the identifier of the session concerned, the version of the text you were shown, and the timestamp of that display.
- A confirmation log for the exceptional-conditions banners (night session, extreme heat, black ice, storm, unusual route), with the timestamp of your confirmation.
On the medical declaration. The declaration that you have no medical contraindication is data concerning health within the meaning of Article 9 of the GDPR. We process it on the dual basis of your explicit consent (GDPR Art. 9(2)(a)), given when you tick the dedicated box before your first participation, and of the necessity of that processing for the establishment, exercise, and defence of legal claims (GDPR Art. 9(2)(f)).
We record no information about your actual state of health, no diagnosis, no medical history, no medical certificate: only the fact that you declared you have no contraindication, and the date of that declaration. This data is never visible to other users, is passed to no analytics or ad measurement provider, and internal access to it is restricted to authorised staff.
Profile
- An optional profile photo.
- An optional short bio.
- A link to your Instagram profile and a link to your Strava profile, both optional. If you add them, they are visible beyond your crew: see Section 3.
Session and coordination data
- Your target event, goal-time band, and city (selected from a list).
- Your crew membership and your time-slot votes for sessions.
- Your attendance records and streak data. A record states either that you attended or that you missed the session. Once recorded, that answer cannot be changed from within the app; see Section 9 to have it corrected.
Content you create
- Messages you send in session chats, including photos, whether from your gallery or taken with the in-app camera. Camera and gallery access is only requested at the moment you use it, and can be declined without preventing you from using the rest of the app.
- Photos, clips, posts, comments, and reactions you share in your crew feed.
Technical and usage data
- A per-device push-notification token, if you enable notifications, used to deliver alerts to that device, together with a per-device delivery receipt recording whether a notification was delivered. Notifications cover session reminders (24 hours and 2 hours before), replies and reactions to your content, and streak alerts. Each category can be turned off separately in settings.
- Product-analytics events (for example, which actions you take in the app, with your user identifier and, where relevant, your crew identifier) used to understand and improve the Service. These events do not include the content of your posts, comments, chat messages, or bio, nor any of the declarations described above — only the type of action and non-content metadata (for example, the length of a post, never its text).
- Basic device and app information attached automatically to analytics and diagnostic events — such as device model, operating-system version, app version, language, and a generated analytics/device identifier.
- Diagnostic and crash data used to detect and fix errors. We configure crash reporting not to attach directly identifying personal information.
- Your IP address is processed transiently by our infrastructure providers as a normal part of connecting your device to the Service; we do not use it to build a location profile. It is also recorded once, at the moment you create your account, as part of the evidence of your acceptance of the Terms of Service.
What we do not collect
- We do not collect your precise or background GPS location. Your city is a value you select, not a device-location reading.
- We do not collect or store payment-card or banking information.
- We do not collect your date of birth and we do not verify your age: see Section 11.
- We collect no medical certificate, no diagnosis, no medical history, and no health data other than the sworn declaration described above.
- Beyond that declaration and the profile fields described above, we do not knowingly collect special-category data.
3. How other users see your data
Leeka is a group product. Two things need to be told apart: what you publish, and your profile.
What you publish is visible only to members of your crew, never to the public: your chat messages and the photos you send in them, your posts, comments and reactions in your crew feed, and your time-slot votes.
Your profile goes further. It is visible to any signed-in Leeka member who opens the page of a run that is open to the whole community, whether or not they are attending that run themselves. That includes your first name (with a last initial if names clash), your profile photo, your city, your bio, your target event and goal-time band, your total distance, your number of sessions, your attendance rate, your current streak, and the Instagram and Strava links you have chosen to add. If you would rather your social profiles not be visible beyond your crew, do not fill those fields in.
On runs limited to a single crew, that same information is visible only to members of that crew.
The declarations and evidence described in Section 2, including the medical declaration, the insurance declaration, and the safety-notice display logs, are visible to no other user whatsoever.
