Last updated · 19 July 2026
Privacy Policy
Leemen is a privacy-first messaging client. This policy explains, in plain language, exactly what the Leemen backend stores, what it can and cannot see, and the rights you have over your data.
The short version. Leemen never stores your messages, contacts, or media — those stay between you and Telegram. Our backend only handles three things: your subscription, promo codes, and an encrypted sync of your private settings. You can delete everything you have with us at any time, from inside the app or via this page.
1 · Who we are
The Leemen app and backend are built and operated by Leemen Software, TOO (Kazakhstan LLP), referred to here as “we”. We are responsible for how the personal data described here is handled. For privacy questions or to exercise your rights, contact us at support@leemen.app.
Leemen is an independent Telegram client: it uses Telegram’s API and is part of the Telegram ecosystem, but is not affiliated with, endorsed by, or operated by Telegram. “Telegram” is a trademark of its respective owner, used here only to describe what Leemen works with.
Why we process your data, and where. We process your data to provide the service (your account, devices, and sync), with your consent where you give it (such as an optional recovery email), and to keep the service secure and free of abuse. Some of the providers we rely on operate in other countries; wherever your data is processed, we require appropriate safeguards and contractual protections so it stays protected — see Where your data lives for exactly where it is stored.
On what basis. We handle your account, device, and sync data because it is needed to give you the service you asked for. We keep your optional recovery email, run product analytics, and record install source only with your permission, which you can withdraw at any time. We keep the short security log to protect the service from abuse, which is our legitimate interest.
2 · Identity & how login works
A Leemen account is not the same thing as your Telegram account — it is a separate record we keep, linked to your Telegram account.
When you sign in, Leemen uses Telegram’s official sign-in to confirm your Telegram account, and we create or look up a Leemen account linked to it. We do not receive or store your phone number, your Telegram password, or your Telegram session.
Optionally, you may add an email address for account recovery. It is stored only if you choose to provide it.
3 · What we store
Everything our backend holds, and why:
| Data | What it is | Why | Retention |
|---|---|---|---|
| Telegram account ID | An identifier from your Telegram sign-in | To identify your account across devices | Until you delete your account |
| Email (optional) | Only if you add one for recovery | Account recovery | Until removed / account deletion |
| Device records | A per-device entry — device name, platform, last-seen time | Multi-device sync & security | Until the device is removed / account deletion |
| Encrypted sync data | Your private settings and content — encrypted on your device | Sync across your devices | Until account deletion |
| Subscription & promo records | Whether you have Premium, its source and expiry; redeemed promo codes | To unlock paid features | While active + as required for records |
| Security audit log | Discrete events (account created, failed login, device added, purchase) — no IPs, no payloads | Abuse & fraud protection | 90 days |
| Product analytics | App-usage events — collected only if you turn it on (off by default). See §6 | To improve the app | 90 days |
4 · Privacy modes
Your private synced data (your settings and related content) is always encrypted on your device before it reaches us. You choose how the encryption key is managed:
Default mode
Your encryption key is kept on our backend in protected form so we can restore it to a new device after you log in — no password to remember. The honest consequence: in this mode we are technically able to decrypt your sync data. We do not do so in normal operation, but you should know it is possible (e.g. under a valid legal order). The contents are still your settings and private content only — never message contents.
Maximum-privacy mode (optional)
Your encryption key never leaves your device in readable form. We keep only protected copies that can be unlocked solely with your password or recovery phrase — which we do not have. In this mode we cannot decrypt your sync data at all. The trade-off: if you forget both your password and your recovery phrase, that data is unrecoverable.
5 · What we never store or see
- Your messages, chats, contacts, or media — these are exchanged directly with Telegram and never pass through Leemen’s backend.
- Your Telegram session or phone number.
- The contents of push notifications. Push is delivered directly from Telegram’s servers to your device through the platform’s push service; our backend is not in that path and has no access to it.
6 · Analytics & attribution
Product analytics is off by default. We collect in-app usage analytics only if you turn it on in Settings → Privacy, and you can turn it back off at any time. While it is on:
- A random install identifier is generated on first launch. It is not your identity and is not your Telegram ID.
- We record only a fixed allowlist of app events (e.g. “onboarding completed”, “paywall viewed”). Anything not on the allowlist is dropped — there is no free-form or message-derived data.
