Last updated · 19 July 2026

Privacy Policy

Leemen is a privacy-first messaging client. This policy explains, in plain language, exactly what the Leemen backend stores, what it can and cannot see, and the rights you have over your data.

The short version. Leemen never stores your messages, contacts, or media — those stay between you and Telegram. Our backend only handles three things: your subscription, promo codes, and an encrypted sync of your private settings. You can delete everything you have with us at any time, from inside the app or via this page.

1 · Who we are

The Leemen app and backend are built and operated by Leemen Software, TOO (Kazakhstan LLP), referred to here as “we”. We are responsible for how the personal data described here is handled. For privacy questions or to exercise your rights, contact us at support@leemen.app.

Leemen is an independent Telegram client: it uses Telegram’s API and is part of the Telegram ecosystem, but is not affiliated with, endorsed by, or operated by Telegram. “Telegram” is a trademark of its respective owner, used here only to describe what Leemen works with.

Why we process your data, and where. We process your data to provide the service (your account, devices, and sync), with your consent where you give it (such as an optional recovery email), and to keep the service secure and free of abuse. Some of the providers we rely on operate in other countries; wherever your data is processed, we require appropriate safeguards and contractual protections so it stays protected — see Where your data lives for exactly where it is stored.

On what basis. We handle your account, device, and sync data because it is needed to give you the service you asked for. We keep your optional recovery email, run product analytics, and record install source only with your permission, which you can withdraw at any time. We keep the short security log to protect the service from abuse, which is our legitimate interest.

2 · Identity & how login works

A Leemen account is not the same thing as your Telegram account — it is a separate record we keep, linked to your Telegram account.

When you sign in, Leemen uses Telegram’s official sign-in to confirm your Telegram account, and we create or look up a Leemen account linked to it. We do not receive or store your phone number, your Telegram password, or your Telegram session.

Optionally, you may add an email address for account recovery. It is stored only if you choose to provide it.

3 · What we store

Everything our backend holds, and why:

DataWhat it isWhyRetention
Telegram account IDAn identifier from your Telegram sign-inTo identify your account across devicesUntil you delete your account
Email (optional)Only if you add one for recoveryAccount recoveryUntil removed / account deletion
Device recordsA per-device entry — device name, platform, last-seen timeMulti-device sync & securityUntil the device is removed / account deletion
Encrypted sync dataYour private settings and content — encrypted on your deviceSync across your devicesUntil account deletion
Subscription & promo recordsWhether you have Premium, its source and expiry; redeemed promo codesTo unlock paid featuresWhile active + as required for records
Security audit logDiscrete events (account created, failed login, device added, purchase) — no IPs, no payloadsAbuse & fraud protection90 days
Product analyticsApp-usage events — collected only if you turn it on (off by default). See §6To improve the app90 days

4 · Privacy modes

Your private synced data (your settings and related content) is always encrypted on your device before it reaches us. You choose how the encryption key is managed:

Default mode

Your encryption key is kept on our backend in protected form so we can restore it to a new device after you log in — no password to remember. The honest consequence: in this mode we are technically able to decrypt your sync data. We do not do so in normal operation, but you should know it is possible (e.g. under a valid legal order). The contents are still your settings and private content only — never message contents.

Maximum-privacy mode (optional)

Your encryption key never leaves your device in readable form. We keep only protected copies that can be unlocked solely with your password or recovery phrase — which we do not have. In this mode we cannot decrypt your sync data at all. The trade-off: if you forget both your password and your recovery phrase, that data is unrecoverable.

5 · What we never store or see

6 · Analytics & attribution

Product analytics is off by default. We collect in-app usage analytics only if you turn it on in Settings → Privacy, and you can turn it back off at any time. While it is on:

Install source. Only if you opt in — it’s off by default, the same kind of choice as analytics — we record once which campaign link brought you, for our own marketing. It tells us the campaign, never who you are; if you don’t opt in, we don’t record it.

We don’t profile you, and we don’t make any decision about you by purely automated means.

7 · Payments

If you buy a paid feature, the payment is handled by a third-party payment provider — Leemen never receives or stores your card details. In most regions this is your app store (Apple App Store or Google Play). Where app-store billing is unavailable (for example, Russia), the payment is instead handled by Tribute (tribute.tg) through Telegram: Tribute processes your card payment and sends us only a record of the subscription, linked to your Telegram account. In either case we keep only a record that the purchase is active, so the feature stays unlocked.

8 · Who processes your data

The providers we use to run the service are Supabase (hosting and our database), Cloudflare (content delivery and security), the Apple App Store and Google Play (billing for paid features), and Tribute (tribute.tg — payment processing in regions where app-store billing is unavailable, such as Russia). Some providers act as independent controllers for their own services, including billing, and process data under their own terms and privacy notices; where a provider processes personal data on our behalf, we use appropriate contractual protections. See the privacy notices for the App Store, Google, and Tribute. We keep this list current — email support@leemen.app for the latest. We do not sell your data, and we do not share it with advertisers.

9 · Where your data lives

Your data is kept in one place by default: our main database, hosted in the European Union (Ireland), under European data-protection rules. Where else it goes depends on where you were when you signed up:

Wherever your data is stored, it is protected by the same encryption and the same contractual safeguards described in this policy.

10 · Your rights

Wherever you live, you can ask us to show you your data, correct it, give you a copy you can take elsewhere (in a standard, machine-readable format), limit or object to how we use it, delete it, or withdraw a permission you’ve given. You can also complain to a data-protection regulator — usually the one where you live or work, or where you think the problem happened (in the UK, that’s the ICO).

You can delete everything yourself: from inside the app via Settings → Delete account, or — without needing the app — from the Delete your account page, where you just sign in with Telegram. Deletion is immediate and permanent. For any other request, email support@leemen.app. We’ll reply as soon as we can, and within one month at the latest; if a request is unusually complex we may need up to two more months, and we’ll tell you why within the first month.

11 · Retention

Account data lives until you delete your account. Security-audit and analytics data are automatically purged after 90 days. Deleting your account erases your account and the devices and settings linked to it, along with your analytics footprint; aggregate, non-identifying counters (e.g. the total number of clicks on a campaign link) may remain as they are no longer linked to you.

12 · Security

Your sync data is encrypted on your device with modern, well-established cryptography before it ever reaches us. In maximum-privacy mode it is end-to-end encrypted — only you hold the key, and we cannot decrypt it; in default mode it stays encrypted in transit and at rest, but we hold the key in protected form, so we are technically able to decrypt it (see Privacy modes). Our systems are built around strict access controls and least privilege, and we never expose payment or key material to client apps. No system is perfectly secure, but privacy is the default in how we build Leemen.

If a security incident ever affects your personal data, we will act quickly to contain it, notify the relevant regulator as the law requires, and tell affected users without undue delay.

13 · Children

Leemen is not directed to children under 16, and we do not knowingly collect their data. If we learn that we have data from someone under 16, we delete it.

14 · Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, surfaced in the app.

15 · Contact

Leemen Software, TOO (Kazakhstan LLP) · ulitsa Qarasai Batyr 40, Talgar, Almaty Region, 041602, Kazakhstan · +7 706 633 62 56 · support@leemen.app