The app does not show other members the sessions you have missed. They only see the indirect effect, through your streak and your attendance rate, which they cannot tell apart from simply not having answered.
Nothing is ever visible to the public or to search engines: all access requires a Leeka account and is enforced at the database level.
4. How we use your data and our legal bases
| Purpose | Legal basis |
|---|---|
| Creating and securing your account; running core features (crews, sessions, chat, feed) | Performance of a contract |
| Collecting and keeping your declaration that you have no medical contraindication | Explicit consent (GDPR Art. 9(2)(a)) and necessity for the establishment, exercise, and defence of legal claims (GDPR Art. 9(2)(f)) |
| Collecting and keeping your personal civil-liability insurance declaration | Performance of a contract, and our legitimate interest in the establishment, exercise, and defence of legal claims (GDPR Art. 6(1)(f)) |
| Keeping the evidence of your acceptance of the Terms of Service and of the display of the safety notice | Our legitimate interest in the establishment, exercise, and defence of legal claims (GDPR Art. 6(1)(f)) |
| Delivering push notifications you have enabled | Consent (you can withdraw it at any time in Settings or your device settings) |
| Sending you Leeka community news: announcements, events, surveys | Legitimate interest in keeping users informed about the service they signed up for (GDPR Art. 6(1)(f)). You can object at any time, using the unsubscribe link in every message. |
| Measuring whether our advertising campaigns lead to installs and sign-ups (Android only — see “Ad measurement (Meta)” below) | Consent (you can withdraw it at any time in Settings → Privacy) |
| Product analytics to understand usage and improve the Service | Our legitimate interest in understanding and improving the Service. You can object to this processing, or ask us to delete your analytics data, at any time by contacting us. |
| Error monitoring and security | Our legitimate interest in a stable, secure Service |
| Responding to your requests and meeting legal obligations | Legal obligation and legitimate interest |
5. Who we share data with
We do not sell your personal data. We share it only with service providers (processors) who help us operate the Service, under contracts that require them to protect it:
- Supabase — database, authentication, file storage (profile photos and feed media), and realtime infrastructure. This is where your account, profile, session, and content data live.
- PostHog — product analytics.
- Sentry — error and crash monitoring. (We do not enable Sentry session replay or any screen-recording feature.)
- Apple and Google — if you use their sign-in. They also operate the push notification networks (Apple Push Notification service on iOS; Firebase Cloud Messaging on Android), so a push you have enabled is delivered through them.
- Expo (Expo Application Services) — push-notification delivery tooling and over-the-air app updates.
- Upstash — Redis-based rate limiting on the website newsletter form, to protect it from abuse (keyed on your IP address or a hashed request fingerprint).
- Resend — email delivery for the website newsletter and for emails sent to the Leeka community.
- Google Workspace — business email used to receive and handle requests you send to privacy@leeka.app and support@leeka.app.
The declarations and evidence described in Section 2, including the medical declaration, the insurance declaration, the evidence of acceptance of the Terms of Service, and the safety-notice display logs, are hosted exclusively in our Supabase database (EU West region, Ireland). They are passed to no product-analytics, error-monitoring, or ad-measurement provider.
Meta is not one of these processors. If you use Leeka on Android and you have given your consent, limited technical data is also shared with Meta for ad measurement, and Meta acts as its own controller for what it then does with that data. This is described in full in “Ad measurement (Meta) — Android only, with your consent”, immediately below.
We may also disclose data where required by law, or to protect the rights and safety of our users and the Service.
Ad measurement (Meta) — Android only, with your consent
If you use Leeka on Android, we ask you at first launch — before you create an account — whether you agree to ad-performance measurement. Only if you accept is the Meta SDK activated in the app, and the following data transmitted to Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland): your device’s advertising ID, your IP address, technical device and app information (device model, operating-system version, app version, language), timestamps, an anonymous identifier generated by the Meta SDK, and app events — an install confirmation, app-activity events (such as app opens and session activity), and a one-time sign-up event when you create an account. We use this to measure whether our advertising campaigns on Meta platforms lead to installs and sign-ups (ad attribution). Legal basis: your consent (GDPR Art. 6(1)(a)). Declining costs you nothing — every part of Leeka works exactly the same either way.