- It contains no message content and no IP addresses, lives in a separate store, and is deleted after 90 days.
Install source. Only if you opt in — it’s off by default, the same kind of choice as analytics — we record once which campaign link brought you, for our own marketing. It tells us the campaign, never who you are; if you don’t opt in, we don’t record it.
We don’t profile you, and we don’t make any decision about you by purely automated means.
7 · Payments
If you buy a paid feature, the payment is handled by a third-party payment provider — Leemen never receives or stores your card details. In most regions this is your app store (Apple App Store or Google Play). Where app-store billing is unavailable (for example, Russia), the payment is instead handled by Tribute (tribute.tg) through Telegram: Tribute processes your card payment and sends us only a record of the subscription, linked to your Telegram account. In either case we keep only a record that the purchase is active, so the feature stays unlocked.
8 · Who processes your data
The providers we use to run the service are Supabase (hosting and our database), Cloudflare (content delivery and security), the Apple App Store and Google Play (billing for paid features), and Tribute (tribute.tg — payment processing in regions where app-store billing is unavailable, such as Russia). Some providers act as independent controllers for their own services, including billing, and process data under their own terms and privacy notices; where a provider processes personal data on our behalf, we use appropriate contractual protections. See the privacy notices for the App Store, Google, and Tribute. We keep this list current — email support@leemen.app for the latest. We do not sell your data, and we do not share it with advertisers.
9 · Where your data lives
Your data is kept in one place by default: our main database, hosted in the European Union (Ireland), under European data-protection rules. Where else it goes depends on where you were when you signed up:
- If you signed up in Kazakhstan: your data lives on our EU database, and a copy of your account data is also kept on a database in Kazakhstan, as local rules require. Your synced settings and content are encrypted before they leave your device, with the keys held outside Kazakhstan, so that copy stays protected.
- If you signed up in the EU, the EEA, or the UK: your account data stays on our EU database and is never copied to Kazakhstan. The limited technical data processed by the service providers listed in Who processes your data stays under the contractual safeguards described there.
- If you signed up anywhere else: your data is stored on our EU database, under European protection — we don’t keep a copy in your home country.
Wherever your data is stored, it is protected by the same encryption and the same contractual safeguards described in this policy.
10 · Your rights
Wherever you live, you can ask us to show you your data, correct it, give you a copy you can take elsewhere (in a standard, machine-readable format), limit or object to how we use it, delete it, or withdraw a permission you’ve given. You can also complain to a data-protection regulator — usually the one where you live or work, or where you think the problem happened (in the UK, that’s the ICO).
You can delete everything yourself: from inside the app via Settings → Delete account, or — without needing the app — from the Delete your account page, where you just sign in with Telegram. Deletion is immediate and permanent. For any other request, email support@leemen.app. We’ll reply as soon as we can, and within one month at the latest; if a request is unusually complex we may need up to two more months, and we’ll tell you why within the first month.
11 · Retention
Account data lives until you delete your account. Security-audit and analytics data are automatically purged after 90 days. Deleting your account erases your account and the devices and settings linked to it, along with your analytics footprint; aggregate, non-identifying counters (e.g. the total number of clicks on a campaign link) may remain as they are no longer linked to you.
12 · Security
Your sync data is encrypted on your device with modern, well-established cryptography before it ever reaches us. In maximum-privacy mode it is end-to-end encrypted — only you hold the key, and we cannot decrypt it; in default mode it stays encrypted in transit and at rest, but we hold the key in protected form, so we are technically able to decrypt it (see Privacy modes). Our systems are built around strict access controls and least privilege, and we never expose payment or key material to client apps. No system is perfectly secure, but privacy is the default in how we build Leemen.
If a security incident ever affects your personal data, we will act quickly to contain it, notify the relevant regulator as the law requires, and tell affected users without undue delay.
13 · Children
Leemen is not directed to children under 16, and we do not knowingly collect their data. If we learn that we have data from someone under 16, we delete it.
14 · Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, surfaced in the app.
15 · Contact
Leemen Software, TOO (Kazakhstan LLP) · ulitsa Qarasai Batyr 40, Talgar, Almaty Region, 041602, Kazakhstan · +7 706 633 62 56 · support@leemen.app