Last updated July 2026
Leadly ("we") is a platform for finding local jobs — used by teens, students, young adults, the people who hire them, and freelancers looking for local clients. This policy explains exactly what we collect, why, where it goes, and what control you have. Leadly currently serves the United States and Canada.
• Account: email, name, password (stored only as a secure hash by our auth provider), and optionally a phone number, business name, and profile photo.
• Job posts: title, description, pay, category, schedule, safety notes, an approximate location (a neighborhood or city name and, if you choose to attach it, approximate coordinates — never your exact address). The posting form doesn't currently collect photos; older posts may include them, and photos on a listing are publicly viewable. The email/phone typed into the posting form are used for your contact preference label only — they are not saved to our database and are never shown on a listing.
• Applications: your message, availability, age range (e.g. "Under 16", "16–17", "18+"), and experience. Your application is delivered to the job poster as an in-app message.
• Messages: the messages you send and receive in-app.
• Find Clients (freelancers): leads and businesses you save, notes, pipeline stages, and outreach you generate or send (including the recipient and content of outreach emails you choose to send).
• Reports & moderation: if you report a job, we store the reason and note with the reported post; moderation decisions (automatic and human) are recorded in an internal audit log.
• Security events: sign-ins, failed sign-ins, signups, and password-reset requests are logged with your email, IP address, and browser type to detect account attacks. Your legal acceptances (terms version, date, IP) are recorded with your account.
• Newsletter: the email you subscribe with and which article you subscribed from.
• Support: messages you send to support, with your account email as the reply address.
You can type a ZIP or postal code, or grant browser location permission — we use it to find jobs, businesses, and a readable city name near you. Your searching location is kept on your device (local storage), not in our database. The one place location is stored server-side is on content you create: a job post keeps its approximate coordinates and neighborhood text so nearby people can find it. We never collect background or continuous location.
To run the platform: show jobs near people, deliver applications and messages, send the emails you'd expect (welcome, password reset, new-message notification, security alerts), screen new job posts for safety, power moderation and anti-abuse systems, and understand product usage in aggregate. We do not sell your personal data, we do not run ads, and we do not build advertising profiles.
Job listings are visible to signed-in users and show your display name and approximate location — never your email, phone, or exact address; all contact happens through in-app messaging. Profile photos and job photos are stored in public image storage, which means anyone with the file's direct link can view it — don't upload a photo you wouldn't share publicly. Messages and applications are private between the two people involved.
Where a feature uses AI, we send our AI provider (Anthropic) only what the feature needs: the text of a new job post for safety screening; your skills, age range, city, and public business information for Find Clients scoring and outreach drafts; and a job name plus age for application tips. We never send your private messages, contact details, or account credentials to the AI provider. AI screening cannot reject a job by itself — it can only flag a post for human review. See the AI Policy for the full feature-by-feature breakdown.
Analytics are first-party and minimal: a pageview beacon records a random visitor id, the page path, coarse device type (e.g. iPhone/Android/Desktop), country, and referring site — no IP address is stored with analytics, and no third-party analytics or advertising scripts are loaded. Blog articles record anonymous reading events (scroll depth, helpful votes) tied to a random id, not your account. What never goes into analytics: precise location, addresses, phone numbers, message contents, or your search text. You can turn analytics off anytime in Settings → Notifications → "Help improve Leadly with basic usage analytics."
Leadly uses only essential, first-party cookies: the session cookies that keep you signed in, and a short-lived cookie that remembers where to return you after sign-in. There are no advertising or third-party analytics cookies. Preferences like theme, language, and your saved search location live in your browser's local storage, on your device. Details are in the Cookie Policy.
We share data only with the processors needed to run Leadly, each limited to its function: Supabase (accounts, database, file storage), Anthropic (AI features, as above), Google (Maps, and Places searches — your search area is sent to return nearby businesses), Resend (sending email), Cloudflare (network security and the sign-up CAPTCHA, which processes your IP to tell humans from bots), and Vercel (hosting, which derives the country used in analytics). If paid plans are enabled, Stripe processes payments — card details go to Stripe directly and never touch our servers. We disclose information if required by law or to protect users' safety, and we may share aggregate statistics that identify no one.
Your content and account data are kept while your account exists. We don't currently apply automatic expiry to logs and analytics, so they are retained until deleted or until we adopt a retention schedule; security logs are kept to protect accounts even after deletion (see below).
Settings → Delete account permanently deletes your login, profile, applications, conversations and messages, saved leads and clients, outreach history, and support requests. Job posts you created are anonymised rather than deleted: the description, location, coordinates and pay are erased, the post is archived so it no longer appears anywhere on Leadly, and it is unlinked from you — the emptied record is kept only so people who applied to it keep their own application history. A few other things are not removed by account deletion: security logs (sign-in events with email, IP, and browser type — kept to investigate attacks and fraud), moderation audit records (kept for accountability of enforcement decisions), anonymous analytics (which don't identify you), and the newsletter list (managed separately — email us to unsubscribe or be removed). Uploaded photo files may also persist in storage after deletion; email us and we'll remove them. Messages you sent to other people were delivered to them, like email, and deletion doesn't recall them from the recipient's view.
You can edit your profile in Settings, delete your account yourself, turn analytics off, and control email notifications. To request a copy of the personal data we hold about you (or correction of it), email [email protected] from your account email — there is no self-serve export button yet, so we fulfill these requests manually. We will never discriminate against you for exercising privacy rights.
Leadly is not for children under 13, and we don't knowingly collect their data — if we learn an account belongs to a child under 13, we will delete it. Teens 13–17 may use Leadly with a parent or guardian's permission. Parents and guardians can contact us at [email protected] to review what information we hold about their teen, have it corrected or deleted, or have the account closed. The Parent & Guardian Guide explains what teens share on Leadly and the safety features that apply.
California law gives you the right to know what personal information we collect (this policy is that disclosure), to access it, to correct it, to delete it, and to not be discriminated against for exercising those rights — use Settings or email us as described above. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" opt-out to make. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
If you are a California resident under 18, you may request removal of content you posted on Leadly by deleting it in the app or emailing us. Removal applies to content you posted; it may not extend to copies delivered to other users (like sent messages) or records we're required to keep, and it does not guarantee complete removal from all systems where the law does not require it.
Leadly serves the United States and Canada. For Canadian users, we handle personal information consistent with PIPEDA principles — collection limited to what the feature needs, use limited to the purposes above, and access/correction available on request. Data is processed on servers in the United States. If you use Leadly from elsewhere, you understand your data is processed in the US.
Everything is served over HTTPS. Database access is protected with per-user row-level security — your private rows are readable only by you; internal logs are reachable only by our servers, never from a browser. Secret keys stay server-side. Sign-in is protected by rate limiting, attack detection with alert emails, and an optional CAPTCHA. Admin access is restricted to an allowlist, admin views mask user emails, and administrators never read message contents in analytics. No system is perfectly secure — if we learn of a breach affecting you, we will notify you as the law requires.
We'll update this policy as Leadly evolves and change the date above; material changes will be flagged in the app. Questions or requests — including privacy, access, correction, and deletion requests: [email protected]. See also the Data Requests page and Account Deletion page.