Leadpocket
Pricing Sign In Get Started

Privacy Policy

Last updated: September 4, 2026

This policy explains, in plain language, how Leadpocket ("we," "us," or "our") handles information across our website and application (the "Service"). We built Leadpocket to be private by design — your workspace is yours alone, we collect only what the Service needs, and we never sell your data.

The short version

  • We don't sell your data. Ever — not lead data, not account data, nothing.
  • Your workspace is isolated. No Leadpocket customer can see another's leads.
  • No ad tech. No advertising trackers, no third-party ad cookies, no cross-site profiling.
  • You're in control. Export or delete your data — including your whole account — anytime from Settings.
  • Encrypted in transit and at rest, and we can't read your password.
  • We use a small, named set of providers (payments, bot protection, optional AI, and more) — listed in full below.

This policy has two parts, because two very different people read it. Jump to the one that fits you:

I use Leadpocket to collect leads You have an account and capture leads with intake forms. Covers your account, your leads, billing, our providers, security and your rights. I'm filling out a form You landed on a form powered by Leadpocket and want to know what happens to the details you enter, and who to contact.

Part A — For businesses that collect leads with Leadpocket

This part is for you if you have a Leadpocket account and use it to capture and follow up with leads. If instead you're a person filling out someone's form, read Part B.

1. What we collect 2. Cookies 3. How we use it 4. AI features 5. Providers & sharing 6. Retention & deletion 7. Security 8. E-signatures (NDAs) 9. Your responsibilities 10. Legal bases 11. International transfers 12. Your rights 13. Children

1. Information We Collect

Account information

When you create an account we collect your name and email address, and you set a password (which is protected so that we cannot read it). If you sign in with Google or Microsoft, we receive your name, email, and profile photo from them instead of a password. Optional profile details you add (company name, phone, photo, notification and AI-voice preferences) are stored to personalize the Service.

Lead data you collect

The Service exists so you can collect information about your leads — names, phone numbers, email addresses, and any custom answers you ask for in your intake forms, plus notes, tags, statuses, files, and outreach history you add. Alongside each lead we may store light context to help you organize and follow up: the form it came from, an approximate capture location derived from the visitor's IP (city/region/country — see providers below), the visitor's time zone, and marketing-attribution values (such as UTM tags or a referrer) when the form's link carried them. This data belongs to you. We store it solely to provide the Service to you, never use it for our own purposes, never sell it, and never share it with other users.

Partial and in-progress form entries

When someone opens one of your intake forms and begins entering information, the answers they type are transmitted to the Service and shown to you — the business that operates the form — as they are entered, and are retained by us on your behalf, even if the person does not press submit. This lets you see fills as they happen and recover started-but-unfinished entries (which we describe as "abandoned" fills) so that a genuine prospect isn't lost. If a visitor has already granted their browser's location permission to your form's page, an approximate map position may be included; we never prompt them for it. These partial entries are lead data that belong to you and are handled exactly like completed submissions: stored only to provide the Service to you, isolated to your workspace, never sold, and never shared with other users. Every intake form tells the person, at the point of entry, that their details go directly to the business operating the form and links to this policy. A visitor who does not want their information collected can simply close the form; as the operator, you are responsible for having an appropriate basis to collect and use this information (see Section 9).

Form analytics

So you can see how your forms perform, we record form views and submissions with a coarse channel (e.g. "QR code," "Instagram," "direct"). To count unique visitors without storing anyone's IP address, we keep only a salted one-way hash of the IP for de-duplication — the raw address is not retained for analytics.

Billing information

Payments are processed by Stripe. Your card details are entered directly on Stripe's secure checkout pages and never touch our servers. We store only your Stripe customer reference, your plan, and your subscription status.

Push notification subscriptions

If you enable push notifications, we store the push subscription endpoint your browser issues so we can deliver notifications to your device. You can remove it at any time from Settings.

What we do not collect

We do not use analytics trackers, advertising pixels, device fingerprinting, or third-party advertising cookies. We do not log your browsing behavior for marketing, and we do not build advertising profiles.

2. Cookies

We keep cookies to a minimum and use only first-party cookies — never third-party or advertising cookies:

  • Session cookie (essential) — keeps you signed in. It holds a random identifier only and is required for the Service to work.
  • Returning-visitor hint — a small, non-sensitive flag so that after your session expires we can send you to the sign-in screen rather than the marketing homepage. It is not used for tracking.
  • Referral attribution — if you arrive through a partner referral link, we set a single cookie for up to 60 days so we can credit the partner who referred you. It contains only the partner's referral code.

Your browser's local storage is also used for small device-side preferences (for example, remembering that you dismissed a notice, or briefly queuing a form submission you made offline). That data stays on your device.

3. How We Use Information

  • To provide, maintain, secure, and improve the Service.
  • To process subscription payments through Stripe.
  • To protect forms and accounts from bots and abuse.
  • To send push notifications you have explicitly enabled, and account or service emails (such as verification, password resets, and important notices).
  • To respond to support requests you send us.

