Privacy
Privacy policy
LEASH holds your most sensitive keys, so we collect as little as we can and say exactly what that is.
The short version
- No passwords, no email address required, no tracking, no analytics, no ads, no third-party scripts.
- Your face or fingerprint never reaches us. We only ever see a public key and a signature.
- API keys you vault are encrypted, and no API or person on our side can read them back to you or anyone else.
- One cookie: your sign-in session. Nothing else is stored in your browser.
- You can delete your account and everything in it yourself, at any time, in the app.
Face ID and passkeys
When you sign in or approve a held call, LEASH uses a passkey (the WebAuthn standard, the same one Apple, Google and GitHub use). Your phone or laptop asks you for Face ID, Touch ID, Windows Hello, a fingerprint or your device PIN. That check happens entirely on your device, inside its secure hardware.
If it passes, your device signs a one-time challenge from us with a private key that never leaves it. We receive the signature and check it against the public key you registered. We never receive, store or have any way to see your face, fingerprint, PIN or private key.
The demo on our homepage
The "Try it" section and the "nine seconds" replay on our homepage are simulations that run only in your browser. Pressing "Approve with Face ID" there does not use Face ID, does not use your camera, sends nothing to us, and stores nothing. The only request the homepage makes is to load the public list of irreversible calls.
What we store
| Data | Why |
|---|---|
| The name you type at sign-up | So the app can greet you. It can be anything. |
| Your passkey's public key and a usage counter | To verify sign-ins and approvals, and to detect cloned authenticators. |
| API keys you add to the vault, encrypted | To call the provider on your agent's behalf. Each key has its own AES-256-GCM key, wrapped by a master key held outside the database. We keep the last four characters in clear so you can tell keys apart. |
| Agent tokens, as a hash | To recognise your agents. The token itself is shown to you once and never stored. |
| Held calls: method, host, path, rule, time, decision, and a preview of the request (query string and up to 2 KB of the body or SQL) | So you can see exactly what you are approving. The preview is deleted a day after you decide; the audit log keeps only a fingerprint (hash) of it. |
| Your audit log | Calls, holds, approvals, token and key changes, hash-chained so tampering is detectable. |
| Session records, as a hash | To keep you signed in. Web sessions and CLI sessions expire automatically. |
| A salted hash of your IP address | Only for rate limiting, deleted when the limit window ends. IPv6 addresses are grouped by /64 before hashing. |
What we never store
- Your biometric data, device PIN or private keys.
- Your API keys in readable form, anywhere: not in the database, not in logs, not in error messages.
- The bodies of requests your agents send or the responses they get back. They pass through and are gone. The only exception is the short preview of a held call, kept until a day after you decide on it.
- Your IP address in clear, your location, or any device fingerprint.
Where it lives
LEASH runs on Cloudflare Workers and Cloudflare D1. Cloudflare is our only processor. Requests are handled at the Cloudflare location nearest to you; the database lives in one Cloudflare region. Cloudflare's own request logs (URL path, status, timing) are kept for a few days for debugging and never contain your keys or tokens.
When public receipts are enabled for the service, LEASH sends a minimal record of each decision to the WITNESS transparency log: the method, the host and a hash of the path. Never the path itself, your name or your keys.
How long we keep it
- Sign-in challenges: minutes. Device login codes: minutes. Rate limit records: until the window ends.
- Sessions: until they expire or you sign out.
- Vault keys and tokens: until you delete or revoke them.
- Holds and audit log: until you delete your account.
Your rights
You can see everything we hold about you in the app: your vault, your tokens, your holds and your audit log. You can delete any key or token at any time. Delete account in the app erases your account, passkeys, vault, tokens, holds, sessions and audit log immediately; there is no soft delete. Database backups kept by Cloudflare roll off within 30 days.
Wherever you live, including under GDPR, PIPEDA or CCPA, you can also ask us to access, correct, export or delete your data by writing to us. We do not sell or share personal data.
Contact
LEASH is run by Gautam Khosla in Ottawa, Canada. Privacy questions: privacy@gautamkhosla.com. Security reports: see our security page.