Effective date: 12th September 2025 Last updated: 12th September 2025
Contact: info@leephealth.com • Web: https://www.leephealth.com/privacy-policy
Key points (plain English)
- Your data stays on your phone by default. Cloud backup/sync is optional and off until you switch it on.
- We don’t sell your data. Ever.
- You’re in control. Export your data, delete your account, and change permissions any time.
- Wellness, not medical. We provide lifestyle insights, not diagnoses.
- Integrations are your call. Apple Health / Google Fit only if you enable them.
- Global compliance. We follow UK/EU GDPR, CPRA (US/CA), PIPEDA (Canada), APPs (Australia), and APPI (Japan).
1) Who we are (Controller)
- Leep Health Limited (Company No. 16012351)
71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ - Data Controller (UK/EU GDPR): Alap Shah, Director
- Contact: info@leephealth.com
2) Scope
This policy covers the Leep Smart Ring, Leep mobile app, our website and related services (the “Services”).
3) Data we collect
- Account & profile: name, email, phone, date of birth, gender, height, weight, country, time zone.
- Wellness/biometric data (special category): sleep stages/score/duration/consistency/trends; heart rate, HRV, temperature, blood oxygen; steps, calories, readiness score; derived insights/coaching and recommendations.
- Integrations (by your consent): data you choose to sync with Apple Health or Google Fit.
- Device/usage analytics (opt-in only): app events, crash logs, device identifiers, IP, cookie IDs (website).
- Payments: not collected by Leep. Purchases via Amazon/Shopify/Kickstarter/retailers are under their policies.
4) How we use data (purposes)
- Provide core features; generate insights and trends; personalised tips/coaching.
- Optional integrations (Apple Health/Google Fit) with your consent.
- Account communications and service notices.
- Marketing only if you opt in (unsubscribe any time).
- Research/product improvement using aggregated/anonymised data only if you opt in.
- Security, fraud prevention, and compliance with legal obligations.
5) Legal bases (EU/UK GDPR)
- Contract (to provide the Services).
- Consent (health data; integrations; analytics; marketing; research).
- Legitimate interests (service safety, improvement) balanced against your rights.
- Legal obligation (tax, accounting, regulatory requests).
6) Children & age limits
- Accounts are for 16+.
- Under 16s may use only with verified parental/guardian consent.
- We do not knowingly collect data from children under 13.
7) Sharing & disclosure
We do not sell personal data. We may share:
- At your direction: Apple Health, Google Fit, or future partners you opt in to.
- Service providers: e.g., cloud hosting (AWS), support tools - bound by confidentiality and DPAs.
- Legal reasons: to comply with law, protect rights/safety.
- Aggregated/anonymised data for research and statistics (non-identifiable).
8) Storage, location & transfers
- Offline-first: data is processed and stored on your device by default.
- Cloud backup/sync: optional; hosted on AWS (primary UK/EU, with global regions/backups).
- Encryption: in transit and at rest.
- International transfers: safeguarded via Standard Contractual Clauses and equivalent mechanisms where required.
9) Retention
We keep data while your account is active and as needed to provide the Services. You can delete your account to trigger deletion of cloud backups; certain records may be retained where law requires.
10) Your rights
Depending on your region, you can: access, correct, delete, restrict/object, portability, and withdraw consent.
Contact info@leephealth.com. We’ll verify identity and respond within statutory timeframes. You may have the right to complain to your local regulator.
11) Cookies & similar tech (website)
12) Region-specific notices
EU/UK (GDPR/UK GDPR): You may rely on the rights in Section 10. Special category (health/biometric) data is processed only with your explicit consent.
California (CCPA/CPRA): We do not “sell” personal information. You may request access, deletion, correction, and limit use of sensitive data; a “Do Not Sell/Share” control is available if ad tech is ever introduced.
Canada (PIPEDA): You may access/correct your data and withdraw consent (subject to legal limits).
Australia (APPs): You may access/correct information and complain to the OAIC if unresolved.
Japan (APPI): Cross-border transfers use appropriate safeguards; you may request disclosure/correction/suspension per APPI.
13) Changes to this policy
We’ll post updates here and in-app, and notify you of material changes. Continued use means you accept the updated policy.
14) Contact
Leep Health Limited • info@leephealth.com
71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