Questa pagina è disponibile solo in inglese. La versione inglese è quella giuridicamente vincolante.
LEORA
Privacy Policy
- Effective Date
- 1 October 2026
- Last Updated
- 29 September 2026
- Version
- 2.0
- Controller
- Leora IO LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA
- Contact
- hello@leorastudio.com
At a Glance
- We collect: the account details you sign in with (Google, Apple, or an email address and password), payment records from Stripe, the settings you send to our Customization Tool and the files we render for you, any logo or image you upload, the lamps you save in the Studio while signed in, the email address you give us to receive the free Starter download, and usage and server-log data — only what is needed to run the Platform and enforce your license.
- The Studio runs in your browser: the lamp you shape in the Studio, and the print files it exports, are computed on your own device. We receive a lamp's design only when you save it while signed in; when you download a lamp with a Plan, we keep only a fingerprint of it, from which the design cannot be read (Section 2).
- We do not sell: your personal data. We do not sell or rent it to anyone.
- We share with: Google (sign-in, hosting, and database; YouTube, only if you play a video in the Guides), Apple (sign-in), Stripe (payments), Amazon Web Services (rendering and file storage), Resend (email), PostHog (analytics), and TikTok (advertising measurement, only with your consent). Full list in Section 4.
- Your rights: access, correct, delete, and export your data; delete your account yourself from the Account page. EU/UK, California, and Canadian rights in Section 7.
- Cookies: strictly necessary, functional, and analytics & advertising — you manage them in the cookie banner and via "Cookie Settings" in the footer. Section 8.
- Contact: hello@leorastudio.com — we respond within the time your law allows: one month for EU/UK residents, 45 days for California residents, 30 days for everyone else.
1. Who We Are and How to Contact Us
This Privacy Policy is issued by Leora IO Limited Liability Company, a Delaware limited liability company ("Leora," "we," "us," or "our"), registered at 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Leora is the data controller for personal data collected through the website at e-leora.com, the Leora web application, the Studio, the account portal, and related services (the "Platform") — meaning we decide why and how your data is processed.
For all privacy questions, rights requests, or complaints, contact us at hello@leorastudio.com (subject: "Privacy Request").
We will respond within the timeframe required by your applicable law: one calendar month for the EU/UK (GDPR); 45 days for California (CCPA); 30 days for Canada (PIPEDA) and all others.
EU and UK representative: Leora does not currently have a representative appointed under GDPR Article 27 or UK GDPR Article 27. EU and UK residents may contact us directly at hello@leorastudio.com. This section will be updated when a representative is appointed.
This is Version 2.0 of the Privacy Policy, effective 1 October 2026. It replaces the version last updated on 6 April 2026. It reflects the launch of Leora 2.0 — the browser-based Studio and the lamps you can save to your account, three subscription plans, and sign-in with Apple and with email and password — and adds a description of the advertising measurement with TikTok, which we already use with your consent (Section 8). It was updated on 27 September 2026, before taking effect, to describe the lamps you can save to your account, the fingerprints of the lamps you download, and the videos in the Guides (Sections 2, 4, 6, and 8), and on 29 September 2026 to describe the record we keep of the files you download from the library (Sections 2 and 6). If you held an account before 1 October 2026, the changes in this version take effect for you fourteen (14) days after we notify you of them by email, as the previous version of this Policy promised.
