Last updated · 22 August 2026
Privacy Policy
This policy covers the Leemen app, Leemen-operated services, and their interaction with Telegram and other providers. It explains what is processed on your device, what goes to Telegram, and what Leemen receives.
The key point. Leemen has three distinct data-processing contexts: your device, Telegram services, and Leemen services. Leemen is an independent Telegram client, so messaging, contacts, calls, media, and location features use Telegram infrastructure and are also governed by the Telegram Privacy Policy. Leemen’s own backend does not receive the contents of your Telegram chats or your address book through the Leemen API, but the app itself accesses them and sends selected data to Telegram to provide features you request.
1 · Who we are and scope
The Leemen app (Android package app.leemen.android), the leemen.app website, and Leemen-operated server services are built and maintained by Leemen Software, TOO (a Kazakhstan LLP), referred to as “Leemen”, “we”, or “us”. We are responsible for processing within our own services as described below. For privacy questions, contact support@leemen.app.
Leemen uses the Telegram API but is not affiliated with, endorsed by, or operated by Telegram. Telegram processes Telegram account and communications data as an independent controller under its own terms and Privacy Policy. Bot and Mini App developers, websites you visit, merchants, and payment organizations may likewise be independent controllers of their services.
This policy covers Leemen features, including those inherited from the Telegram client, Private Space, the Leemen account and subscription, the website, and support. It does not replace Telegram’s policy or the policy of a third-party service you choose to use.
2 · How data is processed
- On your device. The app stores your Telegram session, local database and cache, settings, in-app browser history, and a working copy of Private Space state within the app’s isolated storage. You can remove parts of this data through settings, sign-out, cache/app-data clearing, or uninstalling the app.
- Through Telegram. Your phone number and login data, Telegram profile, contacts, messages, media, calls, location, and other communications data are sent directly to Telegram when required by a feature you choose.
- Through Leemen. Leemen’s separate backend processes a Telegram identifier to link your account, device records, encrypted Private Space sync, consent history, localization and security signals, subscriptions, and — if you allow it — product analytics.
- Through providers. Google/Firebase, server/network infrastructure and hosting providers, app stores, Tribute, map providers, websites, bots, and other services receive data needed for the relevant feature or data you choose to provide to them.
Access on the device does not always mean Leemen receives the data on its servers. For example, biometric verification is performed locally by Android, and Android account names are read locally only to let you choose where to save a contact.
3 · Data processed by Telegram
To operate as a Telegram client, the app may process and send Telegram the following categories:
- Registration and login: phone number, one-time code, two-step-verification data and, if that method is selected, a Google sign-in token. Your Telegram password goes to Telegram, not to the Leemen backend.
- Profile and account: Telegram ID, first and last name, username, phone number, profile photo, language, Premium status, and account settings.
- Communications: messages, drafts, media, files, voice and video messages, contacts/vCards, reactions, polls, stories, group and channel information, call data, and other information you create or send.
- Contacts: with your permission, names and phone numbers from your address book are uploaded to Telegram to find people you know and synchronize contacts. You can turn contact sync off and delete previously synced contacts in privacy settings.
- Technical data: IP address, device model and manufacturer, Android and app version, languages, time zone, network state, push token, installation and app identifiers, and diagnostics needed to operate and secure Telegram.
- Install source: a legacy Telegram mechanism may receive the Google Play install referrer, store it locally, and send it to Telegram independently of the Leemen product-analytics setting.
- Calls: microphone, camera, call signaling, and call diagnostics. A direct P2P connection may reveal your IP address to the other participant; P2P can be limited in Telegram privacy settings.
- Push notifications: a registration token and encrypted push envelope pass through Firebase Cloud Messaging. The Leemen backend does not receive the contents of Telegram push notifications.
Ordinary Telegram cloud chats are stored in the Telegram cloud and are not end-to-end encrypted in the same way as Secret Chats. Secret Chats use end-to-end encryption between devices. Telegram determines retention, recipients, international transfers, and deletion for this data; see the Telegram Privacy Policy.
Deleting your Leemen account does not delete your Telegram account or Telegram cloud data. Use Telegram’s separate deletion controls for that purpose.
