Legal

Privacy

Leadgible builds lead-qualification funnels that other businesses embed on their own websites. That puts us in two different positions at once - we hold our customers' account data, and we handle the answers their visitors give them - and this page keeps the two apart, because the rules that govern them are different.

In effect from 2026-08-31. It is written to be checked: every factual claim below is held against the code or the specification that makes it true, by a test that runs before this page can be published.

Who is responsible for what

For the account you open with us - your name, your email address, your sign-in credentials, and your billing status - we decide what happens to it, so we are the controller and this policy governs it.

For the answers your funnels collect, you decide what is asked, who it is shared with and how long it is kept. You are the controller and we are your processor: we act on your instructions and we do not use your leads for our own purposes, sell them, or train anything on them.

If you answered someone's funnel

The business whose site you filled the form in on decides what happens to your answers, not us. Ask them first. If you contact us instead we will pass the request to them and tell you who they are.

What we hold

Your account. Your name, your email address, your sign-in credentials, the organisation and workspaces you belong to, and your plan and payment status.

The leads your funnels collect. Every answer a respondent gives, including free text written in their own words. A lead may carry a name, email, phone and company. We also record how the visit reached you: an IP address subject to the setting below, an approximate country, region, city and timezone, campaign parameters, the referring page, the landing page, the device and browser, and how long each step took.

What we work out from it. A score, the band it falls in, and the sentence explaining why.

Calls, once the voice agent ships. Call audio is discarded at session end; only the transcript is kept.

Where it is held

The primary database is in North America. Answers, extractions and transcripts are stored in object storage, not the database. If you or your respondents are in the United Kingdom or the European Economic Area, that means personal data is transferred to the United States. Standard Contractual Clauses cover the primary datastore, not only the sub-processor list. We say it that way round on purpose: it is a wider commitment than a list of vendors, and it is the one the location of our database actually requires.

IP addresses

An IP address is personal data, so it is a setting rather than an assumption. IP capture has three modes. You can capture it in full, capture it with the last part zeroed, or not capture it at all. The default is anonymised. Masking happens before the row is written, not on read. A funnel set to anonymise never holds a complete address to begin with.

What we put on a device

The embed stores a partial answer set in the respondent's browser so they can resume. It is not a cookie, it is not readable by any other site, it is never sent to us as an identifier, and clearing the browser's site data removes it.

The dashboard sets one first-party cookie so that you stay signed in. This site ships no JavaScript, so it cannot track anyone. There is no analytics script on it, no tag manager and nothing from a third party - which is checkable rather than promised, because the page you are reading contains no script tag at all.

The submission endpoint is protected by a bot-mitigation challenge. It is there to keep automated submissions out of your funnels.

How long we keep it

Your plan sets how far back your leads are kept:

  • Free - 30 days
  • Starter - 6 months
  • Pro - 2 years
  • Scale - Unlimited
  • Agency - Unlimited

Every completed lead is stamped at capture with the date its retention period ends.

Said plainly

The scheduled purge is not yet in service. The date is recorded on every lead and nothing acts on it yet, so until that job ships, data is deleted when you ask us rather than on a schedule. We would rather write that here than imply an automatic deletion you are not getting.

Who else touches it

These are the companies we rely on to run the service. A row marked with a milestone is one we do not use yet - it is listed so that the list does not have to change quietly later.

  • Cloudflare, Inc. - Hosting and compute, the database, object storage, caching, queues, platform email and bot mitigation. Everything the platform runs on.
  • Lemon Squeezy - Merchant of record. Handles payment and subscription billing, and holds the payment details - we never receive a card number.
  • Mailgun - Email delivery, and only for a customer who supplies their own Mailgun credential to send from their own domain. Nothing is sent through it by default.
  • Cloudflare Workers AI - Reading free-text answers into typed facts. Not yet in use - arrives at M2.
  • OpenAI, or a compatible provider you choose - Escalated analysis where the default model is not enough, and any provider you connect with your own key. Not yet in use - arrives at M2.
  • Slack - Notification delivery, for a customer who connects a workspace. Not yet in use - arrives at M4.
  • GoHighLevel - CRM delivery and outcome writeback, for a customer who connects an account. Not yet in use - arrives at M4.
  • Cartesia and ElevenLabs - Speech synthesis for the AI voice agent. Not yet in use - arrives at M5.

This list is published here and changes are published here. Platform email is sent by Cloudflare, with no third-party key.

AI, and what it is shown

No model reads your leads today. Reading free text into typed facts arrives with the milestone marked above, and two things are true of it when it does. Contact fields are stripped from model prompts unless opted in per field. And a funnel that uses AI analysis says so to the person filling it in.

The scoring itself is not an AI decision. Rules you write turn facts into a score, so the same answers always produce the same result, and the reason is shown rather than inferred.

Keys you store with us

If you connect your own provider, its key is encrypted before it is stored. Customer credentials are held under envelope encryption. A stored credential is never returned by any route. The interface shows you the last few characters and offers to replace it. There is no endpoint that will hand a stored key back, and one cannot be added without removing the check that forbids it.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to how we are using it, or complain to your data protection authority. Write to us at the address below and we will act on a verified request without undue delay.

Self-serve export and erasure are not built yet, so a request today is carried out by a person. If you are asking about answers you gave to someone else's funnel, see the note at the top of this page - they decide, and we will put you in touch.

How it is protected

Data belonging to one customer is separated from every other by the query layer itself rather than by a filter each page remembers to apply. Everything that leaves the system - an API response, a notification, an export, a delivery to your CRM - passes through one function that strips what must not leave, so a new feature cannot leak by forgetting.

If something goes wrong

If personal data we hold is exposed, we will tell the customers affected without undue delay after we become aware of it, with what we know and what we are doing, so that you can meet your own obligations to the people in your data.

Changes

This page is published from the same source as the product it describes, and it carries the date the current version took effect. When something material changes we will change this page and move that date.

Contact

Leadgible
Davao City, Philippines
privacy@leadgible.com