2. What Data We Collect and Why
The table below lists every category of personal data we collect, what is included, why we collect it, and the GDPR legal basis. We do not intentionally collect any special category data (health, biometric, racial or ethnic origin, political, religious, or sexual orientation data). If you submit such data inadvertently, we will delete it upon becoming aware.
| Category | What we collect | Why | Legal basis (GDPR) |
|---|---|---|---|
| Account & identity | Email address; name and profile picture where your sign-in provider shares them; the identifier your provider assigns to you (Google account ID or Apple user ID). With Apple, you may choose to hide your email, in which case we receive an Apple private relay address. | Creating and managing your account | Contract |
| Password (email sign-in) | If you sign in with an email address and password, your password is stored by Firebase Authentication as a salted hash. Leora never sees or stores it in readable form. | Authenticating you | Contract |
| Sign-in tokens | Session and refresh tokens issued by Firebase Authentication to keep you signed in. Not used for any other purpose. | Maintaining your session | Contract; legitimate interests |
| Subscription & payment | Plan, purchase and renewal dates, Stripe customer and subscription identifiers, transaction identifiers, billing country, invoice history. Card details are handled by Stripe — never received or stored by Leora. | Processing payment; issuing and renewing your license; receipts and reminders | Contract; legal obligation |
| Download & export records | The Customization Tool jobs and downloads recorded in our database (your account, the model, timestamps, and job status); for each lamp you download from the Studio with a Plan, a fingerprint of the lamp (a one-way hash of its design settings, from which the design cannot be read) and when you downloaded it; for each file you download from the library, which file and which version, and when you downloaded it; our server logs of requests to the library (the request, the time, and your IP address); and, if you have consented to analytics, an analytics event when you export from the Studio | Delivering your files; counting the Studio lamps included in your Plan; license compliance and piracy detection; handling refund requests (Terms and Conditions, Section 4.6) | Contract; legitimate interests |
| Customization Tool jobs (Plus and Pro) | The parameter settings you choose, the model chosen, the preview and download files we render for you, credit usage, and job status. Rendering runs on our cloud infrastructure at Amazon Web Services in the United States (Section 4). | Rendering your previews and Customized Files; managing your credits | Contract |
| User Content | A logo or image you upload to apply to a design (PNG) | Rendering it onto your design | Contract |
| Saved lamps | When you save a lamp in the Studio while signed in: the name you give it, when you saved it, and its design settings (the blooms, their sizes and shapes, and the colors you chose), stored with your account. Lamps you save while signed out stay in your browser (Section 8) and are not sent to us; when you next sign in on that browser, they move to your account. Apart from saved lamps, the Studio computes your design and its export on your own device, and your design is not sent to us. | Keeping your lamps so you can open them again in any browser you sign in to | Contract |
| Usage & technical data | Browser type, device type, operating system, IP address, pages visited, session duration, error logs, server request logs | Platform security, performance, and debugging; showing the Platform in your language (Section 8) | Legitimate interests |
| Support & contact communications | Your name, email address, and the content of messages you send through the contact form or by email | Customer support | Contract; legitimate interests |
| Free Starter download requests | The email address you enter to receive a link to the free Starter lamp from the Studio, when you asked, when the link expires, and how many times it was opened. So that the form cannot be used to send email to people who did not ask for it, we also count the links sent to each address each day, stored under a one-way hash of the address. | Sending you the download link you asked for; preventing misuse of the form | Contract; legitimate interests |
| Cookie, analytics & advertising data | Consent choice; PostHog analytics identifiers and events; TikTok pixel identifiers and events, and a hashed version of your email address and account ID sent with a purchase event (Sections 4 and 8). Before you consent, PostHog receives only anonymous, cookieless page events with your IP address discarded and precise location removed; everything else in this category is collected only with your consent. | Understanding how the Platform is used; measuring our advertising | Consent; legitimate interests (anonymous usage statistics only) |
| Compliance records | The date your account was created, which records your acceptance of the Terms and this Policy at registration; Stripe's record of your acceptance of the Terms at checkout; your cookie consent choice, which is held in your own browser | Legal compliance; enforcement | Legal obligation; legitimate interests |
How data reaches us
- Directly from you: when you create an account, purchase a subscription, use the Customization Tool, upload a logo, save a lamp in the Studio while signed in, download a file, ask us to email you the free Starter download, contact support, or submit feedback.
