Last updated · 22 August 2026

Privacy Policy

This policy covers the Leemen app, Leemen-operated services, and their interaction with Telegram and other providers. It explains what is processed on your device, what goes to Telegram, and what Leemen receives.

The key point. Leemen has three distinct data-processing contexts: your device, Telegram services, and Leemen services. Leemen is an independent Telegram client, so messaging, contacts, calls, media, and location features use Telegram infrastructure and are also governed by the Telegram Privacy Policy. Leemen’s own backend does not receive the contents of your Telegram chats or your address book through the Leemen API, but the app itself accesses them and sends selected data to Telegram to provide features you request.

1 · Who we are and scope

The Leemen app (Android package app.leemen.android), the leemen.app website, and Leemen-operated server services are built and maintained by Leemen Software, TOO (a Kazakhstan LLP), referred to as “Leemen”, “we”, or “us”. We are responsible for processing within our own services as described below. For privacy questions, contact support@leemen.app.

Leemen uses the Telegram API but is not affiliated with, endorsed by, or operated by Telegram. Telegram processes Telegram account and communications data as an independent controller under its own terms and Privacy Policy. Bot and Mini App developers, websites you visit, merchants, and payment organizations may likewise be independent controllers of their services.

This policy covers Leemen features, including those inherited from the Telegram client, Private Space, the Leemen account and subscription, the website, and support. It does not replace Telegram’s policy or the policy of a third-party service you choose to use.

2 · How data is processed

Access on the device does not always mean Leemen receives the data on its servers. For example, biometric verification is performed locally by Android, and Android account names are read locally only to let you choose where to save a contact.

3 · Data processed by Telegram

To operate as a Telegram client, the app may process and send Telegram the following categories:

Ordinary Telegram cloud chats are stored in the Telegram cloud and are not end-to-end encrypted in the same way as Secret Chats. Secret Chats use end-to-end encryption between devices. Telegram determines retention, recipients, international transfers, and deletion for this data; see the Telegram Privacy Policy.

Deleting your Leemen account does not delete your Telegram account or Telegram cloud data. Use Telegram’s separate deletion controls for that purpose.

4 · Access to device data and features

Leemen asks for permissions in the context of a feature. If you refuse, that feature may be unavailable, but the app should not access the data without the relevant Android permission.

Data or accessHow it is usedWho may receive it
Contacts and Android accountsNames and phone numbers for contact discovery/sync; Android account names and types locally to choose where to save a new contactTelegram; the system contact provider you select when saving a contact
Photos, videos, audio, files, and documentsSelect, view, edit, send, save, or cast material you chooseTelegram, a selected chat/bot/Mini App, a connected Chromecast device, or another recipient you choose
Camera and microphonePhotos/video, QR codes, voice/video messages, calls, stories, Passport, bots, and Mini AppsTelegram, call/chat participants, a bot, Mini App, or website after your permission
Screen sharingShare a selected screen during a call or broadcastTelegram and the participants of the selected call/broadcast
Phone, call log, and call stateNumber autofill, pausing audio during a cellular call, and, when Telegram offers this method, login verification by incoming flash call: the app detects that call number and timeOrdinary call state is processed locally; a login or verification number is sent to Telegram
Bluetooth and connected devicesAudio routing and headset display; Wear/Chromecast interaction you chooseThe paired or selected device
ClipboardPaste a code, link, or text; a Mini App can read clipboard text only after a recent user action in a permitted flowThe recipient into which you paste or send it; the Leemen backend does not automatically receive your clipboard
BiometricsLocal app or private-area unlockChecked locally by Android; Leemen does not receive your biometric template
NotificationsDeliver messages, calls, and active-feature statusTelegram, Firebase Cloud Messaging, and paired devices according to OS settings

Files may contain EXIF and other metadata. When you send an original file, that metadata may remain and become available to the recipient. Android system backup may also save limited settings or app-state tokens with the backup provider configured on your device; your Android settings and that provider’s policy apply.