4 · Access to device data and features
Leemen asks for permissions in the context of a feature. If you refuse, that feature may be unavailable, but the app should not access the data without the relevant Android permission.
| Data or access | How it is used | Who may receive it |
|---|---|---|
| Contacts and Android accounts | Names and phone numbers for contact discovery/sync; Android account names and types locally to choose where to save a new contact | Telegram; the system contact provider you select when saving a contact |
| Photos, videos, audio, files, and documents | Select, view, edit, send, save, or cast material you choose | Telegram, a selected chat/bot/Mini App, a connected Chromecast device, or another recipient you choose |
| Camera and microphone | Photos/video, QR codes, voice/video messages, calls, stories, Passport, bots, and Mini Apps | Telegram, call/chat participants, a bot, Mini App, or website after your permission |
| Screen sharing | Share a selected screen during a call or broadcast | Telegram and the participants of the selected call/broadcast |
| Phone, call log, and call state | Number autofill, pausing audio during a cellular call, and, when Telegram offers this method, login verification by incoming flash call: the app detects that call number and time | Ordinary call state is processed locally; a login or verification number is sent to Telegram |
| Bluetooth and connected devices | Audio routing and headset display; Wear/Chromecast interaction you choose | The paired or selected device |
| Clipboard | Paste a code, link, or text; a Mini App can read clipboard text only after a recent user action in a permitted flow | The recipient into which you paste or send it; the Leemen backend does not automatically receive your clipboard |
| Biometrics | Local app or private-area unlock | Checked locally by Android; Leemen does not receive your biometric template |
| Notifications | Deliver messages, calls, and active-feature status | Telegram, Firebase Cloud Messaging, and paired devices according to OS settings |
Files may contain EXIF and other metadata. When you send an original file, that metadata may remain and become available to the recipient. Android system backup may also save limited settings or app-state tokens with the backup provider configured on your device; your Android settings and that provider’s policy apply.
5 · Location and media geotags
Leemen may access approximate or precise location only after Android permission and only for features you initiate:
- send a one-time location or start Live Location in a selected chat;
- search for nearby places through the configured Telegram venue bot;
- add weather or a place to a story through a weather/location bot;
- display a map, calculate local sunrise/sunset time, or suggest a place;
- give location to a selected bot, Mini App, or website after a separate prompt;
- generate a map preview through the selected map provider.
Background location is used only when you explicitly start Live Location for a period you choose. It keeps updates working while Leemen is minimized, the screen is locked, or the app is otherwise not in use. Coordinates, accuracy, heading, and related parameters are sent to Telegram and become available to participants in the selected chat. A persistent notification is shown while sharing. You can stop Live Location in the app at any time or revoke permission in Android settings. Leemen does not use GPS location for its own advertising or product analytics.
Android’s media location permission allows Leemen to read the GPS geotag of a photo or video you select. In the story location picker, the app immediately uses those coordinates to search for nearby places and sends them to Telegram and the configured Telegram venue-search bot; the selected map or geocoding provider may also process them. Chat participants or story viewers receive the location you select only if you continue sending or publishing. A GPS geotag may also remain in the metadata when a file is sent as an original.
Depending on the feature and settings you select, current coordinates or the coordinates in a message may be received by Telegram, chat participants, the configured bot, a Mini App/website, Google Maps/Fused Location, Yandex Maps, or another selected map provider. Their own policies apply. The country inferred from IP when a Leemen account is created is a separate technical signal and is not GPS location.