- Automatically: when you use the Platform — technical and usage data is collected by our systems, and analytics and advertising data is collected via PostHog and the TikTok pixel with your consent.
- From Google: your name, verified email address, Google account ID, and profile picture, sent by Google when you sign in with Google. Leora requests only the minimum scopes necessary; you can see the scopes requested on the Google permissions screen.
- From Apple: your name (on first sign-in only, if you share it), your email address or an Apple private relay address, and your Apple user identifier, sent by Apple when you sign in with Apple.
- From Stripe: transaction confirmation, subscription status, billing country, invoice details, and fraud signals when you purchase or renew a subscription.
- From MakerWorld: for backers of our MakerWorld campaign, where we need to confirm your backing before issuing your discount — your MakerWorld account identifier and backing tier only, once.
Automated decision-making
Leora does not make any decisions about you based solely on automated processing that produce legal or similarly significant effects. Access controls are rule-based (your plan and subscription status in our database). We do not use your data to train AI or machine learning models.
3. How We Use Your Data
We use your personal data only for the following purposes. Where we rely on legitimate interests, we have assessed that those interests — operating a licensed 3D-printing design business, protecting our intellectual property, and preventing piracy — are not overridden by your privacy rights.
- Delivering the Platform: account management, payment processing, license issuance, running the Customization Tool and allocating credits, keeping the lamps you save in the Studio, file downloads, and customer support.
- Transactional communications: purchase receipts, renewal reminders, payment failure notices, password reset and sign-in emails, the free Starter download link you ask for, and notices about changes to the Terms or this Policy. These are service communications — you cannot opt out while your account is active.
- License compliance and enforcement: keeping the records of Customization Tool jobs, server logs, and consent records described in Section 2 to detect unauthorized file sharing and enforce the Terms and Conditions.
- Legal obligations: tax and accounting records, responding to lawful legal process, and maintaining the breach register required by GDPR Article 33(5).
- Platform security and integrity: detecting unauthorized access, monitoring download patterns for piracy indicators, and maintaining infrastructure performance.
- Platform improvement: analyzing usage patterns, in aggregate, to improve the Studio and the Customization Tool. Before you consent to analytics cookies this is limited to anonymous, cookieless page statistics (Section 8).
- Advertising measurement: with your consent, measuring whether our advertising on TikTok leads to sign-ups and purchases (Section 8). We do not show you targeted advertising on the Platform.
- Marketing emails: promotional emails about new models or features — only where you have opted in or where permitted by applicable law (for example the soft opt-in for existing customers under UK PECR). You may unsubscribe at any time via the link in any such email or by emailing hello@leorastudio.com.
4. How We Share Your Data
We do not sell, rent, or trade your personal data. We share it only with the service providers below, who are bound by data processing terms, and in the limited circumstances described.
| Provider | Role | Data shared | Country | Transfer basis |
|---|---|---|---|---|
| Google LLC — Firebase Authentication | Sign-in and account management (Google, Apple, and email sign-in are all handled through Firebase Authentication) | Email address, name, profile picture, provider identifiers, password hash (email sign-in), session tokens | USA | EU-US DPF; Google Cloud Data Processing Terms |
| Google LLC — Google Sign-In | Identity provider | Name, email, Google account ID, profile picture, sent by Google to Leora at sign-in. Google is an independent controller for its own processing. | USA | EU-US DPF; Google API Services Terms |
| Apple Inc. — Sign in with Apple | Identity provider (where offered) | Name (first sign-in), email or private relay address, Apple user ID, sent by Apple to Leora at sign-in. Apple is an independent controller for its own processing. | USA | Apple's privacy terms; SCCs as applicable |