5 · Location and media geotags

Leemen may access approximate or precise location only after Android permission and only for features you initiate:

Background location is used only when you explicitly start Live Location for a period you choose. It keeps updates working while Leemen is minimized, the screen is locked, or the app is otherwise not in use. Coordinates, accuracy, heading, and related parameters are sent to Telegram and become available to participants in the selected chat. A persistent notification is shown while sharing. You can stop Live Location in the app at any time or revoke permission in Android settings. Leemen does not use GPS location for its own advertising or product analytics.

Android’s media location permission allows Leemen to read the GPS geotag of a photo or video you select. In the story location picker, the app immediately uses those coordinates to search for nearby places and sends them to Telegram and the configured Telegram venue-search bot; the selected map or geocoding provider may also process them. Chat participants or story viewers receive the location you select only if you continue sending or publishing. A GPS geotag may also remain in the metadata when a file is sent as an original.

Depending on the feature and settings you select, current coordinates or the coordinates in a message may be received by Telegram, chat participants, the configured bot, a Mini App/website, Google Maps/Fused Location, Yandex Maps, or another selected map provider. Their own policies apply. The country inferred from IP when a Leemen account is created is a separate technical signal and is not GPS location.

6 · Data received by Leemen

Leemen-operated services do not receive Telegram message text, your address book, call content, or your Telegram session through the Leemen API. They process the following data:

CategoryWhat it is and whyRetention
Telegram loginSigned Telegram login data: Telegram ID and, if Telegram includes them in the payload, name, username, language, photo, and Premium flag. The payload is verified for authentication; Telegram ID links the accountsTelegram ID until account deletion; the one-time replay-protection hash becomes eligible for deletion after 2 hours and is normally removed by the next daily job
Leemen account and sessionInternal master/sync UUIDs, privacy mode, and creation/update times. A signed token containing identifiers is stored on the device and normally lasts up to 30 daysAccount record until deletion; token until expiry, sign-out, or account deletion
Email, if the feature is availableAn address you voluntarily provide for recovery or supportUntil the address/account is deleted or the request is resolved, subject to lawful retention
DevicesInternal device ID, name/model, platform, Ed25519 public key, registration time, and last-seen timeUntil account deletion
IP, country, and localizationThe network infrastructure provider processes the IP of each API request to deliver it. On first account creation, the full signup IP, the country inferred from it, and the localization decision are storedFirst-signup record until account deletion; network logs according to infrastructure-provider schedules and security needs
Encrypted syncEncrypted Private Space blobs: selected dialog/message IDs and state, pins, private-search IDs, PIN hash/salt, timeout, screenshot and UI settings; nonce, version, and update time. Telegram message text and media are not added to these blobsUntil account deletion
Key materialProtected/wrapped copies of the master key and device public keys; the form depends on privacy modeUntil account deletion; residual copies may remain in backups until rotation
Consent historyConsent type, grant or withdrawal, text/policy version, locale, and timestampUntil account deletion to apply your choice and evidence consent
Subscriptions and promo codesProvider, product, status, expiry, purchase/subscription/original transaction ID or token, Leemen UUID binding, and promo redemptionUntil account deletion, or longer when required for accounting, disputes, fraud prevention, or law
Security eventsA limited set of account/login/device/purchase events without message content; separate infrastructure logs may contain IP, request time/route/status, Telegram/account/device/subscription identifiers, and technical error detailsCurated log normally up to 90 days; infrastructure logs according to provider schedules and legal needs
Support correspondenceEmail, Telegram username/ID, message text, and attachments you sendWhile handling the request and then as reasonably needed to document resolution, protect security, and meet legal duties

7 · Private Space and encryption

A working copy of Private Space state exists on your device within the app sandbox. On supported Android versions, key material is additionally protected with Android Keystore; for compatibility, a Keystore failure or an older Android version can fall back to app storage. We therefore do not claim that every local copy is always hardware-encrypted.