6 · Data received by Leemen
Leemen-operated services do not receive Telegram message text, your address book, call content, or your Telegram session through the Leemen API. They process the following data:
| Category | What it is and why | Retention |
|---|---|---|
| Telegram login | Signed Telegram login data: Telegram ID and, if Telegram includes them in the payload, name, username, language, photo, and Premium flag. The payload is verified for authentication; Telegram ID links the accounts | Telegram ID until account deletion; the one-time replay-protection hash becomes eligible for deletion after 2 hours and is normally removed by the next daily job |
| Leemen account and session | Internal master/sync UUIDs, privacy mode, and creation/update times. A signed token containing identifiers is stored on the device and normally lasts up to 30 days | Account record until deletion; token until expiry, sign-out, or account deletion |
| Email, if the feature is available | An address you voluntarily provide for recovery or support | Until the address/account is deleted or the request is resolved, subject to lawful retention |
| Devices | Internal device ID, name/model, platform, Ed25519 public key, registration time, and last-seen time | Until account deletion |
| IP, country, and localization | The network infrastructure provider processes the IP of each API request to deliver it. On first account creation, the full signup IP, the country inferred from it, and the localization decision are stored | First-signup record until account deletion; network logs according to infrastructure-provider schedules and security needs |
| Encrypted sync | Encrypted Private Space blobs: selected dialog/message IDs and state, pins, private-search IDs, PIN hash/salt, timeout, screenshot and UI settings; nonce, version, and update time. Telegram message text and media are not added to these blobs | Until account deletion |
| Key material | Protected/wrapped copies of the master key and device public keys; the form depends on privacy mode | Until account deletion; residual copies may remain in backups until rotation |
| Consent history | Consent type, grant or withdrawal, text/policy version, locale, and timestamp | Until account deletion to apply your choice and evidence consent |
| Subscriptions and promo codes | Provider, product, status, expiry, purchase/subscription/original transaction ID or token, Leemen UUID binding, and promo redemption | Until account deletion, or longer when required for accounting, disputes, fraud prevention, or law |
| Security events | A limited set of account/login/device/purchase events without message content; separate infrastructure logs may contain IP, request time/route/status, Telegram/account/device/subscription identifiers, and technical error details | Curated log normally up to 90 days; infrastructure logs according to provider schedules and legal needs |
| Support correspondence | Email, Telegram username/ID, message text, and attachments you send | While handling the request and then as reasonably needed to document resolution, protect security, and meet legal duties |
7 · Private Space and encryption
A working copy of Private Space state exists on your device within the app sandbox. On supported Android versions, key material is additionally protected with Android Keystore; for compatibility, a Keystore failure or an older Android version can fall back to app storage. We therefore do not claim that every local copy is always hardware-encrypted.
Sync data is encrypted on your device before being sent to Leemen. The selected mode determines who can technically obtain the key:
Default mode
The backend stores the master key in a form protected by server-side KMS/Vault, can unwrap it, and sends it only to an authenticated client over TLS. Consequently, in Default mode Leemen is technically capable of decrypting synchronized blobs. We do not use this ability to read data in ordinary operation, but it exists, for example to restore access on a new device.
Maximum-privacy mode
The active database stores copies of the key wrapped with a password and/or recovery phrase. Without your secret, the active records do not let Leemen unwrap the key. If your account previously used Default mode, Leemen previously processed a server-recoverable copy of the same key, and that copy may remain in backups until they rotate. If you lose both the password and recovery phrase, the data may be impossible to recover.
The Kazakhstan copy may contain encrypted blobs and wrapped key material, but it does not contain the server KMS secret or your password/recovery phrase; that copy alone is insufficient to decrypt the data.
8 · Analytics, diagnostics, push, and website
Optional Leemen product analytics
This is off by default and starts only after your separate choice. When enabled, the app sends random install/session UUIDs, an internal Leemen account ID after login, timestamps, app version/build, and events from a fixed allowlist with limited properties. Examples include first app open, signup and one-time-code stages, setup completion, Private Space onboarding stage, paywall placement and selected option, and purchase-flow start. The install ID does not contain a Telegram ID, but may be linked to the Leemen account after login so events can be attributed and deletion requests honored. Message contents, contacts, the list of hidden chats, and GPS coordinates are not added to Leemen product events.
When Leemen attribution is enabled, Leemen receives the raw install referrer, campaign/click/source ID, and install ID. Separately, opening a go.leemen.app campaign link creates a random click ID and may record campaign code, inferred platform, and time before the app is installed; that click does not itself include a Telegram ID, but may be linked to an installation/account after attribution consent.
Turning analytics off stops future sending by the client. Raw events and attribution records have a retention target of about 90 days; cleanup runs as a maintenance operation, so this is not a guaranteed automatic deadline for every record. The install-to-account link and activity date may remain until account deletion so deletion and metric integrity can be supported. After deletion, individual campaign-link click records not linked to an account (random click ID, campaign code, inferred platform, and time) may remain until their next cleanup, together with derived aggregate metrics.
Firebase and Google services
- Firebase Crashlytics is enabled in the release build independently of the Leemen analytics setting. On a crash, Google/Firebase receives Crashlytics/Firebase installation IDs, a stack trace, time, app version, device model/manufacturer and characteristics, Android version, and process state. This is used for diagnostics; Firebase states that it retains this data for about 90 days before beginning removal from live and backup systems.
- Firebase Cloud Messaging creates an installation/registration ID and token for push delivery; the token is sent to Telegram. Google may receive the app version and SDK technical data.
- Google Maps/Fused Location, Play Billing, Play Integrity/SafetyNet/reCAPTCHA, Google Sign-In, Remote Config, and Android system backup process data required for their respective functions.
