This Privacy Policy explains how the Leo desktop product (“Leo”, “we”) handles personal information, including Google and Gmail data when you choose to connect a Google account. It is intended to describe Leo’s current product behavior, not marketing promises.
Leo is a personal operating assistant that runs as an application on your computer. Leo helps you work with information and tools you already use. Leo is not a public social network and is not designed to collect Gmail content from people who have not connected their own accounts in the product.
Depending on how you use Leo, Leo may process:
Connecting Google/Gmail is initiated by you in Leo. Leo supports multiple explicitly connected Google accounts. Personal Retrieval is account-bound: Leo uses the account you select, and when more than one connected inbox could apply, Leo asks you to choose before reading Gmail.
For Gmail Personal Retrieval (CAP03), Leo’s read credentials use these Google scopes:
https://www.googleapis.com/auth/gmail.metadatahttps://www.googleapis.com/auth/gmail.readonly when message-body access is requiredRead credentials are kept separate from any Gmail operations credentials that may exist for other product features. A read credential is not used as send/compose/modify authority, and an operations credential is not used as Personal Retrieval authority.
Retrieved email content is used to answer your retrieval request. Email content does not itself become authority for Leo to perform unrelated effects. Gmail content is not automatically persisted into Leo’s situational-awareness subsystem, is not written into Fleet learning telemetry as private message content, and does not authorize Software Update.
Leo uses Google user data only to provide user-facing features you request—primarily connecting your Google account and retrieving personal Gmail information for you. Leo does not sell Google user data. Leo does not use Google user data obtained through these scopes to train generalized foundation models, serve advertising, or build unrelated profiles for third parties.
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
OAuth credential material for Gmail is stored locally in Leo’s user data area as encrypted records. On macOS, the encryption key material is held with the platform Keychain-backed secret architecture used by Leo. Plaintext access and refresh tokens are not persisted as ordinary files. Account-slot metadata may identify the connected account (for example, email address, scopes, and verification status) without exposing token bytes. User Gmail credentials are not packaged inside Leo software release bundles.
Leo may use AI model providers for other product features. This policy does not claim that every piece of information you ask Leo about remains exclusively on your device in all product modes. For Gmail Personal Retrieval, Leo’s accepted path retrieves from Google to serve your request and keeps credential secrets in the local protected credential architecture described above.
If you uninstall Leo or delete Leo’s local user data directory, local credential and account metadata stored there are removed with that local data. Revoking Leo’s access from your Google Account security settings also stops future Google API access for that grant.
Leo contacts Google’s OAuth and Gmail APIs to connect accounts and retrieve authorized mailbox information. Credential secrets are not uploaded into Leo release packages. Fleet learning does not receive private Gmail message content as telemetry fields. Leo does not use Gmail content as authority for Software Update.
This website (leoos.app) is a public product identity surface. Ordinary web hosting/CDN infrastructure may process standard request logs for the website itself. That website traffic is separate from your desktop Leo Gmail credentials.
Leo is not directed to children and is intended for use by adults who control the computer and accounts they connect.
If this policy changes in a material way, we will update this page and the effective date above.
For privacy questions about Leo’s Google/Gmail connection, use the
support or developer contact email shown on Leo’s Google OAuth consent
screen for the Leo project. Dedicated support@leoos.app or
privacy@leoos.app mailboxes are not claimed by this policy
unless separately provisioned.