Sync data is encrypted on your device before being sent to Leemen. The selected mode determines who can technically obtain the key:

Default mode

The backend stores the master key in a form protected by server-side KMS/Vault, can unwrap it, and sends it only to an authenticated client over TLS. Consequently, in Default mode Leemen is technically capable of decrypting synchronized blobs. We do not use this ability to read data in ordinary operation, but it exists, for example to restore access on a new device.

Maximum-privacy mode

The active database stores copies of the key wrapped with a password and/or recovery phrase. Without your secret, the active records do not let Leemen unwrap the key. If your account previously used Default mode, Leemen previously processed a server-recoverable copy of the same key, and that copy may remain in backups until they rotate. If you lose both the password and recovery phrase, the data may be impossible to recover.

The Kazakhstan copy may contain encrypted blobs and wrapped key material, but it does not contain the server KMS secret or your password/recovery phrase; that copy alone is insufficient to decrypt the data.

8 · Analytics, diagnostics, push, and website

Optional Leemen product analytics

This is off by default and starts only after your separate choice. When enabled, the app sends random install/session UUIDs, an internal Leemen account ID after login, timestamps, app version/build, and events from a fixed allowlist with limited properties. Examples include first app open, signup and one-time-code stages, setup completion, Private Space onboarding stage, paywall placement and selected option, and purchase-flow start. The install ID does not contain a Telegram ID, but may be linked to the Leemen account after login so events can be attributed and deletion requests honored. Message contents, contacts, the list of hidden chats, and GPS coordinates are not added to Leemen product events.

When Leemen attribution is enabled, Leemen receives the raw install referrer, campaign/click/source ID, and install ID. Separately, opening a go.leemen.app campaign link creates a random click ID and may record campaign code, inferred platform, and time before the app is installed; that click does not itself include a Telegram ID, but may be linked to an installation/account after attribution consent.

Turning analytics off stops future sending by the client. Raw events and attribution records have a retention target of about 90 days; cleanup runs as a maintenance operation, so this is not a guaranteed automatic deadline for every record. The install-to-account link and activity date may remain until account deletion so deletion and metric integrity can be supported. After deletion, individual campaign-link click records not linked to an account (random click ID, campaign code, inferred platform, and time) may remain until their next cleanup, together with derived aggregate metrics.

Firebase and Google services

See Firebase privacy and security information and the Google Privacy Policy.

The Leemen website

When you visit leemen.app, the hosting provider receives ordinary HTTP request data, including IP, user agent, URL, and time. The website analytics service automatically produces aggregated page-view statistics: page path, filtered parameters, referrer, approximate IP-derived geography, OS, browser, and device type. In the current configuration, this analytics does not use cookies and discards its visitor-session hash after 24 hours; aggregated data may be retained according to the provider’s service periods. Your light/dark theme preference is stored locally in the browser.

9 · Bots, Mini Apps, the in-app browser, and external sites

Bots, Mini Apps, and websites are independent third parties. They may receive Telegram context and data you send or separately allow: messages, profile information, files, contacts, precise/approximate location, camera, microphone, and clipboard. For sensitive access, Leemen presents a prompt in the context of that origin. Review the bot/site policy before providing data; Leemen and Telegram do not control an independent recipient’s later processing.

The in-app browser stores URL, time, and page metadata, cookies, cache, and web storage on the device until cleared. Websites receive IP, requests, cookies, and data you enter. Address-bar text may be sent to the selected search provider (such as Google, DuckDuckGo, Bing, Yahoo, or Brave) for suggestions and results. Browser settings let you clear history, cache, and cookies.

Translation, speech recognition, Passport, weather/venue bots, external maps, and other Telegram features may send selected text, audio, documents, or coordinates to Telegram and providers identified by it; their policies and the Telegram Privacy Policy apply.