We do not send marketing emails unless you opt in, and we never sell or rent personal information to anyone.

4. AI Features

If you use the optional AI features (AI-personalized outreach messages and the AI flow assistant), the relevant flow templates, your instructions, and the applicable lead's form answers are transmitted to our AI provider (Anthropic, USA) to generate the requested text, and are processed under their commercial terms — which do not permit the use of your data to train their models. AI features are entirely optional — if you don't enable them, no lead data is shared with the AI provider. Generated messages are always shown to you for review before anything is sent.

5. Service Providers & Data Sharing

We never sell your data and never share your leads with other Leadpocket users — every workspace is fully isolated. We share data only with the limited set of providers ("subprocessors") needed to operate the Service, each only for the purpose shown, and we may disclose information if required by law.

ProviderPurposeWhat it may receive
StripeSubscription paymentsYour billing details (entered on Stripe), plan and status
Cloudflare (Turnstile)Bot protection on sign-in and public formsA bot-check token and related request signals
IP-geolocation providerApproximate location from an IP addressA visitor's IP address, to return city/region/country
Lead-enrichment providerOptional lead enrichment (only when you run it)The public social handle you ask us to look up
AnthropicOptional AI features (see Section 4)Only the content described in Section 4, when enabled
Your browser's push service
(Google / Apple / Mozilla)
Delivering notifications you enabledThe encrypted notification and your push endpoint

Optional features (AI, enrichment, push) only involve their providers when you choose to use them. If you never enable them, no data goes to those providers.

6. Data Retention & Deletion

Your data is retained for as long as your account exists. You are always in control:

  • Export — download all of your leads as a CSV from Settings at any time.
  • Delete — delete individual leads, forms, or flows whenever you want.
  • Delete your account — from Settings, permanently and immediately erase your account and all associated leads, forms, flows, and notification subscriptions. This also cancels any active subscription.

Partial and in-progress form entries (Section 1) are kept only for a limited time so you can recover them: an unfinished fill is retained for up to about 30 days, after which it is automatically deleted if you have not converted it into a lead. In-progress and completed sessions that are not flagged as abandoned are cleared within a couple of hours. If you convert a partial entry into a lead, it is retained like any other lead until you delete it or your account.

7. Data Protection & Security

Protecting your data is fundamental to how Leadpocket is built. We take a layered, conservative approach so that your information stays safe both while it travels and while it is stored.

  • Encrypted in transit. All data exchanged between you and the Service is encrypted while it travels over the internet, so it cannot be read or tampered with on the way.
  • Encrypted at rest. Your data is encrypted while it is stored on our systems, so it stays protected even when it isn't actively being used.
  • Your password stays private. Passwords are protected in a way that means even we cannot read them.
  • Strict access isolation. Every workspace is walled off from every other. Your leads, forms, and flows are accessible only to your account, and we never expose one customer's data to another.
  • Trusted payment handling. Card payments are processed entirely by Stripe (certified to PCI-DSS Level 1, the highest standard in the payments industry). Your card details never touch our servers.
  • Protected notifications. Push notification content is encrypted end-to-end to your device under the Web Push standard.
  • Minimal by design. We collect only what the Service needs to function, which means there is simply less of your data to protect in the first place.

No method of transmission or storage can ever be guaranteed 100% secure, but we design defensively, collect minimally, and continually work to keep your information safe.

8. E-Signatures (NDAs)

If you use the NDA feature, you can send a document to a counterparty to sign electronically. To create a legally meaningful record, when someone signs we store the details they provide (such as their typed legal name, and email or title if requested), the signature image they draw, the exact text they agreed to, the date and time, and — as evidence of the signing event — their IP address and browser user-agent. This signing record belongs to you, is stored on your behalf, and is retained with your account until you delete it. As with leads, you are the controller of this data and are responsible for using the feature lawfully.

9. Your Responsibilities as a Lead Collector

When you collect leads through your intake forms, you are the controller of that data and we process it on your behalf as your processor. This includes both completed submissions and the partial or in-progress entries described in Section 1: because those answers are collected through your form and made available to you, you are the controller of them, and you are responsible for having an appropriate basis to collect, retain, and contact leads from that information. You are responsible for complying with the laws that apply to you (for example, the GDPR in the EU/EEA, and consumer-protection and anti-spam laws such as the TCPA and CAN-SPAM in the United States), including any disclosure or consent your own circumstances require before acting on a started-but-unfinished entry. If you are subject to the GDPR or similar laws, our Data Processing Agreement applies to and governs our processing of your lead data; it includes our list of subprocessors.

10. Legal Bases for Processing (EEA/UK Users)

Where the GDPR or UK GDPR applies, we process your personal data on these legal bases:

  • Contract (Art. 6(1)(b)) — your account data, billing status, and the lead data you store, all of which we need to provide the Service you signed up for.
  • Consent (Art. 6(1)(a)) — push notifications and optional AI features; you can withdraw consent at any time by disabling them.
  • Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing abuse (e.g. rate limiting and bot protection), and keeping required business records.
  • Legal obligation (Art. 6(1)(c)) — tax and accounting records connected to your subscription.

