Privacy Policy

Last updated: 2026-08-11

Leap Past ("the Service", "we", "our") is a private, work-only tool for teams. This Policy describes what data the Service collects, why we collect it, and how it is stored.

What we collect

  • Account info — the email address and company affiliation an administrator provides when creating your account. Passwords are stored only as bcrypt hashes; we never see your plain-text password.
  • Your team's content — the fixes, notes, procedures, and photos your team contributes. Photos are scanned with on-server OCR so the text inside them becomes searchable; the extracted text is stored alongside the photo.
  • Questions and answers — the questions you ask the assistant and the answers it returns, retained for audit and product-quality purposes.
  • Audit log — a record of significant actions (logins, content creation, moderation decisions) kept inside your company's isolated tenant.
  • Device info — standard HTTP request metadata (IP, user-agent) logged transiently for security and rate-limiting.

What we do with it

We use the data only to provide the Service's core function: retrieving the right document or fix to answer your question, attributing contributions to their authors, and maintaining an audit trail for your company's administrators. We do not sell data, share it with advertisers, or use it to train third-party large language models.

Tenant isolation

Every piece of data you contribute is tagged with your company and is invisible to any other company on the platform. Cross-company access requests return HTTP 404; cross-company tokens are rejected at every request. Photos are gated by the same boundary — a user from another company cannot fetch your photos by guessing their filenames.

Where it lives

Data is stored inside our own cloud account on Amazon Web Services, with bcrypt password hashes and HTTPS-in-transit (TLS 1.2+). The large language model that produces answers runs either on our own server (open-source models) or inside an AWS account (AWS Bedrock, Claude models). It never touches an external LLM vendor's shared API. Your prompts and our retrieved context are not used to train anyone else's model — including ours. The server refuses to start with any other LLM provider configured.

Retention

We retain your data for as long as your company's account is active. On request, your company administrator can purge your account and all your contributions in one operation. Soft-deleted items are retained for audit purposes for up to 90 days and then hard-deleted.

Your rights

You can request a copy of your personal data, ask for it to be corrected, or request deletion. Email hello@leappast.com with your request and we will respond within 30 days.

Children

The Service is a workplace tool not directed at anyone under 18, and we do not knowingly collect data from minors.

Changes

We may update this Policy. The "Last updated" date at the top reflects the most recent change. Material changes will be announced to administrators through the Service.

Contact

Questions about privacy? Email hello@leappast.com.