10 · Payments

Leemen subscriptions are processed by Google Play, the Apple App Store, or, where available, Tribute. Leemen does not receive your card number. Leemen receives and stores data needed to verify access: product ID, purchase/subscription token or transaction ID, source, status, expiry, and a binding to the Leemen account. Google Play receives the Leemen account UUID as an obfuscatedAccountId, and Apple receives it as an appAccountToken. For a Tribute subscription, the provider sends Leemen the payer’s Telegram ID, subscription ID, and expiry. The payment provider keeps its own records under its policy.

Payments inside Telegram bots are separate from a Leemen subscription. If you choose to provide them, Telegram, the merchant, and its payment provider may receive your name, phone number, email, delivery address, and tokenized payment information. Card details are handled by the selected payment provider, such as Stripe or Google Pay, not the Leemen backend.

Deleting your Leemen account removes linked Leemen entitlement records but does not necessarily cancel an active subscription or delete app-store/payment-provider records. Cancel separately through Google Play, the App Store, or Tribute.

11 · Recipients and providers

We do not sell personal data. Leemen’s own analytics is not used to sell data or provide it to advertisers; campaign data is used to measure promotion of Leemen.

12 · Purposes and legal bases

Depending on applicable law, we process data:

You can revoke an Android permission in device settings. You can withdraw Leemen analytics consent in the app; this does not disable Telegram functions required for the service or Crashlytics, which is always enabled in the current release build.

13 · Where data is processed

Leemen’s primary account database is hosted in the European Union. Providers listed in section 11 may process data globally in their own regions and data centers.

When an account is first created, a country is approximately inferred from the IP address. This value is fixed for localization and may not match citizenship or actual residence because of VPN, Tor, travel, or network behavior. Leemen does not request or verify citizenship.

Telegram, Google, app stores, infrastructure providers, and other independent services determine processing locations under their own policies. We use contractual and technical international-transfer safeguards where required.

14 · Retention and deletion

You can delete a Leemen account in the app through Settings → Search → “Delete account” or, without the app, on the Delete your account page. Account-linked data, devices, encrypted sync, consents, the localization record, entitlement/promo records, and the linked analytics footprint are removed from the active primary database; replica deletion propagates asynchronously. Deletion does not cover raw campaign clicks not linked to the account and derived aggregate metrics until their next cleanup, technical anti-replay/payment identifiers (for example, processed Apple notification IDs) reasonably needed to prevent duplicate processing or meet legal duties, data in backups/logs that have not yet rotated, or independent-provider data. To remove local copies on other devices, sign out or clear app data/uninstall on those devices.

Deleting Leemen does not delete your Telegram account or cancel a subscription with a payment provider.

15 · Your rights and controls

Depending on applicable law, you may request access, correction, a portable copy, restriction, objection, deletion, or withdrawal of consent. You may also complain to the competent data-protection authority.

Self-service controls include:

For deletion of selected data or another request, email support@leemen.app. We may securely verify your identity. We respond within the time required by applicable law, ordinarily within one month, subject to lawful extension for a complex request.

16 · Security

We use TLS in transit, server-storage encryption, access controls, least privilege, separate device keys, and auditing for sensitive operations. Encrypted Private Space blobs do not contain the plaintext working state, but Leemen’s ability to unwrap the master key depends on the selected mode as explained in section 7.

No system can guarantee absolute security. If a personal-data incident occurs, we take steps to contain it and notify users and authorities where required by law.

17 · Children

Leemen is not directed to children under 16, and we do not knowingly collect their data. If we learn of such an account, we will take steps to remove associated data, subject to legal requirements and Telegram procedures.

18 · Changes to this policy

We update this policy when the app, providers, or requirements change. The revised text and date are published on this page. We provide notice and request a fresh user choice for material changes when and in the manner required by applicable law. You may request a previous version by email.

19 · Contact

Leemen Software, TOO · support@leemen.app