Leo

Privacy Policy

Effective date: 5 October 2026 · Product: Leo · Domain: leoos.app

This Privacy Policy explains how the Leo desktop product (“Leo”, “we”) handles personal information, including Google and Gmail data when you choose to connect a Google account. It is intended to describe Leo’s current product behavior, not marketing promises.

1. Who Leo is for

Leo is a personal operating assistant that runs as an application on your computer. Leo helps you work with information and tools you already use. Leo is not a public social network and is not designed to collect Gmail content from people who have not connected their own accounts in the product.

2. Information Leo may process

Depending on how you use Leo, Leo may process:

3. Google / Gmail connection and Personal Retrieval

Connecting Google/Gmail is initiated by you in Leo. Leo supports multiple explicitly connected Google accounts. Personal Retrieval is account-bound: Leo uses the account you select, and when more than one connected inbox could apply, Leo asks you to choose before reading Gmail.

For Gmail Personal Retrieval (CAP03), Leo’s read credentials use these Google scopes:

Read credentials are kept separate from any Gmail operations credentials that may exist for other product features. A read credential is not used as send/compose/modify authority, and an operations credential is not used as Personal Retrieval authority.

Retrieved email content is used to answer your retrieval request. Email content does not itself become authority for Leo to perform unrelated effects. Gmail content is not automatically persisted into Leo’s situational-awareness subsystem, is not written into Fleet learning telemetry as private message content, and does not authorize Software Update.

4. How Google user data is used (Limited Use)

Leo uses Google user data only to provide user-facing features you request—primarily connecting your Google account and retrieving personal Gmail information for you. Leo does not sell Google user data. Leo does not use Google user data obtained through these scopes to train generalized foundation models, serve advertising, or build unrelated profiles for third parties.

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Credential storage and account metadata

OAuth credential material for Gmail is stored locally in Leo’s user data area as encrypted records. On macOS, the encryption key material is held with the platform Keychain-backed secret architecture used by Leo. Plaintext access and refresh tokens are not persisted as ordinary files. Account-slot metadata may identify the connected account (for example, email address, scopes, and verification status) without exposing token bytes. User Gmail credentials are not packaged inside Leo software release bundles.

6. What is persisted and what is not

Leo may use AI model providers for other product features. This policy does not claim that every piece of information you ask Leo about remains exclusively on your device in all product modes. For Gmail Personal Retrieval, Leo’s accepted path retrieves from Google to serve your request and keeps credential secrets in the local protected credential architecture described above.

7. Retention, disconnect, and deletion

If you uninstall Leo or delete Leo’s local user data directory, local credential and account metadata stored there are removed with that local data. Revoking Leo’s access from your Google Account security settings also stops future Google API access for that grant.

8. Sharing and third parties

Leo contacts Google’s OAuth and Gmail APIs to connect accounts and retrieve authorized mailbox information. Credential secrets are not uploaded into Leo release packages. Fleet learning does not receive private Gmail message content as telemetry fields. Leo does not use Gmail content as authority for Software Update.

This website (leoos.app) is a public product identity surface. Ordinary web hosting/CDN infrastructure may process standard request logs for the website itself. That website traffic is separate from your desktop Leo Gmail credentials.

9. Children

Leo is not directed to children and is intended for use by adults who control the computer and accounts they connect.

10. Changes

If this policy changes in a material way, we will update this page and the effective date above.

11. Contact

For privacy questions about Leo’s Google/Gmail connection, use the support or developer contact email shown on Leo’s Google OAuth consent screen for the Leo project. Dedicated support@leoos.app or privacy@leoos.app mailboxes are not claimed by this policy unless separately provisioned.