| Google LLC — Firebase and Google Cloud | Hosting of the website and API, database (Firestore), infrastructure | All Platform data described in Section 2 | USA | EU-US DPF; Google Cloud Data Processing Terms |
| Google LLC — YouTube | Playing the videos embedded in the Guides, in YouTube's privacy-enhanced mode (youtube-nocookie.com), only when you press play | When you press play: your IP address, browser details, and the video you watch; YouTube may set cookies or similar identifiers. Nothing is sent to YouTube before you press play. Google is an independent controller for its own processing. | USA | EU-US DPF; Google Privacy Policy |
| Amazon Web Services, Inc. | Rendering for the Customization Tool (AWS Deadline Cloud) and file storage (Amazon S3) for model assets, rendered files, and uploaded User Content | Customization parameters, rendered files, uploaded logos and images, account identifiers attached to jobs | USA | EU-US DPF; AWS Data Processing Addendum |
| Stripe, Inc. | Payment processing, hosted checkout, and billing portal | Email address, billing country, amount, plan, transaction details. Card data is handled by Stripe under PCI-DSS — never received or stored by Leora. Stripe is an independent controller. | USA | EU-US DPF; stripe.com/privacy |
| Resend, Inc. | Transactional email delivery, including messages you send us through the contact form and the free Starter download links | Recipient email address and email content | USA | Standard Contractual Clauses; Resend DPA |
| PostHog, Inc. | Product analytics | Usage events collected from your browser. Before you consent, PostHog runs without cookies or local storage, does not identify you, and receives only basic anonymous page events with your IP address discarded and precise location removed; after you consent it may use cookies and link events to your account. PostHog is our processor. | USA | Standard Contractual Clauses; PostHog DPA |
| TikTok Technology Limited and TikTok Inc. | Advertising measurement (the TikTok pixel and the TikTok Events API), only with your consent | Pixel events (page views, sign-ups) and, for purchases, a server-side event containing a hashed email address, a hashed account identifier, the TikTok click and browser identifiers from your visit, your IP address, and browser type. TikTok is an independent controller for its own use of this data. | Ireland / USA | Standard Contractual Clauses; TikTok's privacy policy |
| MakerWorld (Bambu Lab) | Campaign backer verification (one-time, only where needed) | Account identifier and tier confirmation only. No ongoing data sharing. | USA / China | SCCs as applicable; makerworld.com/privacy |
You may request the name and privacy policy of any specific service provider by emailing hello@leorastudio.com.
We may also disclose data to law enforcement, courts, or regulators where required by law or to protect the rights, property, or safety of Leora or its users. If Leora is acquired or merges with another entity, your data may transfer to the successor — we will notify you by email at least 30 days before any such transfer and you may delete your account before it takes effect.
5. International Data Transfers
Leora is based in the United States, which does not have a general EU adequacy decision. Where your personal data is transferred from the EEA, the UK, or Switzerland to the US, we rely on the following mechanisms:
- EU-US Data Privacy Framework (DPF), including its UK extension: Google, Amazon Web Services, and Stripe are DPF-certified. We rely on their certification for transfers to those providers. This section will be updated if Leora obtains its own certification.
- Standard Contractual Clauses (SCCs): for transfers to providers not covered by the DPF or an adequacy decision — Resend, PostHog, and TikTok — we rely on the 2021 European Commission SCCs (Decision 2021/914) included in their data processing terms.
- UK International Data Transfer Addendum (IDTA): applied to UK-specific transfers where SCCs are used.
MakerWorld (Bambu Lab) has operations in China. Where the one-time eligibility check described in Section 2 is needed, it involves transmitting your MakerWorld account identifier to MakerWorld, whose servers may be located in or accessible from China. This is minimized to the data strictly necessary for verification.
Canadian users: your data is processed in the United States, which has different privacy laws than Canada. US authorities may access data under US law in ways Canadian law would not permit. You may contact us to ask what countries your data is sent to.
You may request details of the specific safeguards in place for any transfer by emailing hello@leorastudio.com.