We never send Meta your name, your email address, or anything you post or record in the app — not your messages, your photos, your runs, or your session data. Nor do we ever send the declarations and evidence described in Section 2, in particular the medical declaration. The Meta SDK features that could read screen or form content — Automatic Advanced Matching, codeless events, and similar — are disabled in our code.
You can withdraw your consent at any time in Settings → Privacy. Withdrawal stops future collection; it takes full effect the next time the app starts, and it does not delete data already transmitted to Meta. We keep a timestamped record of your consent decision — granted or withdrawn — so that we can demonstrate it (GDPR Art. 7(1)).
Meta may process this data in the United States. That transfer is covered by Meta’s certification under the EU-U.S. Data Privacy Framework. For Meta’s own processing, see Meta’s privacy policy.
On iOS, no Meta software is included in the app and no advertising identifier is read. Install attribution on iOS uses Apple’s SKAdNetwork, in which Apple sends a signed postback that, per Apple’s documentation, contains no user- or device-specific data.
6. International transfers
Our core providers store your data in the European Union, within the EEA: Supabase (database,
authentication, and file storage) in its EU West region (Ireland); PostHog (analytics) in its EU
region (eu.i.posthog.com); and Sentry (crash monitoring) in its EU region. The
declarations and evidence described in Section 2 never leave Supabase and are therefore never
transferred outside the EEA.
When you enable push notifications, the notification is relayed through Expo, Apple, and/or Google, whose notification infrastructure may process the notification and your device push token outside the EEA (including in the United States). Where that occurs, the transfer relies on Standard Contractual Clauses and equivalent safeguards offered by those providers.
For email delivery, two further providers are involved. Resend (Resend, Inc.), which delivers the
newsletter and the community emails, is based in the United States, so writing to you involves a
transfer outside the EEA; that transfer relies on Standard Contractual Clauses and equivalent
safeguards. Upstash, which rate-limits the newsletter form, processes that data in its EU West
region (Ireland, eu-west-1), within the EEA, so no transfer outside the EEA is
involved.
If you consented to ad measurement on Android, the data listed in “Ad measurement (Meta)” above is also transferred to Meta, which may process it in the United States. That transfer relies on Meta’s certification under the EU-U.S. Data Privacy Framework rather than on Standard Contractual Clauses.
7. How long we keep your data
We keep your personal data for as long as your account is active and as needed to provide the Service. When you delete your account, your profile information is scrubbed as described in Section 8; note that the underlying account login record (including your email) and the content you posted are retained as explained there.
We keep analytics events for no longer than necessary to understand and improve the Service. Our analytics provider does not automatically expire this data, so we delete it when it is no longer needed and, on request, when you delete your account. Crash and diagnostic data is retained for up to 90 days. Database backups are retained for 7 days.
The declarations and evidence described in Section 2 follow their own retention periods, justified by their evidential purpose:
- Your medical and insurance declarations, together with the evidence of your acceptance of the Terms of Service and of this policy (version, timestamp, IP address), are kept for the whole lifetime of your account, then for 5 years.
- The safety-notice display logs and the exceptional-conditions banner confirmation logs are kept for 10 years from the session concerned. That period matches the limitation period applicable to liability claims for personal injury.
After those periods, these items are deleted.
We keep the timestamped record of your ad-measurement decision — consent given or withdrawn — for 3 years from the deletion of your account or from your most recent withdrawal, so that we can demonstrate it if needed (GDPR Art. 7(1)). That record contains only your internal account identifier, the date of your decision, which way it went, the version and language of the text you were shown, and the screen you answered from. It contains no name, no email address, no advertising identifier and no IP address. After that period it is deleted.
8. Deleting your account and data
You can delete your account from within the app (Settings → Delete account). When you confirm, the following happens and the action is irreversible:
- If you signed in with Apple, your Sign in with Apple authorisation is revoked.