- Firebase Analytics and advertising-ID collection are disabled in Leemen’s current release configuration.
See Firebase privacy and security information and the Google Privacy Policy.
The Leemen website
When you visit leemen.app, the hosting provider receives ordinary HTTP request data, including IP, user agent, URL, and time. The website analytics service automatically produces aggregated page-view statistics: page path, filtered parameters, referrer, approximate IP-derived geography, OS, browser, and device type. In the current configuration, this analytics does not use cookies and discards its visitor-session hash after 24 hours; aggregated data may be retained according to the provider’s service periods. Your light/dark theme preference is stored locally in the browser.
9 · Bots, Mini Apps, the in-app browser, and external sites
Bots, Mini Apps, and websites are independent third parties. They may receive Telegram context and data you send or separately allow: messages, profile information, files, contacts, precise/approximate location, camera, microphone, and clipboard. For sensitive access, Leemen presents a prompt in the context of that origin. Review the bot/site policy before providing data; Leemen and Telegram do not control an independent recipient’s later processing.
The in-app browser stores URL, time, and page metadata, cookies, cache, and web storage on the device until cleared. Websites receive IP, requests, cookies, and data you enter. Address-bar text may be sent to the selected search provider (such as Google, DuckDuckGo, Bing, Yahoo, or Brave) for suggestions and results. Browser settings let you clear history, cache, and cookies.
Translation, speech recognition, Passport, weather/venue bots, external maps, and other Telegram features may send selected text, audio, documents, or coordinates to Telegram and providers identified by it; their policies and the Telegram Privacy Policy apply.
10 · Payments
Leemen subscriptions are processed by Google Play, the Apple App Store, or, where available, Tribute. Leemen does not receive your card number. Leemen receives and stores data needed to verify access: product ID, purchase/subscription token or transaction ID, source, status, expiry, and a binding to the Leemen account. Google Play receives the Leemen account UUID as an obfuscatedAccountId, and Apple receives it as an appAccountToken. For a Tribute subscription, the provider sends Leemen the payer’s Telegram ID, subscription ID, and expiry. The payment provider keeps its own records under its policy.
Payments inside Telegram bots are separate from a Leemen subscription. If you choose to provide them, Telegram, the merchant, and its payment provider may receive your name, phone number, email, delivery address, and tokenized payment information. Card details are handled by the selected payment provider, such as Stripe or Google Pay, not the Leemen backend.
Deleting your Leemen account removes linked Leemen entitlement records but does not necessarily cancel an active subscription or delete app-store/payment-provider records. Cancel separately through Google Play, the App Store, or Tribute.
11 · Recipients and providers
- Telegram — account, cloud communications, contacts, calls, location, push registration, and Telegram features; independent controller. Telegram Privacy Policy.
- Server infrastructure provider — Leemen’s primary database, server functions, synchronization, key management, and technical logs.
- Network infrastructure provider — delivery of requests to Leemen services, IP-derived country, and processing of campaign-link visits.
- Google/Firebase — FCM, Crashlytics, Maps/Fused Location, Google Play Billing, Integrity/SafetyNet/reCAPTCHA, Sign-In, Remote Config, and, depending on device settings, Android Backup. Google Privacy Policy.
- Website hosting and analytics provider — hosting
leemen.appand producing visit statistics. - Apple App Store and Google Play — purchases and subscriptions; system backup where selected on the relevant platform.
- Tribute — subscriptions in supported regions. Tribute Privacy Policy.
- Corporate email provider — delivery and storage of correspondence sent to support@leemen.app.
- Google Maps, Yandex Maps, search providers, bots, Mini Apps, websites, merchants, payment providers, and connected devices — when you choose the relevant feature or it is required to provide it.
- Message and call recipients — the users, groups, channels, and other recipients you select.
We do not sell personal data. Leemen’s own analytics is not used to sell data or provide it to advertisers; campaign data is used to measure promotion of Leemen.
12 · Purposes and legal bases
Depending on applicable law, we process data:
- to perform our contract and provide requested functions — login, communications, sync, devices, subscription, and support;
- with your consent — optional analytics/attribution, contact sync, location, camera, microphone, and other access where a choice is required;
- for Leemen’s legitimate interests — security, fraud prevention, crash diagnosis, infrastructure protection, and protection of users’ rights;
- to comply with legal obligations — accounting, lawful requests, localization requirements, and dispute handling.
