Privacy

Privacy policy

LEASH holds your most sensitive keys, so we collect as little as we can and say exactly what that is.

Last updated 7 October 2026

The short version

Face ID and passkeys

When you sign in or approve a held call, LEASH uses a passkey (the WebAuthn standard, the same one Apple, Google and GitHub use). Your phone or laptop asks you for Face ID, Touch ID, Windows Hello, a fingerprint or your device PIN. That check happens entirely on your device, inside its secure hardware.

If it passes, your device signs a one-time challenge from us with a private key that never leaves it. We receive the signature and check it against the public key you registered. We never receive, store or have any way to see your face, fingerprint, PIN or private key.

On a phone, approving a held call looks just like unlocking an app: you tap Approve, Face ID or your fingerprint confirms, done. On a laptop it is Touch ID, Windows Hello, or a QR code you scan with your phone.

The demo on our homepage

The "Try it" section and the "nine seconds" replay on our homepage are simulations that run only in your browser. Pressing "Approve with Face ID" there does not use Face ID, does not use your camera, sends nothing to us, and stores nothing. The only request the homepage makes is to load the public list of irreversible calls.

What we store

DataWhy
The name you type at sign-upSo the app can greet you. It can be anything.
Your passkey's public key and a usage counterTo verify sign-ins and approvals, and to detect cloned authenticators.
API keys you add to the vault, encryptedTo call the provider on your agent's behalf. Each key has its own AES-256-GCM key, wrapped by a master key held outside the database. We keep the last four characters in clear so you can tell keys apart.
Agent tokens, as a hashTo recognise your agents. The token itself is shown to you once and never stored.
Held calls: method, host, path, rule, time, decision, and a preview of the request (query string and up to 2 KB of the body or SQL)So you can see exactly what you are approving. The preview is deleted a day after you decide; the audit log keeps only a fingerprint (hash) of it.
Your audit logCalls, holds, approvals, token and key changes, hash-chained so tampering is detectable.
Session records, as a hashTo keep you signed in. Web sessions and CLI sessions expire automatically.
A salted hash of your IP addressOnly for rate limiting, deleted when the limit window ends. IPv6 addresses are grouped by /64 before hashing.

What we never store

Where it lives

LEASH runs on Cloudflare Workers and Cloudflare D1. Cloudflare is our only processor. Requests are handled at the Cloudflare location nearest to you; the database lives in one Cloudflare region. Cloudflare's own request logs (URL path, status, timing) are kept for a few days for debugging and never contain your keys or tokens.

When public receipts are enabled for the service, LEASH sends a minimal record of each decision to the WITNESS transparency log: the method, the host and a hash of the path. Never the path itself, your name or your keys.

How long we keep it

Your rights

You can see everything we hold about you in the app: your vault, your tokens, your holds and your audit log. You can delete any key or token at any time. Delete account in the app erases your account, passkeys, vault, tokens, holds, sessions and audit log immediately; there is no soft delete. Database backups kept by Cloudflare roll off within 30 days.

Wherever you live, including under GDPR, PIPEDA or CCPA, you can also ask us to access, correct, export or delete your data by writing to us. We do not sell or share personal data.

Contact

LEASH is run by Gautam Khosla in Ottawa, Canada. Privacy questions: privacy@gautamkhosla.com. Security reports: see our security page.