- Your profile information is scrubbed: your first and last name, profile photo, bio, gender, and city are cleared.
- Your push-notification tokens are retired so you stop receiving notifications.
- You are signed out, and the account can no longer be used to sign back in — the deletion cannot be undone from your device.
What this does not do, so you know exactly where you stand: content you posted to a crew — posts, photos, comments, chat messages, and session votes — remains in that crew’s history. Once your profile is scrubbed, that content is shown as coming from a removed member and is no longer labelled with your name or photo, but the content itself is not deleted. For the same reason, your underlying account login record (including your email address) is retained rather than erased, and your content stays linked to an internal account identifier. In other words, this flow pseudonymises your presence to other users rather than fully erasing all of your data.
The following are also retained, attached to your internal account identifier, for the periods stated in Section 7:
- The evidence of your acceptance of the Terms of Service and of this policy: the version accepted, the timestamp, and the IP address of the connection. That IP address is kept deliberately, because it is part of what gives this record its value in the event of a dispute.
- Your medical and insurance declarations, as timestamped flags dissociated from your name and your photo.
- The safety-notice display logs and the exceptional-conditions banner confirmation logs.
These items are kept for the sole purposes of the establishment, exercise, and defence of legal claims. They are used for no other purpose.
Finally, the timestamped record of your ad-measurement decision is retained, in hidden form, for the period stated in Section 7. Once your profile is scrubbed, it carries nothing but the internal identifier of an account emptied of its information.
You can also request deletion without using the app — including if you no longer have it installed — at leeka.app/en/delete-account, or by emailing privacy@leeka.app. Use either route to ask us to erase any data this in-app process does not remove.
9. Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. One case is worth spelling out: attendance records, whether present or missed, cannot be changed from within the app. If one of them is wrong, email us at privacy@leeka.app and we will correct it. To exercise any of these rights, contact us at privacy@leeka.app.
Two limits are worth stating clearly:
- The right to erasure does not apply to data kept for the establishment, exercise, or defence of legal claims, in accordance with GDPR Art. 17(3)(e). This covers the items listed in Section 8, for the periods stated in Section 7.
- You can withdraw at any time the consent relating to your declaration that you have no medical contraindication, by emailing us at privacy@leeka.app. As that declaration is a condition of taking part in sessions, withdrawing it ends your ability to take part. The declaration already collected remains stored for the period stated in Section 7, on the basis of GDPR Art. 9(2)(f).
If you believe we have mishandled your data, you have the right to lodge a complaint with the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), at www.cnil.fr.
10. Security
We use access controls, encryption in transit, and database-level row security. Content posted within a crew is accessible only to members of that crew. The profile information described in Section 3 is accessible to all signed-in members in the context of runs open to the whole community.
Health-related declarations are subject to stricter access restrictions: they are accessible to no other user, are exposed by no interface of the app, and internal consultation of them is reserved to authorised staff.
No system is perfectly secure, but we take reasonable measures to protect your data.
11. Children
The Service is reserved for adults. You must be at least 18 years old to use Leeka.
We do not ask for your date of birth and we do not verify your age: by creating an account, you declare that you are of legal age.
We do not knowingly collect data from anyone under 18. If you believe an account belongs to a minor, contact us at privacy@leeka.app and we will delete it along with the associated data.
12. Changes to this policy
We may update this policy as the Service evolves. We will revise the “Last updated” date above.
Any material change to this policy is notified to you individually, by email or by an in-app notification, at least thirty (30) days before it takes effect. If you do not accept the new version, you can delete your account free of charge before that date.
13. Contact
Data controller:LEEKA, société par actions simplifiée (SAS), share capital €999
RCS Paris 108 437 344
94 Boulevard Flandrin, 75116 Paris, France
privacy@leeka.app
This English text is a courtesy translation. The French version, available at leeka.app/fr/privacy, is the legally binding version; in the event of any discrepancy, the French version prevails.