You can revoke an Android permission in device settings. You can withdraw Leemen analytics consent in the app; this does not disable Telegram functions required for the service or Crashlytics, which is always enabled in the current release build.
13 · Where data is processed
Leemen’s primary account database is hosted in the European Union. Providers listed in section 11 may process data globally in their own regions and data centers.
When an account is first created, a country is approximately inferred from the IP address. This value is fixed for localization and may not match citizenship or actual residence because of VPN, Tor, travel, or network behavior. Leemen does not request or verify citizenship.
- If the signup IP is identified as Kazakhstan, account data is first processed in the primary European Union database and is additionally replicated to a database in Kazakhstan. The replica may include account and device records, entitlements/promo records, consents, security/localization signals, linked analytics/attribution, Apple subscription bindings, encrypted Private Space state and identifiers, and wrapped key material, but not Telegram message text/media, the server KMS secret, or your password/recovery phrase. When the app presents a notice about this cross-border processing, the acknowledgement (
kz_cross_border), text version, locale, and time are stored in consent history. - For other signup-country values, the account is not copied to Kazakhstan under this rule.
Telegram, Google, app stores, infrastructure providers, and other independent services determine processing locations under their own policies. We use contractual and technical international-transfer safeguards where required.
14 · Retention and deletion
- Local data remains on the device until sign-out, history/cache/app-data clearing, system deletion, or app uninstall; backups depend on Android and the selected backup provider.
- Telegram data is retained and deleted under the Telegram Privacy Policy and your Telegram settings.
- Core account-linked Leemen records remain until account deletion, except for shorter periods stated in section 6.
- Raw analytics/attribution and curated security events have a retention target of about 90 days; actual cleanup runs through maintenance tasks. The install/account link and activity date may remain until account deletion. Technical-log, Crashlytics, website, and backup retention follows the relevant provider and service configuration.
- Purchase data may remain longer where needed for accounting, fraud prevention, a refund/dispute, or law. Payment providers retain their own records independently.
- Support correspondence is kept while a request is handled and then for a reasonable period to document the resolution, protect security, and meet legal duties.
You can delete a Leemen account in the app through Settings → Search → “Delete account” or, without the app, on the Delete your account page. Account-linked data, devices, encrypted sync, consents, the localization record, entitlement/promo records, and the linked analytics footprint are removed from the active primary database; replica deletion propagates asynchronously. Deletion does not cover raw campaign clicks not linked to the account and derived aggregate metrics until their next cleanup, technical anti-replay/payment identifiers (for example, processed Apple notification IDs) reasonably needed to prevent duplicate processing or meet legal duties, data in backups/logs that have not yet rotated, or independent-provider data. To remove local copies on other devices, sign out or clear app data/uninstall on those devices.
Deleting Leemen does not delete your Telegram account or cancel a subscription with a payment provider.
15 · Your rights and controls
Depending on applicable law, you may request access, correction, a portable copy, restriction, objection, deletion, or withdrawal of consent. You may also complain to the competent data-protection authority.
Self-service controls include:
- stopping Live Location and revoking Android location permissions;
- turning contact sync off and deleting contacts previously uploaded to Telegram;
- disabling Leemen product analytics/attribution;
- managing bot, Mini App, website, camera, and microphone permissions;
- clearing in-app browser history, cookies, and cache;
- clearing local cache and deleting Leemen and Telegram accounts through separate procedures.
For deletion of selected data or another request, email support@leemen.app. We may securely verify your identity. We respond within the time required by applicable law, ordinarily within one month, subject to lawful extension for a complex request.
16 · Security
We use TLS in transit, server-storage encryption, access controls, least privilege, separate device keys, and auditing for sensitive operations. Encrypted Private Space blobs do not contain the plaintext working state, but Leemen’s ability to unwrap the master key depends on the selected mode as explained in section 7.
No system can guarantee absolute security. If a personal-data incident occurs, we take steps to contain it and notify users and authorities where required by law.
17 · Children
Leemen is not directed to children under 16, and we do not knowingly collect their data. If we learn of such an account, we will take steps to remove associated data, subject to legal requirements and Telegram procedures.
18 · Changes to this policy
We update this policy when the app, providers, or requirements change. The revised text and date are published on this page. We provide notice and request a fresh user choice for material changes when and in the manner required by applicable law. You may request a previous version by email.
19 · Contact
Leemen Software, TOO · support@leemen.app