Privacy policy
Last updated
1. Introduction
Lead Strategist processes your personal data in accordance with the GDPR. This policy describes what data we collect, how we use it and what rights you have.
2. Data we collect
- Name and email address when you create an account.
- Your password, stored only as a secure hash.
- Hashes of your API keys and OAuth tokens, and which AI clients you have connected.
- Usage metadata for MCP calls: which tool was called, when, and whether the call succeeded. We do not store your prompts or the results your AI shows you.
- Payment details, once payments open, are handled by our payment provider. We never store card details.
3. Purpose
We use the data to deliver the service: your account, access to the MCP server, usage metering and, later, billing. We do not store the lead lists your AI client shows you, and we do not use your data for marketing or sell it to third parties.
4. Cookies and local storage
- ls_session: signed session cookie, required for login.
- sidebar: remembers whether the sidebar is open or closed.
- theme: stored in localStorage (light or dark theme).
- Plausible Analytics: loaded only if you choose "Accept all". Used for anonymous page statistics without identifying you.
You can accept or decline optional cookies in the cookie banner.
5. Data processors
- Hosting provider: the servers that run the service.
- Email provider: account confirmation and password reset emails.
- Plausible: web statistics, only if you accept all cookies.
- Payment provider: once payments open.
6. Your rights
You have the right of access, rectification, erasure and data portability. You can also complain to the Danish Data Protection Agency (Datatilsynet).