6. How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes in this Policy or as required by law. When a retention period expires, data is securely deleted or irreversibly anonymized. Data subject to active legal proceedings may be retained until the matter is resolved.
| Data | Retention period | Reason |
|---|---|---|
| Account data | Account lifetime + 3 years after closure | Dispute resolution; statute of limitations |
| Sign-in tokens | Session only — invalidated on sign-out or expiry | Not needed beyond an active session |
| Payment & transaction records | 7 years from the transaction date | US IRS and EU VAT record-keeping obligations |
| Customization Tool jobs, rendered files, and uploaded User Content | With your account data (account lifetime + 3 years after closure); Leora may remove rendered preview and download files earlier once they are superseded | Delivering your files; license enforcement; data minimization |
| Saved lamps | Until you delete them, and deleted at the same time as your account. Lamps kept in your browser stay there until you delete them, clear your browser's storage, or sign in on that browser (they then move to your account) | Letting you open your lamps again |
| Studio download records (lamp fingerprints) and library download records | With your account data (account lifetime + 3 years after closure) | Counting the lamps included in your Plan; license enforcement; refund requests |
| Consent & compliance records | With your account data; Stripe keeps your checkout acceptance with the transaction record (7 years) | Proof of lawful processing; GDPR Article 5(2) accountability |
| Support & contact communications | 3 years from the last communication | Customer service continuity; dispute resolution |
| Free Starter download requests | 12 months from the request (the link itself works for 30 days); the daily count per address, 2 days | Sending the link; preventing misuse of the form |
| Server logs | 30 days (our hosting provider's standard log retention), longer only where needed for a security investigation | Security monitoring; debugging |
| Strictly necessary storage (sign-in state, consent choice) | Until you sign out, change your choice, or clear your browser's storage | Platform function; consent record |
| Language (the "leora.lang" session storage; the "leora-lang" cookie if you pick a language in the language menu) | Until the end of your browser session; the cookie 12 months if you allow functional cookies | Showing the Platform in your language |
| Analytics data and cookies (PostHog) | Up to 12 months | Platform improvement |
| Advertising cookies (TikTok "_ttp"; our "ttclid" cookie) | Up to 13 months; 30 days | Advertising measurement |
| Data breach records (internal) | Minimum 3 years | GDPR Article 33(5) breach register |
7. Your Privacy Rights
How to exercise any right: email hello@leorastudio.com with the subject "Privacy Request," your name, the email address registered to your account, and the right you wish to exercise. We may verify your identity before acting. We will not charge a fee unless a request is manifestly unfounded or excessive. You can also delete your account yourself at any time from the Account page; records we must keep by law (such as transaction records) are retained as set out in Section 6.
7.1 EU and UK Residents (GDPR / UK GDPR)
You have the following rights under the GDPR and UK GDPR:
- Access (Article 15): receive a copy of the personal data we hold about you, including how it is used and who it is shared with.
- Rectification (Article 16): ask us to correct inaccurate or incomplete data.
- Erasure (Article 17): ask us to delete your data. This right is not absolute — we may retain data required by law (for example tax records and license compliance logs). Where we cannot delete in full, we will tell you what we can delete and what we must retain.
- Restriction (Article 18): ask us to pause processing while you contest accuracy or an objection is pending.
- Portability (Article 20): receive your data in a structured, machine-readable format (such as JSON or CSV) where processing is based on consent or contract.
- Object — legitimate interests (Article 21(1)): object to processing based on our legitimate interests. We will stop unless we have compelling overriding grounds or need the data for legal claims.
- Object — direct marketing (Article 21(2)): object to marketing use of your data at any time. This right is absolute.
- Withdraw consent: withdraw your consent to analytics and advertising cookies at any time via "Cookie Settings" in the footer. Withdrawal does not affect processing that took place before it.
- Automated decisions (Article 22): as stated in Section 2, Leora does not make legally significant automated decisions about you.
Right to complain: you may lodge a complaint with the supervisory authority in your EU member state (directory: edpb.europa.eu/about-edpb/board/members_en) or, for UK residents, with the ICO (ico.org.uk | 0303 123 1113). We encourage you to contact us first.
