← Home

Legal

Privacy Policy

This policy explains what Lightning Leap Analytics collects, why, who processes it for us, and how you can see, export or delete it. Effective 29 September 2026.

Who we are

Lightning Leap Analytics is a marketing workspace for planning, publishing and measuring social media, email and advertising. It is operated by Lightning Leap Analytics Private Limited, H No 506, Plot 36-D, Sector 56, Gurugram, Haryana 122003, India (“we”, “us”). We are responsible for the personal data described in this policy.

Where you upload data about other people to your workspace — for example an email contact list — you decide what that data is for, and we process it on your behalf and on your instructions.

What we collect

  • Account data. Your name, email address and organisation name; your password, stored only as a one-way hash; and, if you use them, your passkeys, two-factor settings and the Google or GitHub account you sign in with.
  • Workspace content. The projects, posts, drafts, media, campaigns, email contacts and other material you and your team create or upload.
  • Connected-platform data. When you connect a social or advertising account, the data that platform shares with us with your permission — described in the two sections below. We never see or store your password for those platforms.
  • Billing data. Your plan and subscription status. Card details are entered on Stripe’s checkout and never reach our servers.
  • Usage and security logs. The IP address and browser of each signed-in session, and an audit log of security-relevant actions such as sign-ins and permission changes.
  • Cookies and local storage. The app keeps your sign-in token and display preferences in your browser’s local storage, and sets a 10-minute cookie while you sign in with Google or GitHub to protect that sign-in. Our public marketing pages set a first-party cookie (verjson_visitor_id, up to 24 months) to count visits and page views; it is not set inside the app or on this page, and we use no third-party advertising cookies.
  • Messages to us. What you send when you request a demo or email us.

How we use it

  • To provide the service: publish and schedule your posts, show your analytics, run your campaigns and emails, and let your team work together.
  • To keep accounts secure, prevent abuse, and investigate problems.
  • To bill you for a paid plan.
  • To send you messages about your account, such as password resets, invitations and deletion confirmations.
  • To meet our legal obligations.

We do not sell personal data and do not use it to show you advertising. When you use an AI feature — for example drafting a caption or suggesting a reply — the content you send to it is passed to third-party AI model providers solely to generate the output you asked for.

Facebook and Instagram data

Lightning Leap Analytics, operated by Lightning Leap Analytics Private Limited, connects to Facebook Pages and Instagram professional accounts only when a user chooses to connect them. With the user’s permission we access: the names, profile pictures and follower counts of the connected Pages and Instagram accounts; the posts published through our app and their insights; comments on those posts; and Messenger and Instagram Direct messages sent to the connected accounts, including the sender’s name and profile picture.

We use this data only to publish and schedule the user’s posts, show their analytics, and let their team read and reply to comments and messages. We do not sell it, use it for advertising, or share it with third parties other than our infrastructure providers (DigitalOcean, Cloudflare, Resend) and, when a team member asks for an AI-drafted reply or sentiment score, the AI model provider that produces it. They process it only on our behalf.

Access tokens are stored encrypted. Disconnecting an account deletes its access token immediately. Users can delete all their data at any time as described at https://studio.lightningleap.store/data-deletion.

Requests from public authorities: if we receive a request from a public authority for users’ personal data, we review whether it is lawful, challenge it where we consider it unlawful, disclose only the minimum data necessary, and keep a record of each request and our response.

Other connected platforms

You can also connect Threads, LinkedIn (to post from your personal profile), Pinterest, TikTok, X and YouTube. The same principles apply to each: we connect only when you choose to, request only the permissions needed to publish your posts and report on them, and where a platform allows, show your comments and messages so your team can reply. From each we store the account’s name, identifier and profile picture, the posts you publish through us and their metrics, and an encrypted access token.

Disconnecting any account deletes its access token immediately. You can also revoke our access from the platform’s own settings at any time.

Who processes data for us

  • DigitalOcean — hosting and database.
  • Cloudflare — network delivery and secure connections to our servers.
  • Resend — sending account and transactional email.
  • Stripe — payments and subscription billing.
  • AI model providers — generating output for the AI features you use.

Each processes data only to provide its service to us. The platforms you connect (Meta, LinkedIn and the others above) receive what you publish through us under their own privacy policies.

International transfers

We are based in India and our servers are hosted by DigitalOcean in the United States, so your data is transferred to and stored in the United States. Our processors may handle it in other countries where they operate. We rely on our agreements with them to protect it wherever it is processed.

How long we keep it

  • Account and workspace data: while your account is active.
  • Access tokens for a connected account: deleted as soon as you disconnect it.
  • After you delete your account: a 7-day window in which you can cancel, then your personal data is permanently deleted.
  • A data export you request: available to download for 7 days.
  • Billing records and the record that a deletion happened: as long as the law requires.

Your rights

Subject to the law that applies to you — including India’s Digital Personal Data Protection Act, 2023 and, where it applies, the EU and UK GDPR — you can:

  • Access and export your data: sign in and go to Settings → Privacy to download an archive.
  • Delete your account from Settings → Privacy, or follow the data deletion instructions.
  • Correct inaccurate details by asking us.
  • Withdraw consent for a connected platform by disconnecting it.
  • Complain to us, and to your data protection authority (in India, the Data Protection Board of India).

For anything you cannot do in the app, email kartikaye@lightningleapanalytics.com. We reply within 30 days.

Security

Connections to the service are encrypted in transit. Access tokens and other credentials are encrypted at rest, and passwords are stored only as one-way hashes. You can protect your account with two-factor authentication or a passkey, and workspace owners control what each team member can see and do. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

Children

Lightning Leap Analytics is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We will update the date at the top of this page when we change the policy, and tell you in the app or by email before a material change takes effect.

Contact

Lightning Leap Analytics Private Limited, H No 506, Plot 36-D, Sector 56, Gurugram, Haryana 122003, India. Email kartikaye@lightningleapanalytics.com.