Privacy Policy

If you do not agree with this policy, please do not use the Service.

Contents

  1. Who we are
  2. The short version
  3. Information we collect
  4. How we use your information
  5. Health information & HIPAA
  6. AI processing of your messages
  7. Voice features (Deepgram)
  8. Analytics (PostHog)
  9. Cookies and similar technologies
  10. How we share information
  11. Data retention
  12. Security
  13. Your rights
  14. International data transfers
  15. Children
  16. Changes to this policy
  17. Contact us

1. Who we are

2. The short version (TL;DR)

3. Information we collect

3.1 You give us

CategoryExamples
AccountUsername, email, hashed password, display name, role (patient or clinical role such as physician, RN, NP, PA, pharmacist, student)
ProfileCare team / provider names you choose to save
Conversation contentMessages you send to Leny, including symptoms, conditions, medications, lab values, and any free-text health information you choose to share
VoiceAudio you record when you use voice input (transcribed in near-real time, see Section 7)
VerificationA photo of a government-issued ID. We only ask for photo ID for primary verification — we do not collect medical licenses, diplomas, or board certificates as primary verification documents
CommunicationsMessages you send to support, feedback, survey responses

3.2 Collected automatically

3.3 From third parties

4. How we use your information

We process your information to:

We do not use your conversation content to train third-party foundation models without your consent. We may use de-identified or aggregated data to improve our own prompts, evaluations, and product quality.

5. Health information — important context (HIPAA, sensitive data)

Please read this section carefully. It is the most commonly misunderstood part of using a tool like Leny.

6. AI processing of your messages

7. Voice features (Deepgram)

8. Analytics and product improvement (PostHog)

9. Cookies and similar technologies

We use cookies, localStorage, and similar technologies to keep you signed in (leny_token), remember guest sessions (leny_is_guest, leny_username), persist your in-progress chat (Leny_v21), and run analytics. For details on each cookie/storage key, its purpose, and how to control it, see our Cookie Policy.

10. How we share information (sub-processors, no sale)

We share information only with:

RecipientPurposeData involved
[AWS]Cloud hosting and storageAll Service data
[Anthropic / OpenAI]AI model inferenceYour prompts and conversation context
DeepgramVoice-to-text transcriptionYour audio input
PostHogProduct analyticsEvent metadata, pseudonymous IDs
[Email provider]Transactional and account emailEmail address, message content
Identity providers (if used)Sign-inAccount identifiers
Professional advisorsLegal and financial supportAs needed
Government / legalWhere required by law, subpoena, or to protect rights and safetyAs required
Acquirer (in a merger or asset sale)Continuity of the ServiceAll Service data, with notice

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.

A current sub-processor list is available at [/sub-processors] (or by request to info@leny.ai).

11. Data retention

12. Security

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law (see Section 13.3 for EU breach timing).

13. Your rights

13.1 All users

You can:

To exercise these rights, email info@leny.ai from the email on your account, or use in-app settings where available. We respond within 30 days (or as required by your local law).

13.2 California residents (CCPA/CPRA)

If you live in California, you have the right to:

You may use an authorized agent. We will verify requests using information already on file (we do not request additional sensitive documents for verification).

13.3 EU/UK/EEA residents (GDPR / UK GDPR)

If you are in the EU, UK, or EEA, you have the rights to:

Legal bases we rely on:

If a notifiable personal data breach occurs, we will notify the relevant supervisory authority within 72 hours where required, and affected users without undue delay.

14. International data transfers

Leny is operated from the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US and other countries where our sub-processors operate. For transfers from the EU/UK/EEA, we rely on the EU Standard Contractual Clauses (and the UK Addendum) with our sub-processors, plus supplementary measures where appropriate.

15. Children

Leny is intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact info@leny.ai and we will delete it.

16. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in-app or by email. Continued use of the Service after the effective date means you accept the updated policy.

17. Contact us / DPO

Privacy questions and rights requests: info@leny.ai
Mailing address: Leny, 7660H Fay Ave, Suite 504, La Jolla, CA 92037
EU/UK representative (Art. 27 GDPR): [to be appointed if/when EU users are in scope]
Data Protection Officer: [to be appointed where required]