7.2 California Residents (CCPA / CPRA)
We extend the following rights, modelled on the CCPA/CPRA, to all California residents, whether or not that law applies to a business of Leora's size:
- Know: request disclosure of the categories and specific pieces of personal information collected about you in the last 12 months, including sources, purposes, and third parties.
- Delete: request deletion of your personal information, subject to exceptions (completing transactions, security, legal obligations).
- Correct: request correction of inaccurate personal information.
- Opt out of sale or sharing: Leora does not sell personal information. Sending advertising measurement data to TikTok with your consent may be considered "sharing" for cross-context behavioral advertising under the CPRA. You can opt out, or withdraw consent, at any time via "Cookie Settings" in the footer — declining the "Analytics & advertising" category stops any sharing with TikTok.
- Limit use of sensitive personal information: we do not collect sensitive personal information as defined by the CPRA.
- Non-discrimination: we will not deny service, charge different prices, or reduce quality because you exercised a privacy right.
To submit a California request: email hello@leorastudio.com (subject: "California Privacy Request"). We respond within 45 days (extendable by 45 days with notice). You may designate an authorized agent with written proof of authorization. If we deny your request, you may ask us to reconsider by replying with "CCPA Appeal" in the subject, and you may complain to the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General at any time.
7.3 Canadian Residents (PIPEDA and Quebec Law 25)
Under PIPEDA you have the right to access personal information we hold about you, challenge its accuracy, and withdraw consent to its collection, use, or disclosure (subject to legal and contractual restrictions — withdrawal may mean we can no longer provide the Platform). Under Quebec Law 25, you also have the right to receive your personal information in a structured, commonly used format (portability) and, in certain circumstances, to have it de-indexed or its dissemination stopped. To exercise any of these rights, email hello@leorastudio.com. We respond within 30 days. You may also lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca | 1-800-282-1376) or, for Quebec residents, with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
8. Cookies and Similar Technologies
We use cookies and browser storage on the Platform in the three categories below, which match the cookie banner shown on your first visit. You can change your choice at any time via "Cookie Settings" in the footer or through your browser settings.
Strictly necessary
Required for the Platform to function and cannot be switched off: the sign-in state kept by Firebase Authentication in your browser, security protection during sign-in and checkout, the record of your cookie consent choice, and the language you are reading the Platform in — kept in your browser's session storage ("leora.lang") and, if you pick a language in the language menu, in a "leora-lang" cookie, both only until the end of your browser session; and the lamps you save in the Studio while signed out, kept in your browser's local storage ("leora.lamps") because you asked for them to be saved, until you delete them, clear your browser's storage, or sign in on that browser (they then move to your account). No consent is required for these.
Functional
Remember choices you make in the interface — your Studio print-bed and file options, the look you chose, the language you picked in the language menu (its "leora-lang" cookie is then kept for 12 months rather than until the end of your browser session), and whether you closed an announcement — so you do not have to make them again. They are written to your browser's storage only when you make the choice and hold nothing but that choice; they are not used to track you.
Analytics & advertising
- PostHog measures how the Platform is used so we can improve it. Before you consent, PostHog runs without cookies or local storage and does not identify you (Section 4). After you consent, it may place cookies (names beginning "ph_") and link usage to your account.
- The TikTok pixel measures whether our advertising on TikTok leads to sign-ups and purchases. It is not loaded until you consent. With your consent, it places cookies such as "_ttp", and we keep the "ttclid" identifier from a TikTok ad link you arrived through in a cookie for 30 days so that a later purchase can be attributed; we then send TikTok a server-side purchase event as described in Section 4. Declining or withdrawing consent stops both.
Videos in the Guides: the Guides show our videos from YouTube in its privacy-enhanced mode (youtube-nocookie.com). Nothing is loaded from YouTube until you press play. Pressing play is your choice to load YouTube's player, which may then set cookies or similar identifiers under Google's privacy policy; the note under each video says so before you press play.
