Legal
Privacy Policy
This privacy policy explains what data Leadbuild processes, how we safeguard it, and the choices you have regarding your information. It serves as a summary of our operational practices and should be reviewed alongside your executed master agreement and Data Processing Addendum.
Current version
Last updated · July 2026This privacy policy explains what data Leadbuild processes, how we safeguard it, and the choices you have regarding your information. It serves as a summary of our operational practices and should be reviewed alongside your executed master agreement and Data Processing Addendum.
Data we process
Leadbuild processes the raw source materials you upload, sync, or connect to your workspaces. This includes, but is not limited to: customer interview transcripts, raw survey records, help desk exports, website URLs, marketing guideline PDFs, and ad performance history. We process this data to perform semantic search, locate exact quote spans, and generate citation-verified briefs. All raw source assets, vector database indexes, and cached text segments are stored in isolated, containerized tenant environments dedicated exclusively to your organization.
How we use and isolate your data
Your data is used solely to extract insights, verify claims, and build briefs for your own business or designated clients. We enforce strict logical isolation between tenant databases at the storage and application layers. Furthermore, Leadbuild guarantees that your proprietary source materials and approved campaign briefs are never used to train or fine-tune public LLMs. For organizations with high security standards, our architecture supports local model routing: you can direct processing tasks to local model deployments (such as Llama models) running entirely within your secure cloud boundary, ensuring that raw data never leaves your environment.
Sub-processing and third-party APIs
To perform advanced summarization and semantic mapping, we route processing requests to designated LLM sub-processors over secure, encrypted channels. If you configure model routing to external API providers, those providers act as sub-processors under strict confidentiality commitments. When you link outbound marketing channels (such as Meta Ads or Google Ads API), Leadbuild only transmits the specific approved parameters (e.g., ad copy, creative brief summaries, and targeting definitions) that you have explicitly approved through our review workbench.
Retention and the erasure cascade
We retain source materials and campaign records only for as long as your tenant account remains active, or as specified in your agreement. You can trigger the forget-customer cascade at any time. When initiated, this cascade identifies and deletes all raw files, extracted text blocks, vector indexes, generated draft summaries, and proposed briefs associated with that customer. Deletion is propagated across active databases and cached records within 30 days of the request, with backups rotated out according to our standard retention schedule.
Contact & Data Protection Officer
If you have questions about our data handling practices, tenant isolation mechanisms, or wish to exercise your data access rights, please email our security and privacy compliance team at privacy@leadbuild.pro. Our corporate headquarters and security operations team can be reached via mail at Leadbuild Security Operations, 100 Pine Street, San Francisco, CA 94111.
For security architecture, isolation, and erasure details, visit our security overview.