11. International Data Transfers

Our service providers may process data outside your country. Stripe (payments) processes data in the United States under the EU–US Data Privacy Framework and standard contractual clauses. If you enable the optional AI features, the content described in Section 4 is transmitted to Anthropic, which processes it in the United States; transfers from the EEA/UK are protected by standard contractual clauses, and we send only the minimum needed to generate the requested text. You can keep AI features switched off if you prefer that no lead data leaves your workspace. Other providers listed in Section 5 (for example, bot protection and IP-based location) may likewise process limited data internationally under appropriate safeguards. Push notifications are delivered by your own browser vendor's push service (e.g. Google, Apple, Mozilla).

12. Your Privacy Rights

Depending on where you live (including under the GDPR, UK GDPR, and US state laws such as the CCPA/CPRA), you have the right to:

  • Access the personal data we hold about you, and receive a portable copy (the in-app CSV export covers your lead data; we'll provide the rest on request);
  • Correct inaccurate data (your name, email, and workspace details are editable in Settings);
  • Delete your data (account deletion in Settings is immediate and complete);
  • Object to or restrict certain processing, and withdraw consent where processing is based on consent;
  • Not be discriminated against for exercising any of these rights. We do not "sell" or "share" personal information as defined by the CCPA/CPRA.

To exercise any right over your own account data, use the in-app controls or email support@leadpocket.io. We respond within the timeframe required by the applicable law (one month under the GDPR). If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

13. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.


Part B — For people filling out a form

You're reading this because you opened a form powered by Leadpocket and want to know what happens to the details you enter. Here it is in plain terms. If instead you run a business and collect leads with Leadpocket, read Part A.

In one line

The business that runs the form gets and controls your details — Leadpocket is just the software they use to collect and store them. To access or delete your information, contact that business.

Who has your information

The business that operates the form controls your information — not Leadpocket. Leadpocket is the software the business uses to run its form and store the responses. In privacy terms, that business is the "controller" of your data and we are its "processor": we hold the information on their behalf and only act on their instructions. We never use what you enter for our own purposes, never sell it, and never share it with anyone other than the business you filled the form out for.

What is collected

Whatever the form asks you for — which is chosen by the business, not by us. That typically includes things like your name and a way to reach you (phone or email), plus any other questions on that particular form. Along with your answers we record a little technical context so the business can organize and follow up: the date and time, an approximate location worked out from your device's internet (IP) address (roughly your city/region/country — not a precise address), and, where the link you arrived from provides it, a general indication of where your visit came from. If your browser has already granted the form's page permission to access your location, an approximate map position may also be included — but we never pop up a request for it.

Before you press "submit"

So the business doesn't lose a genuine enquiry, the answers you type into the form are sent and made visible to that business as you enter them — even if you never press submit. If you start a form and stop, the business may still see and keep what you had entered (we call this an "abandoned" entry) and may follow up with you. If you don't want the business to receive your details, don't enter them — you can simply close the form. Started-but-unfinished entries are kept for up to about 30 days and then automatically deleted unless the business saves them.

How your information is protected

Your submission travels over an encrypted connection and is stored encrypted on our systems. Each business's data is walled off from every other business's. To keep forms safe from bots, we may run a lightweight, invisible security check (provided by Cloudflare) when you open or submit a form. We collect only what the form needs to work — no advertising trackers, no third-party advertising cookies, and we don't build a marketing profile of you.

Your rights — and who to contact

You have rights over your personal information under laws such as the GDPR (EU/UK) and the CCPA/CPRA (California) — including to access, correct, or delete it, and to object to how it's used. Because the business that runs the form controls your data, please contact that business first — they are the ones who decide how your information is used and can action your request directly. If you're not sure who they are, they were identified on the form when you filled it out (the form states whose it is).

If you can't reach them, you can email us at support@leadpocket.io. We can't unilaterally hand over or delete a business's records, but as their processor we will forward your request to them and assist so it's handled.

Children

Forms powered by Leadpocket are not intended for children under 13. If you believe a child provided information through a form, contact the business that operates it (or us) and it will be removed.


Changes to This Policy

We may update this policy from time to time. Material changes will be announced in the app or by email to account holders. The "Last updated" date above always reflects the current version.

Contact

Questions about privacy? Email us at support@leadpocket.io. If you filled out a form and your question is about how your data is used, please also see "Your rights — and who to contact" in Part B above.

Leadpocket Capture leads anywhere. Close them everywhere.
How It Works Pricing FAQ Sign In Sign Up Terms of Service Privacy Policy Partner Terms
© 2026 Leadpocket. All rights reserved.

Cookies at Leadpocket: we only use essential, first-party cookies — one to keep you signed in, and, if you arrive through a partner referral link, one to credit that partner. No tracking, no ads, no third-party cookies. Privacy Policy