We do not use any other advertising cookies and we do not show targeted advertising on the Platform.
Your language: the Platform is available in several languages, each at its own address (for example e-leora.com/de for German). When you open an English page, the Platform shows it in the language you picked in the language menu or, if you have not picked one, in the language you were reading earlier in the same browser session. Otherwise, once per browser session, it shows the page in the first of your browser's languages that we offer; if your browser lists none of them, it asks our hosting provider, Firebase Hosting, for the country your connection comes from, which Firebase Hosting determines from your IP address, and shows the page in that country's language if we offer it. The country is not stored, and no cookie is set for it.
Opting out with the providers: PostHog — posthog.com/docs/privacy/gdpr; TikTok — see the advertising settings in your TikTok account.
Do Not Track and Global Privacy Control: the Platform does not currently alter its behavior in response to DNT or GPC browser signals; the cookie banner and "Cookie Settings" provide the same control. We will update this section if this changes.
9. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- encryption in transit (TLS 1.2 or higher) for all traffic, and encryption at rest on Google Cloud and Amazon Web Services storage;
- authentication through Firebase Authentication — passwords for email sign-in are stored only as salted hashes, and sign-in with Google or Apple benefits from those providers' own protections, including any two-factor authentication you have enabled with them;
- payment security — full card data is never transmitted to or stored on Leora's systems; all payment processing is handled by Stripe under PCI-DSS Level 1;
- a license notice in every Studio export, and the ability to add watermarks or metadata linking downloaded and exported files to an account, to deter unauthorized redistribution;
- access controls — access to personal data is restricted to Leora personnel who need it for their role, and secrets are held in managed secret storage; and
- vendor security — all service providers are contractually required to maintain appropriate security.
No system is completely secure. If you believe your account has been compromised, contact hello@leorastudio.com immediately. If you sign in with Google, review your Google account security at myaccount.google.com/security; if you sign in with an email address and password, use "Forgot password?" on the sign-in page to reset it.
Sign-in providers and your Leora account: if you revoke Leora's Google permissions or stop using Sign in with Apple for Leora, your session will end and you will not be able to sign back in with that provider until you re-authorize. Your Leora account data remains in our system; contact us at hello@leorastudio.com if you need to manage it.
Data breach notification: in the event of a breach likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Article 33) and notify affected individuals without undue delay where required. For Canadian users, we will report breaches to the OPC as soon as feasible. We maintain an internal breach register as required by GDPR Article 33(5).
10. Children's Privacy
The Platform is intended for adults and is not directed at children. You must be at least 18 to create an account (Terms, Section 3.1). We do not knowingly collect personal data from anyone under 18, and in no case from children below the age of digital consent in their country (13 in the United States and the United Kingdom, 13 to 16 in EU member states under GDPR Article 8, and 14 in Quebec). If you are a parent or guardian and believe your child has created a Leora account, contact hello@leorastudio.com immediately and we will delete the account and associated data.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our data practices or legal requirements. When we make material changes we will: post the updated Policy on the Platform with a new effective date; send email notice to your registered address at least 14 days before the changes take effect; and seek fresh consent for any new processing activity that requires it under the GDPR.
12. Governing Law
This Privacy Policy is governed by the laws of the State of Delaware, USA. This does not deprive you of any mandatory privacy protections under the law of your habitual residence — the GDPR, UK GDPR, PIPEDA, Quebec Law 25, and CCPA/CPRA all apply to our processing of your data regardless of this clause. In the event of any conflict between this Privacy Policy and the Terms and Conditions regarding personal data, this Privacy Policy prevails.
Contact Us
Leora IO LLC | 131 Continental Dr, Suite 305, Newark, DE 19713, USA
Email: hello@leorastudio.com (subject: "Privacy Request")